Security

Cybersecurity Awareness Training: Why Simulations Beat Lectures

One in three employees with no recent security training will click a simulated phishing link today

AJ
Alberte Jespersen
Marketing · Jul 9, 2026 · 12 min read
Cybersecurity team running phishing simulations and security awareness training in a modern workplace.

Cybersecurity Awareness Training: Why Simulations Beat Lectures

One in three employees with no recent security training will click a simulated phishing link today. That statistic, from KnowBe4's 2025 research benchmarks, has barely changed in a decade, not because organizations are not running cybersecurity awareness training, but because most are running the wrong kind.

The annual compliance lecture, a sixty-minute module completed once a year, filed against an audit requirement, and largely forgotten by February, is still the dominant format. It satisfies the checkbox. It does not change behavior. And in a threat environment where AI-generated phishing emails now account for 82.6% of attacks and achieve click-through rates four times higher than traditional lures (CrowdStrike Global Threat Report 2025), behavior is exactly what needs to change.

This article explains why passive training fails at the cognitive level, what phishing simulations do differently, and how to build cybersecurity awareness training that makes a measurable difference to risk, not just to dashboards.

Why the annual lecture doesn't work

The failure is not a motivation problem. It is a memory problem.

In the 1880s, psychologist Hermann Ebbinghaus documented what became known as the forgetting curve: memory decays rapidly in the first hours and days after learning unless it is reinforced. A single long session produces a spike in knowledge that fades quickly. Applied to cybersecurity training, this means an employee who completes a sixty-minute phishing module in January and encounters a spear-phishing email in October has retained very little of what they were taught. That is not because they were not paying attention; it is simply how unrefreshed memory works.

The second failure is cognitive load. Dense compliance modules that try to cover every threat vector in one sitting overwhelm the brain's ability to encode information effectively. When too much competes for attention at once, the brain filters aggressively, and much of the material never sticks in the first place. Covering more content in fewer sessions is not more efficient if the information never lands.

The third failure is the doing gap. A Gartner survey of more than 1,300 employees found that 69% had bypassed cybersecurity guidance in the previous twelve months, and 74% said they would bypass it in the future when under pressure. The problem is not that employees do not know the policy. It is that knowing a policy and applying a practiced instinct under the cognitive stress of a real attack are fundamentally different skills. Lectures can teach the former. Only repeated practice builds the latter.

The scale of the threat, and why it keeps growing

According to the Anti-Phishing Working Group (APWG), more than one million phishing attacks were recorded in the first quarter of 2025 alone, and the figure grew quarter on quarter. According to the Verizon 2026 Data Breach Investigations Report, the human element is involved in 62% of breaches, with phishing remaining the number one initial access vector across all industries. The average data breach now costs $4.44 million (IBM Cost of a Data Breach Report 2025), while the average Business Email Compromise attack — the kind that impersonates an executive or supplier, costs $4.67 million.

What has changed most sharply is the quality of the attacks. AI-generated phishing emails achieve a 54% success rate against human targets, roughly four and a half times the rate of human-written attacks (CrowdStrike 2025). Deepfake voice calls have stolen $25 million in a single incident, while vishing activity surged 442% between the first and second halves of 2024. An organization whose employees were trained against 2023-style, email-only phishing is not prepared for what is landing in inboxes, voicemails, and text messages today.

According to ENISA's Threat Landscape 2025, more than 80% of phishing emails analyzed between late 2024 and early 2025 used AI to some extent. That makes practiced recognition a practical necessity rather than a theoretical benefit.

What phishing simulations do that lectures cannot

A phishing simulation is not simply a more engaging version of a lecture. It is a different category of intervention entirely, and it works for reasons rooted in how the brain consolidates skills rather than facts.

Active learning vs. passive reception. A lecture delivers information and expects employees to encode it. A simulation places employees inside a realistic attack and requires a judgment call with immediate consequences. Research across hundreds of studies consistently shows that active learning outperforms passive instruction for retention and application. A 2014 meta-analysis published in the Proceedings of the National Academy of Sciences found that students in traditional lecture formats were 1.5 times more likely to fail assessments than those in active learning conditions, a gap that applies just as clearly to security training. We explored the broader case for active, scenario-based training in more depth in our guide to interactive learning.

