All enterprises conduct safety consciousness coaching for his or her workers. However whether or not this has tangible advantages is debatable.
Empirical proof means that safety consciousness coaching isn’t working – profitable assaults preserve growing. However opinions on the efficacy of consciousness coaching vary from it doesn’t work to it does work, with generally, maybe and relies upon between the 2 extremes.
Consciousness coaching focuses on two duties: to scale back the impact of dangerous judgment turning an worker into an insider menace; and to harden workers in opposition to falling to malicious social engineering. We concentrate on social engineering.
Compliance theater
The bulk opinion is that consciousness coaching is essential however not all the time successfully delivered – and never essentially on the fault of the corporate involved. Stefan Dasic, senior malware analysis engineer at Malwarebytes, suggests, “Most coaching applications fail due to how they’re run.” He believes they’re repetitive and generic, making them appear pointless.
“A few of that repetition isn’t simply poor design although – quite a lot of it’s pushed by compliance and insurance coverage necessities that mandate the identical content material be re-delivered to each worker yearly, no matter whether or not they already comprehend it.” The hazard right here is that consciousness coaching is diminished to an annual authorized checkbox.
Robert Costello, chief digital and knowledge officer at Merlin Group, has comparable issues. “An excessive amount of of immediately’s coaching is compliance-focused and doesn’t replicate the subtle social engineering and AI-enabled assaults organizations face immediately.”
Mike Lyman, senior safety guide at Black Duck, expands on this concern. “Re-taking an identical programs throughout a number of employers is an effective concrete illustration of training-as-compliance-theater: the sort of factor that produces checkbox completion with none habits change and will clarify why some research discover weak or null results even the place completion charges are excessive.”
The issue with compliance necessities, and never simply in consciousness coaching, is that it offers a stage that may be seen as a goal to realize quite than a baseline that may be improved.
The place and when coaching works
Drew Thompson, world lead for coaching and enablement at UltraViolet Cyber, believes consciousness coaching works, however primarily for the precise conditions coated by the coaching. The issue, nonetheless, is, “The attackers preserve altering what they’re doing, and the coaching is usually making an attempt to arrange folks based mostly on what we already know.”
Josh Bartolomie, VP, world head of menace intelligence at Doppel, agrees. “Safety consciousness coaching nonetheless works, however many organizations predict it to unravel an issue that’s modified.”
Thompson suggests coaching must be extra frequent, ought to evolve extra in keeping with the evolving assaults, ought to embrace route on response to suspicious messages (behavioral coaching), and be extra targeted on the worker’s function within the enterprise.
“And,” he provides, “coaching can’t be the one management. It must be backed by good processes, identification protections, technical controls, and clear verification procedures.”
Bartolomie provides, “Consciousness stays important, however it may well’t be the one line of protection. We will not anticipate people to be the ultimate line of protection in opposition to threats. Know-how must be that.”
Costello says, “Safety consciousness coaching nonetheless has a task; nonetheless, it ought to reinforce a contemporary safety structure, not compensate for the shortage of 1.”
[ Read: Social Engineering Detection Moves Into the Live Conversation ]
Biswajit De, co-founder and CTO at CleanStart, provides, “Consciousness ought to complement engineering, not substitute it. Good engineering assumes issues will fail, and good safety ought to assume folks sometimes will too.”
Jim Dolce, CEO at Lookout, believes coaching might be helpful, “however is essentially outmatched inside immediately’s cell AI menace panorama. The try to show workers right into a human firewall by way of coaching belongs to the sooner desktop-centric age.”
Frontier AI has fully modified the menace panorama and weaponized social engineering – producing hyper-personalized, flawless phishes and voice clones throughout cell channels like SMS, WhatsApp, and messaging apps at machine pace. “Safety consciousness coaching fails as a result of we’re asking people to defeat AI on a 6-inch telephone display. You can not prepare away a structural architectural drawback.”
Mike Aalto, co-founder and CEO at Hoxhunt, factors to a 14-fold surge in AI-generated phishing on the flip of 2025 to 2026. “The massive shift isn’t brand-new ways and zero-day messaging, it’s the modernization of previous assaults. Conventional phishing kits are being upgraded with cleaner formatting, higher writing, and extra personalised messaging that may be generated at scale.”

He has a sound level: protection in opposition to assault stays essentially a sport of whack-a-mole. The issue is primarily an enormous improve of higher shaped (deep-faked moles) delivered at larger pace and scope courtesy of LLMs. But it surely’s nonetheless whack-a-mole.
