Security Awareness Training Isn’t Dead, but It Needs a Rethink
Practitioners say security awareness training has become compliance theater and cannot stop AI-scaled social engineering alone.
SecurityWeek gathered practitioners who argue that much security awareness training is repetitive, generic, and shaped by compliance and insurance requirements rather than behavior change. They say it can help for scenarios already covered, but attackers now use AI to scale polished phishing, voice clones, and mobile lures over SMS and messaging apps. Commenters from Hoxhunt, Lookout, Doppel, and others say training should be frequent and role-specific and must be backed by identity protections, MFA, and other technical controls. Hoxhunt's Mike Aalto pointed to a 14-fold surge in AI-generated phishing from late 2025 into 2026.
- Many programs repeat generic content mainly to satisfy compliance and insurers.
- Training lags AI phishing, voice clones, and mobile messaging lures.
- Experts want continuous, role-based training backed by technical controls.
- Hoxhunt cited a 14-fold surge in AI-generated phishing into 2026.
Full article2,310 words · extracted from securityweek.com · click to collapse
All enterprises conduct security awareness training for their employees. But whether this has tangible benefits is debatable.
Empirical evidence suggests that security awareness training isn’t working – successful attacks keep increasing. But opinions on the efficacy of awareness training range from it doesn’t work to it does work, with sometimes, perhaps and depends between the two extremes.
Awareness training focuses on two tasks: to reduce the effect of bad judgment turning an employee into an insider threat; and to harden employees against falling to malicious social engineering. We focus on social engineering.
Compliance theater
The majority opinion is that awareness training is important but not always effectively delivered – and not necessarily at the fault of the company concerned. Stefan Dasic, senior malware research engineer at Malwarebytes, suggests, “Most training programs fail because of how they’re run.” He believes they are repetitive and generic, making them seem pointless.
“Some of that repetition isn’t just poor design though – a lot of it is driven by compliance and insurance requirements that mandate the same content be re-delivered to every employee every year, regardless of whether they already know it.” The danger here is that awareness training is reduced to an annual legal checkbox.
Robert Costello, chief digital and information officer at Merlin Group, has similar concerns. “Too much of today’s training is compliance-focused and doesn’t reflect the sophisticated social engineering and AI-enabled attacks organizations face today.”
Advertisement. Scroll to continue reading.
Mike Lyman, senior security consultant at Black Duck, expands on this concern. “Re-taking identical courses across multiple employers is a good concrete illustration of training-as-compliance-theater: the kind of thing that produces checkbox completion without any behavior change and may explain why some studies find weak or null effects even where completion rates are high.”
The problem with compliance requirements, and not just in awareness training, is that it provides a level that can be viewed as a target to achieve rather than a baseline that can be improved.
Where and when training works
Drew Thompson, global lead for training and enablement at UltraViolet Cyber, believes awareness training works, but primarily for the specific situations covered by the training. The problem, however, is, “The attackers keep changing what they are doing, and the training is often trying to prepare people based on what we already know.”
Josh Bartolomie, VP, global head of threat intelligence at Doppel, agrees. “Security awareness training still works, but many organizations are expecting it to solve a problem that’s changed.”
Thompson suggests training should be more frequent, should evolve more in line with the evolving attacks, should include direction on reaction to suspicious messages (behavioral training), and be more focused on the employee’s role in the business.
“And,” he adds, “training cannot be the only control. It needs to be backed by good processes, identity protections, technical controls, and clear verification procedures.”
Bartolomie adds, “Awareness remains essential, but it can’t be the only line of defense. We can no longer expect humans to be the final line of defense against threats. Technology should be that.”
Costello says, “Security awareness training still has a role; however, it should reinforce a modern security architecture, not compensate for the lack of one.”
[ Read: Social Engineering Detection Moves Into the Live Conversation ]
Biswajit De, co-founder and CTO at CleanStart, adds, “Awareness should complement engineering, not replace it. Good engineering assumes things will fail, and good security should assume people occasionally will too.”
Jim Dolce, CEO at Lookout, believes training can be useful, “but is fundamentally outmatched within today’s mobile AI threat landscape. The attempt to turn employees into a human firewall through training belongs to the earlier desktop-centric age.”
