Security Awareness Training Isn’t Dead, but It Needs a Rethink
Practitioners say security awareness training has become compliance theater and cannot stop AI-scaled social engineering alone.
SecurityWeek gathered practitioners who argue that much security awareness training is repetitive, generic, and shaped by compliance and insurance requirements rather than behavior change. They say it can help for scenarios already covered, but attackers now use AI to scale polished phishing, voice clones, and mobile lures over SMS and messaging apps. Commenters from Hoxhunt, Lookout, Doppel, and others say training should be frequent and role-specific and must be backed by identity protections, MFA, and other technical controls. Hoxhunt's Mike Aalto pointed to a 14-fold surge in AI-generated phishing from late 2025 into 2026.