Feedback at the moment of highest attention. When an employee clicks a simulated phishing link and immediately receives coaching on what made it suspicious, the lesson arrives at the exact moment they are most cognitively engaged. Annual training, by definition, cannot be timed that way. A calendar-scheduled module is unrelated to an individual's current threat experience. Learning is weakest in a neutral state and strongest immediately after a near miss.

Spaced reinforcement that fights the forgetting curve. Monthly simulations spread practice across the year rather than cramming it into one session, exactly the pattern the spacing effect predicts will produce durable memory. Verizon's 2025 DBIR found that employees trained within the previous thirty days were four times more likely to report a phishing attempt than those without recent training. That drop-off is steep and fast, so a quarterly or annual cadence cannot sustain anything close to the same level of readiness. The same dynamic applies across all compliance training; our piece on what actually drives retention explains the underlying science in more detail.

What the numbers show

The outcomes are consistent across research sources.

Comprehensive security awareness training combined with ongoing simulations reduces phishing susceptibility from an industry baseline of approximately 33% to under 5% over twelve months, a reduction of more than 85%, according to KnowBe4's 2025 research. For North American organizations specifically, the baseline phish-prone rate is 37.1%; after twelve months of simulation-based training, it falls to approximately 4.1%. Organizations running monthly phishing simulations with immediate feedback see a 70–80% improvement within six months. Real-threat detection, employees correctly identifying and reporting genuine attacks, climbs from 13% to 71% across the training curve in Hoxhunt's 2026 Phishing Trends Report.

The comparison is clear. Lecture-only training may meet a compliance requirement, but it typically produces little lasting change in phishing susceptibility, retention, or real-threat reporting. Simulation-based training starts from the same risk baseline, yet ongoing practice and immediate feedback can reduce phish-prone rates to around 4–5% after twelve months, strengthen retention through monthly reinforcement, and raise real-threat reporting rates to as high as 71%.

What effective simulation-based training actually looks like

The evidence supports a clear structure: monthly simulations, immediate remediation after failure, modules under ten minutes, and role-based scenarios rather than generic content.

Role alignment matters more than most security teams realize. Finance teams face invoice fraud and payment diversion. Executives face deepfake voice calls and executive impersonation. IT staff face credential-reset spear-phishing. A simulation built around the attacks a role actually attracts produces stronger outcomes than a generic module delivered uniformly across the workforce. CISA's phishing guidance and the NIST SP 800-50 framework both emphasize role-specific content as a core requirement of effective programs.

Multi-channel coverage is no longer optional. Email-only simulations prepared employees for the threat landscape of 2015. Vishing, smishing, QR code phishing, and AI-generated deepfake video are all active attack channels today. A training program that ignores those channels leaves a gap that attackers are actively exploiting.

Immediate feedback is essential. A remediation module delivered three weeks after a failed simulation has already lost much of its effect. The coaching moment needs to sit directly on top of the near miss: automated micro-training triggered the instant someone clicks, not a scheduled session later in the month. Short modules under ten minutes, triggered automatically, are remembered far more effectively than longer content delivered at a neutral moment. This is exactly where the principles of spaced microlearning, which we covered in our piece on microlearning versus traditional courses, apply most directly to security training.

Building cybersecurity training your team will actually finish

The research case for simulation-based training is strong. The practical barrier for most organizations is production time. Building realistic, engaging, role-specific training scenarios at scale takes significant effort, and the security or HR teams running these programs rarely have time to spare.

Most organizations already have the knowledge they need. Acceptable-use policies, incident response playbooks, phishing examples already documented by the IT team, and recent security bulletins are ready-made source material for effective cybersecurity training. The challenge is turning that existing knowledge into something employees will engage with. That is precisely the problem AI course creators like Saga are built to solve: give it an existing document, and it turns the content into a structured, interactive course in minutes, with quizzes, scenarios, and knowledge checks built in.

