You Want Instinct. You’re Funding Awareness.
The evidence is no longer ambiguous: annual awareness training barely changes behaviour. Here's why organisations keep funding it anyway.
There’s a delusion that haunts corporate learning. It sits quietly in boardrooms and budget meetings, wearing the pleasant expression of common sense. It goes like this: give people the right information, in the right order, and they will do the right thing.
It sounds reasonable. It is also demonstrably untrue.
If information changed behaviour, Verizon wouldn’t report year after year that the human element sits behind most breaches. In 2026 that number climbed to 62%, up from 60% the year before. We’d have trained our way out of this a decade ago. Instead, we respond to the number the same way every year: more content. Better platforms. More reminders. More reports. The machine gets more efficient. The outcomes don’t move.
The Paradox
Here’s what’s actually happening inside most organisations right now.
They want behaviour change, but they invest in formats optimised for efficiency, consistency and legal defensibility. They want instinct, but they fund awareness. They want vigilance, but they approve courses engineered for rapid completion. They want a cultural shift, yet they deploy tools designed to meet compliance obligations and nothing else.
That’s the engagement paradox: the gulf between what organisations want people to do and what their learning actually prepares them for.
And compliance, in the psychological sense, is the enemy of memory. The brain is not an obedient filing system. It’s a miser. It hoards energy, not knowledge, and it discards anything that feels dull, safe or distant. Ebbinghaus mapped this in 1885 and a 2015 replication confirmed it still holds: without reinforcement, roughly half of new information is gone within an hour, and up to 90% within a week.
This is why an employee can pass a phishing quiz at 9am and confidently hand over their credentials to a convincing stranger by 3pm. They have knowledge. What they lack is activation.
The Evidence Is No Longer Ambiguous
In 2025, researchers at UC San Diego and the University of Chicago published the most rigorous study ever done on annual security training. Ten phishing campaigns, 19,500 employees, multiple organisations, several years. The measured difference in click rates between employees who had completed mandatory annual training and those who hadn’t was 1.7 percentage points. Within statistical noise. Functionally zero.
The US Army reached the same conclusion independently and cut its mandatory cyber training from annual to once every five years, because its own analysis found no measurable improvement from the annual frequency.
Now the other side of the ledger. KnowBe4’s dataset of 14.5 million users found that continuous, simulation-based training cut phishing susceptibility from 33.1% to 4.1% in twelve months. An 86% reduction.
1.7% versus 86%. That’s not a contradiction in the research. It’s a demonstration of what happens when the format changes.
Why the Bad Version Survives
If annual awareness training doesn’t work, why does every organisation still run it?
Because it’s measurable. Completion rates are easy to capture. Quiz scores are easy to report. A dashboard full of green ticks is easy to show a board that wants reassurance. The system isn’t designed to change behaviour. It’s designed to demonstrate that something was done. And in the gap between those two goals, the risk hides.
Nobody sets out to build a programme that looks good and changes nothing. The intentions are genuine. The investment is real. But when the metric becomes completion rather than capability, the system optimises for the wrong thing. People learn to finish the module. They learn to pass the quiz. The training achieves its own metric perfectly while the actual goal, behaviour under pressure, goes entirely unmeasured.
The dashboards are green. And somewhere in the business, people are making exactly the decisions the training was designed to prevent.
A Different Question
The organisations getting this right have stopped asking whether their people are aware of the risks. They’ve started asking whether their people are ready for them.
That shift sounds subtle. It isn’t. It changes what gets designed, what gets measured, and what gets reported. It moves learning out of the compliance column and into the risk management conversation, where it belongs.
Because you cannot change behaviour by telling people to behave differently. You can only change behaviour by reshaping the moment itself. Training that feels safe rarely produces behaviour that keeps organisations safe. Training that feels alive, relevant, emotional, unpredictable, does.
The question is not whether engagement matters. The evidence settled that. The question is whether organisations are finally ready to design for it.
Stop Training. Start Rehearsing.
See what changing behaviour actually looks like when the stakes feel real.
Book a Session →
