Revamping Security Awareness Training: Essential Strategies for 2023
Security awareness training remains a critical component of enterprise security, but its effectiveness is under scrutiny as cyber threats evolve.
Compliance-Driven Approaches
The prevailing view is that awareness training is essential but often poorly executed, with issues not always stemming from organizational shortcomings. Stefan Dasic, a senior malware research engineer at Malwarebytes, argues that most training programs fail due to their repetitive and generic nature, which diminishes perceived value. He highlights that some repetition arises from compliance and insurance mandates requiring identical content to be delivered annually to all employees, regardless of prior knowledge. This approach risks reducing training to a mere regulatory checkbox.
Stefan Dasic’s Perspective
Stefan Dasic emphasizes that compliance-driven training often prioritizes checkbox completion over behavioral change, which may explain why some studies show minimal or no impact despite high completion rates.
Effectiveness in Specific Contexts
Drew Thompson, global lead for training and enablement at UltraViolet Cyber, acknowledges that awareness training can be effective but primarily for scenarios directly addressed in the curriculum. He emphasizes that attackers constantly evolve their methods, while training often lags behind by relying on known threats.
Mike Lyman’s Critique
Mike Lyman, a senior security consultant at Black Duck, illustrates this issue through the example of identical courses repeated across multiple employers, describing it as “training-as-compliance-theater.” This model prioritizes checkbox completion over behavioral change, which may explain why some studies show minimal or no impact despite high completion rates.
Modern Threats and Technological Solutions
Josh Bartolomie, VP of global threat intelligence at Doppel, agrees that training remains relevant but notes that many organizations expect it to address a rapidly changing threat landscape. Thompson advocates for more frequent training that aligns with emerging attack patterns, incorporates behavioral guidance for responding to suspicious communications, and integrates with employees’ specific roles.
Jim Dolce’s Concerns
Jim Dolce, CEO at Lookout, acknowledges the utility of training but highlights its limitations in the current mobile AI threat environment. He contends that training employees to act as a “human firewall” is outdated in a landscape dominated by AI-driven attacks.
Frontier AI has transformed the threat landscape by enabling hyper-personalized phishing and voice cloning across mobile channels at unprecedented speed. Dolce asserts that training is fundamentally outmatched by these advancements, as it cannot address structural architectural challenges.
Challenges in Sustaining Behavioral Change
Mike Aalto, co-founder and CEO at Hoxhunt, cites a 14-fold increase in AI-generated phishing attacks between 2025 and 2026. He notes that the shift lies not in novel tactics but in the modernization of traditional attacks, with phishing kits now featuring improved formatting, language, and personalized messaging at scale. This evolution turns defense into a “whack-a-mole” game, with attackers generating more sophisticated threats at greater speed.
Sanny Liao’s Criticism
Sanny Liao, co-founder and CPO at Fable Security, criticizes current training as ineffective, arguing that social engineering succeeds by exploiting context, timing, and psychological factors. She suggests drawing inspiration from adtech, which excels at influencing behavior through context-aware messaging.
Psychological and Cognitive Challenges
Biswajit De of CleanStart explains that attackers require only a single lapse from a distracted employee, emphasizing the difficulty of maintaining constant vigilance. Jordan Richard Schoenherr, a cognitive psychologist at Humanix, highlights that memory retention is inherently unstable, with information fading quickly without reinforcement.
Future Threat Prediction
Schoenherr explains that while short-term predictions are possible, long-term accuracy remains uncertain. He advocates for scenario-based planning under “deep uncertainty,” simulating potential future attack vectors to inform training strategies.
Conclusion
Despite these challenges, awareness training cannot be abandoned. While it cannot resolve the inherent asymmetry of social engineering, it can be improved through methods that align with cognitive science, behavioral conditioning, and technological integration. Continuous refinement of training programs, combined with proactive security measures, remains essential for mitigating evolving threats.