Frontier AI has completely changed the threat landscape and weaponized social engineering – generating hyper-personalized, flawless phishes and voice clones across mobile channels like SMS, WhatsApp, and messaging apps at machine speed. “Security awareness training fails because we are asking humans to defeat AI on a 6-inch phone screen. You cannot train away a structural architectural problem.”
Mike Aalto, co-founder and CEO at Hoxhunt, points to a 14-fold surge in AI-generated phishing at the turn of 2025 to 2026. “The big shift isn’t brand-new tactics and zero-day messaging, it’s the modernization of old attacks. Traditional phishing kits are being upgraded with cleaner formatting, better writing, and more personalized messaging that can be generated at scale.”

He has a valid point: defense against attack remains fundamentally a game of whack-a-mole. The problem is primarily a huge increase of better formed (deep-faked moles) delivered at greater speed and scope courtesy of LLMs. But it’s still whack-a-mole.
He believes ‘behavioral’ training needs to be added to awareness training. Focusing on and rewarding a few measurable core behaviors like threat reporting and MFA usage establishes a cultural bedrock of secure behaviors. “By replacing fear and heavy-handed surveillance with fun, continuous learning and automated behavioral interventions, you don’t just reduce the likelihood of negligence. You fundamentally transform your workforce into an active, intelligent human sensor network that catches the threats your technology misses.”
However, Sanny Liao, co-founder and CPO at Fable Security, says bluntly, “For the most part, security awareness training as done today does not work. Social engineering continues to succeed because attackers exploit context, timing, and psychology, while most training remains generic, infrequent, and removed from the moments when employees are actually making decisions.”
She hints at a novel approach. “One place the industry can look for inspiration is adtech. Marketers have gotten remarkably good at changing behavior by delivering the right message at the right time based on context. Security awareness has largely done the opposite by giving everyone the same training at the same time, regardless of the decisions they’re making or the risks they face. When organizations change behavior instead of simply raising awareness, employees stop being viewed as the weakest link and start becoming an active part of the organization’s security defenses.”
Lyman points to the contradiction faced by awareness trainers. KnowBe4 data has shown that training with simulated phishing can produce real reductions in phish-prone rates. But academic studies show that this effect fades fast. “Effects that look strong right after a course can disappear within months.”
So, does security awareness training work? “Yes,” says De, “but expecting security awareness training alone to stop cyberattacks is like expecting airport security posters to prevent hijackings.”
Advantage to the attacker
Social engineers have three primary advantages over security awareness training: asymmetry, attack is proactive while defense is reactive, and psychology.
Asymmetry. ‘Defenders must be right every time; attackers only need to be right once.’ That’s the standard description of the asymmetry between cybersecurity attack and defense. To combat social engineering, each person must be right every time against every attacker, always, at machine speed. Every single attacker, out of hundreds of thousands, assisted by AI in performance and scale at machine speed, need only succeed once.

“Attackers don’t need everyone to fail,” says De, “they just need one distracted person on one busy afternoon.”
Predicting the future. Trainers primarily teach how to recognize yesterday’s attacks. It is conceivable that excellent training can teach how to recognize today’s attacks. It is hard to imagine how awareness training can teach how to recognize the new and evolving attacks that will come tomorrow. You cannot teach what you don’t know. By the time awareness training is delivered, it could be obsolete.
Psychology. Psychology is complex, including intangibles like memory and motivation. Here, we’ll just ask a single question: can you expect a person whose full-time job is bean counting to be as aware of trickery as a person whose full-time job is trickery? And that’s without delving into the complexities of human memory retention and loss.
Asymmetry is a fact we cannot change and can only reduce with a limitless budget. Predicting the future is largely impossible and never long term. Psychology, however, is current. We can learn and improve from it.
The psychology of awareness training
To explore this angle of security awareness training, we talked to cognitive psychologist Jordan Richard Schoenherr, PhD, a scientist at Humanix and adjunct professor at the University of New South Wales.
Schoenherr’s belief is that security awareness training is largely not working. That’s not to say it cannot work, or at least be improved, but it is difficult owing to the complexities of the human mind and memory. The purpose of awareness is to instill information into long-term memory, coupled with the correct behavioral response to that memory. But, comments Schoenherr, “Forgetting (or entropy) is the default state of memory – and it occurs rapidly.”