He believes ‘behavioral’ coaching must be added to consciousness coaching. Specializing in and rewarding just a few measurable core behaviors like menace reporting and MFA utilization establishes a cultural bedrock of safe behaviors. “By changing concern and heavy-handed surveillance with enjoyable, steady studying and automatic behavioral interventions, you don’t simply scale back the chance of negligence. You essentially remodel your workforce into an energetic, clever human sensor community that catches the threats your know-how misses.”
Nonetheless, Sanny Liao, co-founder and CPO at Fable Safety, says bluntly, “For essentially the most half, safety consciousness coaching as performed immediately doesn’t work. Social engineering continues to succeed as a result of attackers exploit context, timing, and psychology, whereas most coaching stays generic, rare, and faraway from the moments when workers are literally making choices.”
She hints at a novel method. “One place the trade can search for inspiration is adtech. Entrepreneurs have gotten remarkably good at altering habits by delivering the best message on the proper time based mostly on context. Safety consciousness has largely performed the alternative by giving everybody the identical coaching on the identical time, whatever the choices they’re making or the dangers they face. When organizations change habits as an alternative of merely elevating consciousness, workers cease being seen because the weakest hyperlink and begin turning into an energetic a part of the group’s safety defenses.”
Lyman factors to the contradiction confronted by consciousness trainers. KnowBe4 information has proven that coaching with simulated phishing can produce actual reductions in phish-prone charges. However tutorial research present that this impact fades quick. “Results that look sturdy proper after a course can disappear inside months.”
So, does safety consciousness coaching work? “Sure,” says De, “however anticipating safety consciousness coaching alone to cease cyberattacks is like anticipating airport safety posters to forestall hijackings.”
Benefit to the attacker
Social engineers have three main benefits over safety consciousness coaching: asymmetry, assault is proactive whereas protection is reactive, and psychology.
Asymmetry. ‘Defenders should be proper each time; attackers solely should be proper as soon as.’ That’s the usual description of the asymmetry between cybersecurity assault and protection. To fight social engineering, every particular person should be proper each time in opposition to each attacker, all the time, at machine pace. Each single attacker, out of a whole bunch of 1000’s, assisted by AI in efficiency and scale at machine pace, want solely succeed as soon as.

“Attackers don’t want everybody to fail,” says De, “they only want one distracted particular person on one busy afternoon.”
Predicting the longer term. Trainers primarily educate how you can acknowledge yesterday’s assaults. It’s conceivable that wonderful coaching can educate how you can acknowledge immediately’s assaults. It’s onerous to think about how consciousness coaching can educate how you can acknowledge the brand new and evolving assaults that may come tomorrow. You can not educate what you don’t know. By the point consciousness coaching is delivered, it might be out of date.
Psychology. Psychology is advanced, together with intangibles like reminiscence and motivation. Right here, we’ll simply ask a single query: are you able to anticipate an individual whose full-time job is bean counting to be as conscious of trickery as an individual whose full-time job is trickery? And that’s with out delving into the complexities of human reminiscence retention and loss.
Asymmetry is a truth we can’t change and might solely scale back with a limitless funds. Predicting the longer term is essentially inconceivable and by no means long run. Psychology, nonetheless, is present. We will be taught and enhance from it.
The psychology of consciousness coaching
To discover this angle of safety consciousness coaching, we talked to cognitive psychologist Jordan Richard Schoenherr, PhD, a scientist at Humanix and adjunct professor on the College of New South Wales.
Schoenherr’s perception is that safety consciousness coaching is essentially not working. That’s to not say it can’t work, or not less than be improved, however it’s tough owing to the complexities of the human thoughts and reminiscence. The aim of consciousness is to instill info into long-term reminiscence, coupled with the right behavioral response to that reminiscence. However, feedback Schoenherr, “Forgetting (or entropy) is the default state of reminiscence – and it happens quickly.”
Often refreshing the educational is important to keep up that reminiscence. Even when that is profitable, “It doesn’t essentially imply that somebody goes to know, within the second, when and the place to make use of it. So, the complementary method, behavioral nudges, makes an attempt to reactivate that info in a selected context.”
So, the topic of the coaching should be capable to acknowledge a state of affairs, relate the state of affairs to long-term risky reminiscence and activate it within the current, whereas recalling the right behavioral response (settle for, ignore, report, etcetera).
