Research • Cyber-Specific Evidence
Cyber Security Awareness Training Statistics That Matter
Not a hunch. Not an opinion. A randomised controlled study of 19,500 employees found annual cyber security training had no measurable impact on phishing susceptibility. Then somebody reproduced it across another 12,511 people. The data is in. Here's what it says.
The Behaviour Cycle White Paper ⋅ Research Series
1.7%
The average difference in phishing susceptibility between employees who had completed annual cyber security training and those who hadn't. Not a typo. After all the modules, all the completions, all the certificates... 1.7%. That is not a training programme. That is an audit trail with a compliance budget attached.
Ho et al. (2025). UC San Diego / University of Chicago. Randomised controlled study, n=19,500 employees.
0
Significant effects. That's what happened when the same test was run again across another 12,511 employees, at a different company, in a different sector, with a control group that got no training at all. Not a small effect. None. No significant effect on how many people clicked or reported. The paper? Anti-Phishing Training (Still) Does Not Work.
Rozema & Davis (2025). arXiv preprint 2506.19899. v3 October 2025. n=12,511.
81%
of UK businesses ran no staff training or awareness activity whatsoever last year. Not bad training. None. And the figure hasn't budged in a year. So, before anyone concludes that the industry has a quality problem, notice that it also has a turning-up problem too.
Department for Science, Innovation and Technology (2026). Cyber Security Breaches Survey 2025/26. 2,112 UK businesses. 1,085 charities.
The most rigorous study ever done on annual training found it doesn't work.
The first study followed 19,500 employees at a large healthcare organisation for eight months, with randomised assignment, real phishing attempts and actual click data. Not a survey. Not self-report. Behaviour.
The difference between the trained and untrained was 1.7%.
One study is arguable, and it should be. So again, in 2025, two researchers ran the same study somewhere else entirely, added a control group, and this time scored every fake email for how convincing it was, using a standard scale published by NIST. Their finding, in their own words:
Training interventions showed no significant main effects on click rates.. or reporting rates, with negligible side effect sizes.
What did predict clicking? How good the fake was. The most obvious ones caught 7% of people. The most convincing caught 15%.
Two studies, more than 32,000 employees, and the same answer: How good the attack was mattered. Whether people had been trained didn't.
61%
fail the test after training
Completion rates measure attendance, not learning
61% of employees fail a basic security knowledge test after completing mandatory training. Not before. After. The module ran, the certificate was issued, the dashboard went green, and more than half of them can't answer seven basic questions.
A completion rate tells you a video finished playing.
Epignosis (2023). n=1,200 US employees.
4%
of people, 80% of clicks
4% of your people are causing 80% of the phishing clicks
Risk does not spread evenly across a workforce, it clusters, and the concentration is far tighter than the familiar version of this statistic suggests.
The primary research, a Cyentia Institute study of 15.1 million security events across 168,000 people and more than 3,800 organisational departments over six years, found that 4% of people are responsible 80% of the actual clicks of phishing emails that occur. Their words: it is "a little bit worse than just the 80/20 rules for phishing clicks, it's more like the 80/4 rule."
The good news in the same dataset is worth saying: 76% of people have never clicked a phishing email, and 93% have never had a malware incident. Most of your workforce is not the problem.
Annual training reaches that 4% in exactly the same way it reaches the 76% who never really needed it. Once, in a format they will forget.
Uniform delivery cannot address concentrated risk, and a completion rate cannot even see it.
Cyentia Institute. The Size and Shape of Workforce Risk, based on data provided by Elevate Security. 15.1m events. 168k people. 3,800+ departments. January 2016 to December 2021.
+40%
mobile vectors vs email
Social engineering is designed to bypass training, and it isn't only email anymore
Social engineering exploits urgency, authority and trust, which are the same instincts that make people good colleagues. It doesn't wait for you to be alert. It arrives when you're busy and it looks almost right.
