Jul 24, 2026

Cybersecurity Awareness Training: Why Annual Training Is Not Enough

A cybersecurity awareness training course delivered once a year does not meaningfully reduce phishing risk, because people quickly forget what they have learned without reinforcement over time. According to Verizon's Data Breach Investigations Report 2025, roughly 60% of the breaches analysed involved a human element, such as clicking a malicious link or mishandling data.

In this article we look at why the once-a-year cybersecurity awareness training model fails, what research says about continuous training, how the brain processes a phishing attempt, how to structure an effective security awareness training programme, and how the GDPR and the NIS2 Directive frame mandatory training obligations on information security.

Why Annual Cybersecurity Awareness Training Does Not Work

The main problem with annual training is not the content, but is the frequency.

A one-hour session, run just once a year, creates a brief peak of attention that fades within days. Without reinforcement, people quickly revert to previous habits, including risky ones. The forgetting curve described by Ebbinghaus more than a century ago applies to cybersecurity exactly as it does to any other type of learning. Without spaced repetition over time, most of the content vanishes within a week.

The Verizon report notes that the average click rate on phishing simulations remains around 1.5% even in organisations that run continuous training, a figure that reflects a physiological limit that is difficult to eliminate entirely.

What changes with frequent training is not just the click rate, but people's ability to recognise and report a phishing attempt before it causes damage. Proactive reporting, not simply avoiding opening an attachment, is the true indicator of a consolidated cyber security awareness culture.

Cyber threats, particularly phishing, work by exploiting specific psychological mechanisms: perceived urgency, the apparent authority of the sender, familiarity with a known brand. An email that simulates an urgent message from the CEO or a regular supplier bypasses rational defences in the same way a well-crafted suspicious phone call would.

A one-off cybersecurity awareness course does not train this recognition over time.

Recognising an attack pattern requires repeated exposure to realistic examples, spread over weeks or months. Adding to the challenge, phishing messages generated with generative AI have become more convincing and harder to detect than those produced manually. A cybersecurity training programme that does not update regularly risks teaching employees to spot signals that the latest attacks no longer display.

traditional cybersecurity training

Continuous Microlearning vs a Single Course: Frequency Is the Key

The data confirms the value of frequency. According to the DBIR 2025 analysis, employees who received recent training report simulated phishing emails at a significantly higher rate than those who have not been trained recently.

The true ROI of cybersecurity awareness training is the capacity to react, not just the prevention of a click.

Microlearning addresses this need by distributing short content over time. A 3-5 minute module every month, delivered directly inside Microsoft Teams, keeps the topic active in employees' minds without demanding a significant time commitment. This approach draws on the same spaced-repetition principle that memory research associates with better long-term retention.

The practical difference is substantial.

With a one-hour annual course, the employee absorbs information in an artificial setting, disconnected from real work, and forgets nearly all of it within a week. With five-minute monthly modules delivered through Teams, each training session sits within the daily workflow, reinforces previous content and updates on new attack vectors. Training does not interrupt work: it travels alongside it.

A further advantage of the short, frequent format is how it handles updates. When a new attack technique emerges, updating a five-minute module takes hours, not weeks. With a traditional one-hour course, any meaningful update requires almost rebuilding it from scratch.

GDPR and NIS2: What European Regulation Actually Requires

The GDPR does not prescribe a specific format for cybersecurity training, but it requires organisations to adopt adequate organisational measures to protect personal data. Staff training is explicitly recognised as one of those measures.

This means that running a course once and forgetting about it is not sufficient. In the event of a data breach or an inspection by the supervisory authority, the organisation must be able to demonstrate three things:

  1. training was delivered on a continuous basis,
  2. employees actually completed it,
  3. the content was current relative to existing threats.

A microlearning programme with automatic tracking satisfies these requirements far more robustly than an annual course with a paper attendance register.

The NIS2 Directive (transposed into Member States' national law by October 2024) adds a further layer of obligations. As of 2026, organisations in the sectors covered by the directive, approximately 160,000 entities across the EU spanning essential and important categories, are under active supervision by national competent authorities. Article 20 of NIS2 states explicitly that management bodies must undergo cybersecurity training and that organisations must offer equivalent training to all employees on a regular basis. Senior management is not exempt: it is included as a mandatory recipient.

Fines for essential entities can reach 10 million euros or 2% of global turnover. For important entities, the ceiling is 7 million euros or 1.4% of turnover. These are not theoretical risks: national authorities are actively verifying compliance.

Organisations should be able to present structured, per-employee documentation in response to regulatory enquiries, covering completion dates, module content and quiz scores. This is precisely what an LMS with automatic tracking provides.

cybersecurity problems

Understanding the psychology behind attacks helps design a more effective cybersecurity awareness programme.

Phishing does not work because employees are careless or unintelligent. It works because it exploits cognitive systems that everyone uses every day to make fast decisions without overloading conscious attention. Kahneman's System 1, the fast and automatic mode of thinking, is exactly what cybercriminals are trying to activate.

An email arriving from what appears to be a familiar supplier, with an urgent subject line and the correct logo, is not processed by the user's critical, deliberate system: it is processed by automatic pattern-matching. If it resembles the emails that normally arrive from that supplier, the brain treats it as legitimate.

