Cybersecurity awareness training teaches staff to recognise and report threats such as phishing and social engineering. The 2026 benchmark data shows it works: continuous training cuts phishing susceptibility substantially over twelve months. The catch is that the effect fades within roughly six months without reinforcement, so an annual one-off course is the least effective format.
Why this training exists, in one number
The Verizon 2026 Data Breach Investigations Report found the human element involved in 62 percent of breaches, up slightly from 60 percent the previous year. That number has stayed stubbornly around six in ten for years, even as awareness training became near-universal and technical controls improved.
That gap between effort and outcome is the interesting part. Most organizations already run security awareness training. Far fewer run it in the format the evidence says actually changes behaviour. This guide covers what the 2026 data shows, and what to do differently.
| One myth worth killing first: you will often see 'ninety-five percent of breaches are caused by human error'. That figure comes from a garbled citation chain and is not defensible. The precisely defined number is Verizon's 62 percent human element. If a vendor leads with the ninety-five percent stat, treat the rest of their claims carefully. |
What the benchmark data actually shows
The most useful measure in this field is the phish-prone percentage, meaning the share of employees who click, open or otherwise engage with a simulated phishing test. KnowBe4's 2026 Phishing by Industry Benchmarking Report, drawn from millions of simulated tests, gives the clearest picture:
- Before any training, the global average phish-prone percentage is 33.2 percent. If a phishing email gets past your filters today, roughly one in three staff are likely to engage with it.
- Large enterprises of ten thousand or more people run higher, at 39.5 percent, and large healthcare environments peak around 54 percent.
- Within ninety days of introducing training, the global average drops about 40 percent, from 33.2 to roughly 20.1 percent.
- After twelve months of continuous training, it falls to around 4 percent, an approximately 86 percent reduction from baseline.
- Healthcare and pharmaceuticals (42.7 percent), insurance (38.1 percent) and retail and wholesale carry the highest baseline vulnerability.
So the training works, and it works dramatically. The word doing the heavy lifting is continuous.
The finding that should reshape your programme

Peer-reviewed field research published at USENIX SOUPS found that the effects of security awareness training fade back toward baseline in roughly six months, and recommended reinforcement at least every six months. The same research found video-based and interactive refreshers worked best.
Read that alongside the benchmark data and the conclusion is uncomfortable for most programmes: if you train everyone once a year, your workforce spends roughly half of each year drifting back toward its untrained state. The annual compliance course is the format most organizations run, and it is close to the least effective one available.
- Reinforce at least every six months, not annually.
- Prefer short, interactive or video-based refreshers over long once-yearly modules.
- Measure reporting rates, not just completion rates. Programmes that change behaviour push reporting well above the roughly ten percent typical of completion-driven training.
- Treat it as a security control you measure continuously, not a course you tick off.
What the threat landscape now demands you cover
The content most awareness programmes were built around is dating quickly. A few 2026 realities worth reflecting in your curriculum:
- AI-generated phishing. Microsoft research found AI-written phishing achieving substantially higher click rates than human-written attempts, and independent simulations show AI-generated messages matching or exceeding expert human attackers. The old advice about spotting bad grammar is now actively misleading.
- Speed. The median time between a phishing email being opened and the malicious link being clicked is about 21 seconds. There is no window for someone to think it over and consult IT afterwards.
- Third-party risk. Verizon's data shows third-party involvement in breaches climbing sharply year over year, meaning you inherit your suppliers' knowledge gaps. Awareness content should cover supplier and vendor scenarios, not just inbox basics.
- Voice and help-desk channels. Attacks have moved beyond email to phone-based social engineering and help-desk manipulation, including deepfaked voice.
- Credential abuse. It remains a leading initial access vector, so password and MFA behaviour deserves as much attention as phishing recognition.
How to structure a programme that holds
- Baseline first. Run a simulated phishing test before training so you know your starting phish-prone percentage and can prove change later.
- Train on joining. New starters should receive awareness training as part of onboarding, not at the next annual cycle.
- Reinforce every six months at minimum, using short interactive content rather than repeating the full course.
- Run simulations continuously, and treat a click as a teaching moment rather than a disciplinary one. Programmes that punish clicking suppress reporting, which is the opposite of what you need.
- Track reporting rate as your headline metric, alongside phish-prone percentage.
- Keep records of who completed what and when, since security awareness training is mandated under several regulatory regimes and you may need to evidence it.
The bottom line
The evidence on cybersecurity awareness training is genuinely encouraging: continuous programmes cut phishing susceptibility from roughly a third of staff to a few percent over a year. But the same evidence is blunt about format. Effects fade toward baseline within about six months, so annual training leaves you exposed for half of every year. Baseline your phish-prone rate, train on joining, reinforce at least twice a year with short interactive content, measure reporting rather than completion, and update your material for AI-generated attacks.
MyPass LMS handles the scheduling, automatic reassignment and record-keeping a continuous programme depends on, so six-month reinforcement happens without anyone tracking it manually. See the compliance solution, or start a free trial.
Frequently asked questions
How often should cybersecurity awareness training be done?
At least every six months. Peer-reviewed research found training effects fade back toward baseline in roughly six months without reinforcement, which makes annual-only programmes substantially less effective than continuous ones.
Does security awareness training actually work?
Yes, when it is continuous. Benchmark data shows the global average phish-prone percentage falling from 33.2 percent to roughly 4 percent after twelve months of continuous training, an approximately 86 percent reduction. One-off annual training performs far worse.
What percentage of breaches involve human error?
The defensible figure is Verizon's human element measure, which reached 62 percent of breaches in the 2026 Data Breach Investigations Report. The widely repeated claim that 95 percent of breaches are caused by human error comes from a garbled citation chain and should not be used.
What should cybersecurity awareness training cover in 2026?
AI-generated phishing, since advice about spotting poor grammar no longer applies; speed of attack; third-party and supplier scenarios; voice and help-desk social engineering including deepfakes; and credential and MFA behaviour, since credential abuse remains a leading access vector.
What metric should I use to measure the programme?
Phish-prone percentage from simulations plus threat reporting rate. Completion rate measures activity, not behaviour change. Programmes that genuinely change behaviour show markedly higher reporting rates than completion-driven ones.