Most security awareness training is forgotten within two weeks. The annual video module, the generic phishing simulation, the slide deck about password hygiene: these are compliance activities, not behaviour change activities. This article covers what the research says about effective security training and what that means for how sessions should be designed and delivered.

Why generic training does not stick

Generic security awareness training fails for the same reason generic training of any kind fails: it is not connected to the learner's actual work. A slide about phishing that shows an obviously fake email from a Nigerian prince is not useful to a finance team member who receives 200 emails a day from real suppliers with real payment requests. The threat model has to match the actual environment. Training built around scenarios the learner recognises from their own inbox is retained at a significantly higher rate.

The role of phishing simulations

Phishing simulations are useful when they are followed by a debrief. The click rate is a data point, not a measure of resilience. A simulation that is sent, measured, and reported without any follow-up conversation does not change behaviour. The debrief, where the tester explains what the email contained, why it was convincing, and what the correct response would have been, is the part that produces the learning. Most providers skip the debrief because it takes time. We do not.

Scenario-based learning for non-technical staff

Non-technical staff do not need to understand how SQL injection works. They need to understand what a convincing pretexting call sounds like, how to verify an unexpected payment request, and what to do when they receive an email that asks them to click a link urgently. Scenario-based training that uses real examples from red team exercises is more effective than abstract technical explanations. The scenarios we use in our training sessions are drawn from actual engagements, with details changed to protect client confidentiality.

Frequency and format

Annual training is better than nothing. Quarterly short sessions are significantly more effective than one annual session. The format matters less than the frequency and the relevance. A 20-minute session built around three real scenarios from the past quarter is more valuable than a two-hour annual module. If your organisation has a security incident or a near-miss, that is the best possible training material: run a session within two weeks while the event is fresh.

Measuring whether training has worked

The most useful measure of training effectiveness is not the click rate on a phishing simulation. It is the number of suspicious emails reported by staff in the months following training. Organisations with effective training programmes see reporting rates increase. Reporting is the behaviour you want: a staff member who recognises a suspicious email and reports it has done exactly the right thing, regardless of whether they initially clicked.

Swift Vaultgate's security awareness training sessions are built around real scenarios from our red team engagements. Half-day and full-day formats, delivered on-site or via video call, from £1,200. Details on our engagement packages page.