Effective phishing training does not just teach employees to spot technical signals, such as suspicious URLs, unverified senders or unusual attachments. It teaches people to slow down before acting, to recognise the moment when they feel urgency or pressure as a warning signal rather than a call to comply. This kind of conditioned response is built through repetition, not through a single course.

Periodic phishing simulations, integrated into a cybersecurity awareness programme, serve this purpose: they expose employees to realistic attempts in a safe context where failure produces learning rather than damage. An employee who clicks on a simulated link immediately receives a short module explaining what they should have noticed. This immediate feedback is far more effective than a theoretical explanation delivered in a classroom.

How to Structure an Annual Cybersecurity Awareness Programme

An effective annual cybersecurity awareness plan is not built around a single training event, but around a regular cadence of short content.

One practical structure involves a monthly 3-5 minute module covering different topics across the year: recognising basic phishing in the early months, followed by social engineering, secure password management, mobile device security, data protection in remote working scenarios, Business Email Compromise (BEC), videoconferencing security, and updates on emerging attack vectors.

High-risk topics, particularly phishing recognition and credential management, deserve to be addressed more than once during the year with fresh examples. When relevant events occur, such as the introduction of a new regulation or a high-profile attack in the industry, adding an ad hoc module that contextualises the threat specifically for the organisation is a valuable supplement.

Role-specific paths significantly increase programme effectiveness.

An administrative employee, a sales representative, an IT technician and a board member have completely different risk profiles. Generic training covers the fundamentals, but role-specific training addresses the most likely attack vectors for each function. Executives, for example, are preferred targets for BEC and spear-phishing attacks: their training must include scenarios tailored to this profile.

A platform like Microlearning365 enables the cybersecurity awareness programme to be updated immediately when new threats emerge, without engaging an external agency to rebuild the course, and delivers modules directly inside Microsoft Teams. Automatic completion tracking produces the reports needed for GDPR and NIS2 compliance without manual effort from IT or HR.

cybersecurity microlearning365

Some sectors face regulatory requirements that overlap with or reinforce those of NIS2 and the GDPR.

In financial services and banking, the DORA regulation (Digital Operational Resilience Act, applicable from January 2025) requires financial institutions to manage ICT risks systematically, including periodic staff training. The European Banking Authority and national supervisors have included cybersecurity training verification among their inspection criteria.

In the public sector, national digital agencies across Europe have issued specific cybersecurity guidelines that include staff training requirements. Public sector organisations are among the most frequently targeted by ransomware attacks, which means training is not only a compliance obligation but a concrete operational priority.

In critical infrastructure (energy, transport, water), NIS2 applies the strictest supervisory requirements. Cybersecurity training must cover scenarios specific to OT (Operational Technology) and ICS (Industrial Control Systems) environments, where a cyber incident can have physical as well as digital consequences.

Annual Training vs Continuous Programme

Indicatore Corso annuale tradizionale Microlearning continuo
Ritenzione dopo 30 giorni Circa il 20% dei contenuti Circa il 40–50% dei contenuti
Tasso di completamento Basso (attriti nell'accesso) Elevato (integrato nel flusso di lavoro)
Tracciabilità per audit GDPR/NIS2 Manuale, parziale Automatica, per dipendente
Aggiornamenti sulle minacce Una volta all'anno Modulo dedicato disponibile in pochi giorni
Copertura del personale distribuito Spesso escluso Accessibile da smartphone
Documentazione per il management Aggregata o assente Per singolo dipendente, esportabile
Costo degli aggiornamenti dei contenuti Nuovo progetto affidato a un'agenzia Modifica interna in pochi minuti

FAQ

How often should cybersecurity awareness training be delivered?

Research suggests a monthly or bi-monthly cadence with short modules, rather than a single annual session. Regular delivery increases the probability that employees will recognise and report real phishing attempts. NIS2 requires regular training without specifying a minimum frequency: sector best practices recommend at least four to six sessions per year.

Does cybersecurity awareness training actually reduce the risk of breaches?

It reduces risk but does not eliminate it entirely. According to the Verizon DBIR 2025, the click rate on phishing simulations remains around 1.5% even with continuous training, but the reporting rate rises significantly among recently trained employees. Reporting capability is the more important metric, because it allows the organisation to respond before an attack escalates.

Does GDPR require a cybersecurity awareness programme?

The GDPR requires adequate organisational measures for data protection, and staff training is considered one of those measures. In the event of a data breach, demonstrating continuous and traceable training can be decisive in the supervisory authority's assessment. NIS2 adds an explicit obligation for regular training covering all employees, including board members.

How do you demonstrate compliance with a cybersecurity awareness programme during an audit?

With a system that automatically tracks completion and quiz results for each employee, generating reports with dates, content covered and scores. This type of documentation is far more robust than an attendance register from a classroom session, and directly addresses the documentary requests from both GDPR and NIS2 supervisory authorities.

Why is an annual cybersecurity awareness course not enough, even a high-quality one?

Even a well-designed course is subject to the rapid forgetting described by the Ebbinghaus curve: without reinforcement over time, most of the content is lost within days of the training. This is not a function of the course quality but of how human memory works. Only spaced repetition over time produces durable retention.

Explore our collection of 200+ Premium Webflow Templates

Need to customize this template? Hire our Webflow team!