Security awareness training that actually changes behaviour
An annual video and a quiz will get you a completion certificate. It won't change what someone does when a convincing email lands in their inbox at 4:45 on a Friday.
Research into security training keeps landing on the same uncomfortable finding: knowledge and behaviour aren't the same thing. Staff can pass a quiz on what phishing looks like and still click the next realistic attempt, because the training built recognition in a calm moment, not the instinctive response needed under pressure. One review of dozens of workplace studies found that while awareness and attitudes improve after training, measurable changes in actual behaviour are often minimal.
Why the once-a-year video falls short
A single annual session, delivered as a compliance box to tick, tends to produce exactly that: compliance, not resilience. Independent research has found that generic awareness training on its own can reduce phishing click rates only modestly unless it's reinforced by continuous practice and a wider culture shift. Knowledge fades within months; a live phishing attempt doesn't wait for the next refresher.
What actually moves the needle
Programmes that run continuous, realistic phishing simulations — rather than a single test once a year — see phish-prone rates drop dramatically over twelve months, and organisations that measure whether staff report suspicious emails, not just whether they avoided clicking, tend to see reporting rates roughly double compared with completion-based training. The shift is from "did they finish the module" to "what do they actually do when something suspicious lands."
What we run with our workshop clients
Instead of a single annual session, we run short, role-based workshops built around the phishing and social-engineering attempts staff are actually seeing — not generic, three-year-old examples. We pair that with regular, unannounced simulations reflecting real channels: email, SMS, and the kind of urgent "please approve this payment" message that doesn't look like a typical phishing template at all. The goal isn't to catch people out; it's to make reporting something suspicious feel normal and easy, with zero stigma attached to raising a hand.
Measuring what matters
We track reporting rates and simulation outcomes over time rather than certificates issued, because that's the number that actually tells you whether behaviour changed. It also gives leadership a concrete, ongoing figure to look at rather than a once-a-year tick in a compliance spreadsheet.
Keep reading
_____