A person using a laptop with a digital lock and cybersecurity graphics displayed on the screen, indicating data protection and security concepts.

Does Employee Cybersecurity Training Actually Work? An Honest Look at the Return

By Jason Russell · August 21, 2026

I have been recommending security awareness training to small businesses for most of my career. I still do. But I want to write the version of this post that the training vendors will not write, because the honest version is more useful to a business owner deciding where to spend money, and because the honest version still lands in favor of doing it.

Here is the short form. Training does not stop people from clicking on things nearly as well as the industry implies. It does something more valuable than that, and it does it cheaply. The trick is knowing which problem you are actually buying a solution to.

Start with the problem, not the product

Every year Verizon publishes its Data Breach Investigations Report, built from confirmed breaches contributed by law enforcement, incident response firms, and security vendors. The 2026 edition analyzed more than 22,000 confirmed breaches, and it found that the human element was present in 62 percent of them. That figure was 60 percent the year before, and it has hovered in the same range for years. Social engineering was the third most common breach pattern overall, and email remained the primary vector for it.

The FBI Internet Crime Complaint Center tells the money side of the same story. In its 2025 Internet Crime Report, IC3 logged more than one million complaints and recorded losses above $20 billion. Business email compromise, the scam where someone impersonates an executive, vendor, or attorney to redirect a payment, accounted for roughly $3.05 billion of that across 24,768 complaints. Divide those numbers and the average reported BEC loss works out to about $123,000 per incident. Phishing and spoofing generated far more complaints, over 191,000, but far smaller losses per incident.

I want to be careful with these figures. The DBIR skews toward organizations large enough to have an incident response contract. IC3 only counts what victims report. Neither dataset is a clean picture of a 20 person accounting firm in Central Florida. But both point the same direction: most breaches run through a person somewhere along the way, and the most expensive single category of loss for a business is one where a person is talked into moving money.

So the question is not whether people are involved. They are. The question is whether training changes what those people do.

The study nobody in my industry likes to bring up

In 2025, researchers from UC San Diego and the University of Chicago published the largest randomized controlled trial of phishing training ever run. It covered roughly 19,500 employees at UC San Diego Health over eight months and ten separate simulated phishing campaigns. It was presented at the IEEE Symposium on Security and Privacy and again at Black Hat. The design matters here. This was not a vendor survey. Employees were randomly assigned to receive or not receive training, which is the only way to isolate what training itself does.

The findings were not kind to the way most companies run these programs:

  • There was no statistically significant relationship between whether an employee had recently completed the annual mandatory awareness training and whether they fell for a phishing email.
  • Embedded training, the pop-up lesson delivered right after someone clicks a simulated phish, reduced the likelihood of clicking by only about two percent in the researchers’ analysis.
  • Around 75 percent of employees who reached the embedded training page spent a minute or less on it. About a third closed it immediately without reading anything.
  • The lure mattered far more than the training. Only 1.8 percent of employees clicked a fake Outlook password reset. Nearly 31 percent clicked a fake update to the vacation policy.

The one bright spot was interactive question and answer training, which the study associated with a meaningful reduction in susceptibility, but only for the minority of employees who fully completed it. The authors also noted that people who voluntarily finish training may already be the people least likely to click, which makes it hard to know how much credit the training deserves.

The study has limits, and the authors say so. It was a single large healthcare organization. Its employees were already receiving regular simulations before the trial began, so the easy gains may have been taken years earlier. The DBIR reports a median click rate on email phishing simulations of about 1.4 percent across its contributors, which suggests the industry as a whole has already pushed email click rates down to a floor. What the UCSD trial shows is that once you are near that floor, more of the same training does not move it further.

The uncomfortable summary: if the goal of your training program is to get employees to stop clicking on phishing emails, the best available evidence says the standard annual module and quarterly simulation will not accomplish much beyond what you have already achieved.

So why do I still recommend it?

Because stopping clicks was never the most valuable thing training does. When I look at the incidents that have actually cost my clients money over the past decade, the failures fall into a few categories, and training is the right tool for most of them. It is just not the tool the vendors advertise.