This coaching should essentially educate the scholar how you can acknowledge a phish. Such coaching is essentially, of necessity, restricted to identified social engineering patterns – and that in itself might be problematic.
For illustration functions solely, if the coaching is restricted to recognition of the previous ‘Nigerian scams’ and riddled with spelling and grammatical errors, ‘Nigerian scams’ can be simply acknowledged. The hazard is {that a} lack of those flags could be translated as proof of validity. The truth, in fact, is that the absence of proof is just not proof of absence; and that applies to all consciousness coaching.

So, a serious precedence for the coaching is that it should be up-to-date with present social engineering practices. The issue right here is that up-to-date immediately could also be historic subsequent week.
We all know that criminals change and adapt their assault processes quickly. There isn’t a assure that coaching on identified strategies can put together folks for social engineers’ newest disruptive improvements. Coaching for disruptive improvements requires predicting the longer term, which is one thing each trainers and cybersecurity distributors persistently try. Predicting the longer term is feasible (in any other case we wouldn’t have folks being profitable on buying and selling shares and shares), however it’s tough, by no means assured, and possibly short-term solely.
Schoenherr explains: “Once we give folks artistic duties [such as predicting the future], it mainly prompts two major areas of the mind, the inferior temporal lobe the place long-term recollections are saved, and the prefrontal cortex for govt features. All of the constructing blocks in your reminiscence are getting pulled into that prefrontal cortex, which is making an attempt to rearrange them, manipulate, and provide you with what we might name a psychological mannequin. The extent to which that psychological mannequin goes to work or not relies on analogical reasoning. Discover the best form in your long-term reminiscence, or reconstruct one that appears just like the state of affairs, and predict into the longer term.”
(That is mainly the identical psychological course of utilized by an worker questioning if a communication is legitimate or malicious.)
Again to the longer term, we all know from inventory analysts that this may be performed for the brief time period, however we additionally know that these predictions are poorly calibrated for the long run. “Within the brief run, yow will discover folks which might be very efficient at predicting the state of the world as a result of they’re conscious of the variables that exist,” he continued. “They appear to have some sort of magical trick. It’s not magic; it’s as a result of they’ve a psychological mannequin which is congruent with the state of affairs. However then new variables come into play, they usually lose the recent streak of prediction.”
So, can a corporation predict the longer term? Sure. Will these predictions and plans based mostly on them be efficient? Relies upon how effectively the group handles and incorporates what is called ‘resolution making beneath deep uncertainty’. “The choice-making beneath deep uncertainty method assumes it’s best to develop as many potential situations as attainable based mostly on the variables you will have, after which run simulations to see which situation produces the very best outcomes throughout many various iterations. That ‘finest consequence’ is the situation that you simply’re going to run with.”
It’s the situation wanted to foretell possible/attainable future kinds of social engineering. “Will probably be imperfect, it is not going to essentially predict the state of the world completely, however it is advisable to construct up these situations,” Schoenherr continued. However it’s tough. “Folks will all the time be combating the final battle and are usually not essentially able to pondering what is going to occur sooner or later.”
Cognitive psychology helps us perceive how you can navigate the complexities of sustaining and retrieving recollections, and the way finest to undertaking present information to foretell probably future situations – each of that are important for efficient consciousness coaching.
Abstract
Understanding the psychology of cognition can’t resolve the asymmetry of the social engineering menace. That may solely be solved or diminished with a limitless safety funds when most budgets are maintained on the minimal attainable. It may well, nonetheless, help in predicting the longer term route of social engineering. Extra notably, nonetheless, it may well assist in the design of consciousness coaching methodologies more likely to be more practical.
Combining classes realized by way of present consciousness coaching (consciousness coaching and behavioral conditioning backed by refresh frequency and know-how) with the human cognitive processes we be taught from science, may also help us develop new or improved coaching. It’s going to by no means be excellent, however consciousness coaching can’t be deserted. And it may well all the time be improved.
Associated: CyberNut Closes $5M Development Capital for Ok-12 Safety Consciousness Coaching
Associated: Jericho Safety Will get $15 Million for AI-Powered Consciousness Coaching
Associated: Vista Fairness Companions to Purchase Safety Consciousness Coaching Agency KnowBe4 for $4.6B
Associated: Huntress Acquires Safety Consciousness Coaching Startup Curricula for $22M