Frequently refreshing the learning is necessary to maintain that memory. Even if this is successful, “It doesn’t necessarily mean that someone is going to know, in the moment, when and where to use it. So, the complementary approach, behavioral nudges, attempts to reactivate that information in a particular context.”
So, the subject of the training must be able to recognize a situation, relate the situation to long-term volatile memory and activate it in the present, while recalling the correct behavioral response (accept, ignore, report, etcetera).
This training must necessarily teach the student how to recognize a phish. Such training is largely, of necessity, limited to known social engineering patterns – and that in itself can be problematic.
For illustration purposes only, if the training is limited to recognition of the old ‘Nigerian scams’ and riddled with spelling and grammatical mistakes, ‘Nigerian scams’ will be easily recognized. The danger is that a lack of these flags might be translated as proof of validity. The reality, of course, is that the absence of proof is not proof of absence; and that applies to all awareness training.

So, a major priority for the training is that it must be up-to-date with current social engineering practices. The difficulty here is that up-to-date today may be historical next week.
We know that criminals change and adapt their attack processes rapidly. There is no guarantee that training on known methods can prepare people for social engineers’ latest disruptive innovations. Training for disruptive innovations requires predicting the future, which is something both trainers and cybersecurity vendors consistently attempt. Predicting the future is possible (otherwise we wouldn’t have people making money on trading stocks and shares), but it is difficult, never guaranteed, and probably short-term only.
Schoenherr explains: “When we give people creative tasks [such as predicting the future], it basically activates two main regions of the brain, the inferior temporal lobe where long-term memories are stored, and the prefrontal cortex for executive functions. All the building blocks in your memory are getting pulled into that prefrontal cortex, which is trying to rearrange them, manipulate, and come up with what we would call a mental model. The extent to which that mental model is going to work or not is based on analogical reasoning. Find the right shape in your long-term memory, or reconstruct one that looks like the situation, and predict into the future.”
(This is basically the same mental process used by an employee wondering if a communication is valid or malicious.)
Back to the future, we know from stock analysts that this can be done for the short term, but we also know that these predictions are poorly calibrated for the long term. “In the short run, you can find people that are very effective at predicting the state of the world because they are aware of the variables that exist,” he continued. “They seem to have some kind of magical trick. It’s not magic; it’s because they have a mental model which is congruent with the situation. But then new variables come into play, and they lose the hot streak of prediction.”
So, can an organization predict the future? Yes. Will those predictions and plans based on them be effective? Depends how well the organization handles and incorporates what is known as ‘decision making under deep uncertainty’. “The decision-making under deep uncertainty approach assumes you should develop as many potential scenarios as possible based on the variables you have, and then run simulations to see which scenario produces the best outcomes across many different iterations. That ‘best outcome’ is the scenario that you’re going to run with.”
It’s the scenario needed to predict probable/possible future styles of social engineering. “It will be imperfect, it will not necessarily predict the state of the world perfectly, but you need to build up these scenarios,” Schoenherr continued. But it is difficult. “People will always be fighting the last war and are not necessarily capable of thinking what will happen in the future.”
Cognitive psychology helps us understand how to navigate the complexities of maintaining and retrieving memories, and how best to project current knowledge to predict likely future scenarios – both of which are essential for effective awareness training.
Summary
Understanding the psychology of cognition cannot solve the asymmetry of the social engineering threat. That can only be solved or reduced with a limitless security budget when most budgets are maintained at the minimum possible. It can, however, assist in predicting the future direction of social engineering. More particularly, however, it can help in the design of awareness training methodologies likely to be more effective.
Combining lessons learned through current awareness training (awareness training and behavioral conditioning backed by refresh frequency and technology) with the human cognitive processes we learn from science, can help us develop new or improved training. It will never be perfect, but awareness training cannot be abandoned. And it can always be improved.
Related: CyberNut Closes $5M Growth Capital for K-12 Security Awareness Training
Related: Jericho Security Gets $15 Million for AI-Powered Awareness Training
Related: Vista Equity Partners to Acquire Security Awareness Training Firm KnowBe4 for $4.6B
Related: Huntress Acquires Security Awareness Training Startup Curricula for $22M