1. Training turns employees into sensors

A modern email filter catches most phishing before anyone sees it (we covered what filtering does and does not do in Email Filtering for Small Businesses). The problem is the small percentage that gets through, and the fact that a filter cannot tell you it missed something. An employee who forwards a suspicious message to IT can. The DBIR has tracked simulation reporting rates for several years, and the benchmark for a healthy program sits around 20 percent of simulated phish being reported. Most small businesses I onboard are well below that. Many are effectively at zero because nobody has told staff what to do or where to send it.

This is the metric I care about. If four people in a 30 person office get the same convincing invoice email and one of them reports it within ten minutes, we can pull it from the other three mailboxes before anyone acts. That is a measurable reduction in exposure, and it comes almost entirely from training and a one-click report button, not from a smarter filter.

2. Training installs the pause before money moves

Business email compromise usually contains no link and no attachment. It is a well-written message from what looks like a known address asking for a change in wire instructions, a rushed payment, or gift cards for a client event. There is nothing for a filter to detect. There is nothing for an endpoint agent to block. The only control that reliably stops it is a human being who has been taught that any request to move money or change payment details gets verified by phone, using a number already on file, before anything happens.

That is a training outcome. It is also a process outcome, and it works best when the two are bolted together: the training explains why, and a written finance procedure makes the callback mandatory rather than optional. Given that BEC is the second largest loss category IC3 tracks, this single behavior is where I would spend the first training dollar.

3. Training is the only control for phone and text attacks

The 2026 DBIR included voice and text message phishing simulation data at scale for the first time. Phone-centric simulations produced a median engagement rate of about 2 percent versus 1.4 percent for email, a 40 percent difference. The report also found that 41 percent of social engineering breaches involved a vector other than email. Attackers have noticed that email defenses matured and moved to channels where almost no technical control exists. Your phone system does not sandbox a caller claiming to be from your bank. Training is the whole defense on that channel, and most programs still do not cover it.

4. It is required, or close to it

Cyber insurance applications ask whether you run security awareness training and phishing simulations, and answering no affects both eligibility and premiums (see How to Answer Cyber Insurance Renewal Questions Without Voiding Your Policy). HIPAA requires workforce security training for covered entities and business associates. The FTC Safeguards Rule requires it for financial institutions, a category that includes many tax preparers and auto dealers. PCI DSS requires it for anyone handling card data. This is not the most inspiring argument, but for many of my clients it is the deciding one, and there is no reason to pretend otherwise.

5. It changes how fast people admit a mistake

The most expensive incidents I have worked were not the ones where someone clicked. They were the ones where someone clicked, realized it, and said nothing for three days. Attackers who obtain a mailbox typically set up forwarding rules and watch for invoices before they act. Every hour of delay in reporting is an hour of reconnaissance for them. A program that treats mistakes as expected and reporting as the win, rather than shaming the person who clicked, shrinks that window. That is a culture outcome, and it is the reason I tell clients never to publish click rates by name or tie them to performance reviews.

What training will not fix

I owe you the other half of the ledger.

  • It will not close the last two percent. Email click rates plateau. A well-designed lure sent to a distracted person on a busy afternoon will land regardless of how many modules they completed. Plan for that, do not train against it.
  • It will not stop credential theft by itself. When someone does enter their password on a fake login page, the thing that saves them is multifactor authentication, not the training they skipped. Microsoft’s own measurement study found MFA reduced the risk of account compromise by 99.22 percent across its population, and by 98.56 percent even where the password had already leaked.
  • It will not patch your firewall. The 2026 DBIR found that exploitation of software vulnerabilities was the leading initial access method, present in 31 percent of breaches, ahead of stolen credentials. No amount of employee training addresses an unpatched VPN appliance.
  • It will not cover your vendors. Third-party involvement appeared in 48 percent of breaches in the same report, up sharply year over year. Your bookkeeper’s software provider is outside the reach of your training program.
  • It will not substitute for detection. If the plan is that a trained employee will notice the breach, you do not have a plan. Monitoring exists because people miss things.

