www.securityweek.com 8 Oct 2026, 14:30 UTC

Security Awareness Training Falls Short as Social Engineering Evolves

Security Awareness Training Falls Short as Social Engineering Evolves
CyberSIXT Evidence Panel Source marked as original reporting

SECURITY awareness training isn’t dead, but its value is debated. The piece surveys empirical hints that training’s benefits may be limited as successful attacks continue to rise, and notes a spectrum of opinions on whether awareness programmes help. The discussion centres on two aims: reducing insider risk from poor judgement and hardening employees against social engineering. While many agree that training has a role, the consensus is that it is often delivered poorly or treated as a compliance checkbox.

Several interviewees challenge the effectiveness of current approaches. Some blame compliance and insurance requirements for repetitive, one-size-fits-all content that fails to reflect modern threats, including AI-enabled social engineering. Others argue training can work in specific contexts if it’s more frequent, role-focused and backed by strong processes and technical controls. Yet there is worry that attackers’ evolving methods outpace conventional training.

A number of voices advocate supplementing training with behavioural nudges, continuous learning, and a broader security architecture that reduces reliance on humans as the final defence. The piece also discusses psychological factors, memory decay, and the difficulty of predicting future attacks, suggesting that training must be updated continually to address real-time threat trends.

Overall, while not a substitute for robust engineering and technical controls, awareness training should be rethought as part of an integrated, dynamic defence rather than a static compliance task.

View full article

Article by CyberSIXT