Saga's chat-based roleplay scenarios are a natural fit for social engineering training. They put employees in the position of responding to a suspicious request in real time rather than reading about how they should respond in theory. Swipe-format recognition drills are well suited to building the fast pattern recognition needed to distinguish a suspicious sender address from a legitimate one under time pressure. And because Saga supports 50+ languages with context-aware translation, a single cybersecurity module can be authored once and used across an entire global workforce without separate content for each locale.

Keeping cybersecurity training current matters too. Threat landscapes shift from month to month, and a program that takes weeks to update will always lag behind the real attack surface. Turning updated policies or new phishing examples into a refreshed training module in minutes — as Saga makes practical — means the content employees see can stay close to real-world threats instead of reflecting last year's patterns. Templates for common cybersecurity training scenarios are also available as a starting point, so you do not need to begin with a blank page. Saga generates two free courses for waitlist members.

What to measure: beyond the completion dashboard

Completion rates confirm that employees opened a module. They do not confirm that anything changed.

The metrics that show whether a program is working are behavioral. The trend in phishing click rates over time, rather than a single point-in-time result, which is easy to game by making simulations easier — shows whether susceptibility is genuinely declining. Report rate shows whether employees are developing the instinct to flag suspicious messages instead of ignoring them or clicking quietly and hoping for the best. Time to report measures how quickly a potential incident reaches the team that can contain it: the shorter the gap between a phishing email arriving and an employee flagging it, the smaller the window for damage.

A program that shows falling click rates, improving report rates, and fewer repeat clickers tells leadership a fundamentally different story from one that presents completion percentages. The former shows risk reduction. The latter shows training attendance.

Frequently asked questions

Why doesn't annual cybersecurity training reduce phishing click rates?

The Ebbinghaus forgetting curve explains most of it: without reinforcement, memory of what was learned decays rapidly in the hours and days after a training session. A single annual module produces a knowledge spike that fades long before the next phishing attack arrives. Effective programs use monthly simulations and short reinforcement modules to keep recognition skills sharp throughout the year.

How much does phishing simulation training actually reduce click rates?

KnowBe4's 2025 research shows that comprehensive simulation-based training reduces the industry-average phish-prone rate from approximately 33% to under 5% over twelve months. For North American organizations specifically, the rate falls from 37.1% to approximately 4.1% — an 89% reduction.

How often should phishing simulations run?

Monthly is the cadence most consistently supported by the research. Verizon's 2025 DBIR found that employees trained within the previous thirty days were four times more likely to report a phishing attempt than those without recent training. Quarterly or annual cadences cannot maintain that level of readiness.

Do simulations need to cover more than email?

Yes. AI-generated phishing, vishing, smishing, and deepfake video are all active attack channels. Email-only simulations train people to recognize the attack surface of a decade ago. ENISA's Threat Landscape 2025 documents phishing as the dominant initial access method across EU organizations, with the channel mix extending well beyond email.

What is the right way to measure a cybersecurity awareness training program?

Completion rates measure attendance. The metrics that map to real risk reduction are the phishing click-rate trend over time, employee report rate, time to report, and repeat-clicker reduction. A program that improves those numbers is reducing breach probability; one that only improves completion rates is not.

How can we keep training content current without a large time investment?

AI course creation tools make continuous updates practical. Updated security policies, new phishing examples, or revised incident procedures can be turned into a refreshed interactive training module in minutes, without a full content-production effort each time the threat landscape shifts.

Build cybersecurity training that changes behavior

Completing a module is not the same as recognizing a phishing attempt under pressure. Simulation-based training, frequent, realistic, role-specific, and built around immediate feedback, closes that gap in a way annual lectures cannot.

The production barrier that once made scenario-based training difficult to sustain at scale is smaller than it used to be. Saga turns existing security policies, incident playbooks, and phishing examples into interactive, scenario-driven cybersecurity courses in minutes — with roleplay scenarios, recognition drills, and knowledge checks built in for active recall. Waitlist members get two free AI course generations.

// Keep reading

Get the occasional good email.

New writing on AI, learning design and building Saga — roughly twice a month. No spam, unsubscribe anytime.