It also stopped being one channel. Phishing arrives by email, smishing by text, vishing by phone, and the same attack can run across all three. Social engineering is Verizon's third most common breach pattern in 2026, accounting for 16% of all breaches.
And it has moved to channels nobody rehearses. In simulations, the median rate of successful click rates in mobile-centric vectors (i.e. text and voice), is 40% higher than via email. Your people have practiced being suspicious of their inbox. They haven't practiced being suspicious of their phone ringing.
A module teaches recognition. Recognition is not the thing that fails.
Verizon (2026). Data Breach Investigations Report.
4.2%
clicking after 12 months
Frequency changes the numbers. Design changes them more.
Continuous simulation does move the figures. KnowBe4's 2026 dataset shows an average starting point of 33.2% of people clicking, falling to 20.1% after ninety days and 4.2% after twelve months.
It's worth looking at how that gets delivered though, because the intuitive design might not be the best one. Three randomised field experiments published in MIS Quarterly found that training delivered at the point of failure, to the people who clicked, appears effective in laboratory settings but shows mixed or negative results in real-world implementations, partly because people get defensive when they've just been caught. Delayed feedback, sent to everyone rather than only the failures, worked better.
So the answer is more often, to everyone, without the ambush.
KnowBe4 (2026). Phishing by Industry Benchmarking Report. 7 July 2026. Yin, D. et al. (2026). MIS Quarterly, 50(2), 767-786, published 31 May 2026.
The Finding
annual training makes no measurable difference. two studies, 32,000 people. one answer.
In March 2026, the US Army cut mandatory cyber security training from once to every five years. Not because they stopped caring about cyber security. Because the annual model wasn't doing anything, and pretending otherwise cost them time they needed elsewhere.
This is the most honest thing any large organisation has done with this evidence.
Ho et al. (2025) n=19,500 • Rozema & Davis (2025) n=12,511 • DefenseScoop (2026)
The gap isn't between organisations that train and those that don't. It's between formats.
Every organisation we walk into has content. Modules, posters, an intranet page, a policy nobody has opened since induction. The library is almost never the gap.
What they don't have is a single occasion in the year where their people make security decisions under time pressure, in front of colleagues, and then find out what it cost them.
That is the difference between knowing and doing. Your people already know not to click the link. They knew it last year too.
Your people deserve more than a module.
If this research has landed, let's talk about what a different approach looks like for your organisation.
Research sources
Ho, G. et al. (2025). Understanding the Efficacy of Phishing Training in Practice and Black Hat. UC San Diego / University of Chicago. n=19,500.
Department for Science, Innovation and Technology (2026). Cyber Security Breaches Survey 2025/26. UK Government official statistics, 30 April 2026.
Cyentia Institute. They Size and Shape of Workforce Risk, based on data provided by Elevate Security. 15.1m events. 168,000 people. 3,800+ departments. January 2016 to December 2021.
Verizon (2026). Data Breach Investigations Report. Published 19 May 2026.
KnowBe4 (2026). Phishing by Industry Benchmarking Report. Published 7 July 2026.
Rozema, A.T. & Davis, J.C. (2025). Anti-Phishing Training (Still) Does Not Work: A Large-Scale Reproduction of Phishing Training Inefficacy Grounded in the NIST Phish Scale. arXiv:2506.19899 (v3. October 2025). n=12,511. CC BY-NC-SA 4.0.
Yin, D., Mullarkey, M.T., de Vreede, G-J. & Limayem, M. (2026). Learning by Phishing via Post-Simulation Feedback: From Embedded to Non-Embedded Training. MIS Quarterly, 50(2), 767-784. Published 31 May 2026.
DefenseScoop (2026). US Army reduces mandatory cybersecurity training to once every five years. March 2026.
Epignosis (2023). Cybersecurity Training Survey. n=1,200 US employees.
The Behaviour Formula White Paper • Research Series