Where the dollars should go, in order

If a business owner handed me a fixed security budget and asked me to rank spending by evidence, this is the order I would give:

Control What it addresses What the evidence says
Multifactor authentication on every account, phishing-resistant where possible Stolen or phished passwords Over 99 percent reduction in compromise risk (Microsoft measurement study)
Patching, especially internet-facing devices Vulnerability exploitation Top initial access vector at 31 percent of breaches (DBIR 2026)
Email filtering plus a one-click report button Volume of phishing reaching inboxes; speed of response Filters remove the bulk; reporting handles the remainder
Written payment verification procedure Business email compromise Second largest loss category, about $3.05 billion in 2025 (FBI IC3)
Security awareness training, ongoing and multi-channel Reporting behavior, verification habits, phone and text attacks, compliance Weak effect on click rates; strong fit for everything above

Notice where training sits. It is last on the list and it belongs on the list. The controls above it are the ones that make a click survivable. Training is the layer that catches what those controls cannot see, and it is usually the least expensive line on the invoice.

What a program worth paying for looks like

Given all of that, here is what I look for before I put my name on a training program for a client:

  1. Short and frequent beats long and annual. The UCSD trial suggests that recency of an annual module made no difference. Five minutes a month keeps the topic present in a way that a 45 minute session in January does not.
  2. It measures reporting, not just clicking. The number on the dashboard I want is the percentage of simulations reported and how quickly. Click rate is a lagging vanity metric once you are near the floor.
  3. It includes phone and text scenarios. If the simulations are email only, they are testing the channel your people already handle best and ignoring the one attackers are moving toward.
  4. It is tied to a procedure. Finance and anyone with payment authority gets role-specific content and a written callback rule. The two reinforce each other.
  5. It never shames anyone. No names on reports, no performance consequences for clicking, and a clear message that reporting a mistake is the desired behavior. The goal is a faster phone call to IT, not a quieter office.
  6. It runs alongside the technical controls, not instead of them. If a vendor tells you training is your first line of defense, ask them what the second line is. If they do not have a good answer, keep looking.

A note on our own interest

Harmony MSP includes security awareness training in every managed service agreement. We do not sell it separately and we do not upsell it. I want to be plain about why. It is inexpensive for us to deliver, and a client whose staff reports phishing quickly and verifies payment changes by phone generates fewer emergency tickets and fewer incident response bills. That is good for the client and good for our margins. Both things are true, and I would rather say so than dress it up as pure principle.

What we will not do is tell you that training is the fix. It is one layer, with a specific job, and the research is clear enough about that job that I see no reason to oversell it.

Where to start

If you have never run a program, you do not need to buy anything this week. Tell your team where to forward suspicious emails and that reporting is always the right call. Write down a rule that no payment detail changes without a phone call to a known number. Confirm multifactor authentication is on for email. Those three steps cost nothing and cover more ground than most paid programs.

If you would like a second opinion on where training fits in your current setup, or you want to know what your reporting rate actually is, we are happy to talk it through. Harmony MSP works with small businesses across Lake Mary, Orlando, and Central Florida. Call us at (407) 720-6540.

Frequently asked questions

Does security awareness training reduce phishing clicks?

Not by much once a company is past the basics. The largest randomized trial to date, covering 19,500 employees, found no significant effect from annual training and about a two percent reduction from embedded training. Industry-wide median click rates on email simulations sit near 1.4 percent, which suggests most organizations are already at the floor.

Then why run training at all?

Because clicking is not the behavior that matters most. Training raises the rate at which employees report suspicious messages, installs the habit of verifying payment changes by phone, and is the only defense for voice and text message attacks that never touch an email filter. It is also required by HIPAA, the FTC Safeguards Rule, PCI DSS, and most cyber insurance carriers.

How often should employees receive cybersecurity training?

Short and frequent works better than long and annual. A few minutes each month, mixed with simulations across email, text, and phone, keeps the topic current. The research suggests that how recently someone completed a 45 minute annual module has no measurable effect.

Should I tie phishing simulation results to performance reviews?

No. Shame slows reporting, and slow reporting is what turns a click into an incident. Track reporting rates at the team level, keep individual results private, and make it clear that reporting a mistake is the outcome you want.

Sources

A note on figures: DBIR percentages are drawn from the 2026 report and coverage citing specific page references. IC3 dollar figures are from the 2025 annual report. The per-incident BEC average is a simple division of reported losses by complaint count and should be read as an average, not a typical case. Vendor-published click and report rate benchmarks were excluded except where they were incorporated into the DBIR dataset.

Our latest posts