Security Awareness Training That Actually Works
In September 2023, an attacker called MGM Resorts' IT help desk, impersonated an employee found on LinkedIn, and convinced a technician to reset credentials. That ten-minute phone call cascaded into system-wide encryption, a shutdown of slot machines and hotel key cards across Las Vegas, and more than $100 million in damages. MGM's employees had completed their annual security awareness training. It did not matter.
Why Now: The Economics of Social Engineering Have Shifted
Three forces have converged to make traditional awareness programs dangerously inadequate.
First, phishing-as-a-service platforms now sell turnkey kits -- complete with landing pages, evasion techniques, and customer support -- for under $200 per month. The barrier to launching a convincing campaign has collapsed from "skilled attacker" to "anyone with a credit card."
Second, AI-generated phishing has eliminated the grammatical errors and formatting tells that employees were trained to spot. Attackers generate fluent, contextually appropriate messages at scale, rendering the "look for typos" heuristic that anchors most training modules effectively useless.
Third, compliance frameworks are tightening their requirements. CMMC Level 2 assessors are now asking for evidence of role-based training delivery, not just annual completion certificates. Organizations preparing for assessment need to demonstrate that training content maps to specific practice areas and that delivery frequency exceeds the annual minimum. The era of a single yearly module satisfying every auditor is ending.
Why Annual Training Fails
The forgetting curve is brutal. Research consistently shows that retention of security concepts drops below 20% within 30 days of a single training session. An employee who completes a one-hour module in January is operating on instinct by March.
But the problem goes deeper than memory. Annual training treats security awareness as a knowledge problem -- if people know the right answer, they will do the right thing. In practice, security failures are behavioral problems occurring under time pressure, cognitive load, and social manipulation. The MGM help desk technician almost certainly knew that identity verification mattered. In the moment, with a convincing caller on the line and a queue of tickets waiting, knowledge was insufficient.
Annual training also creates a perverse compliance dynamic. When the goal is 100% completion by a deadline, organizations optimize for throughput: shorter modules, easier quizzes, auto-advancing slides. The metric improves while the actual security posture remains unchanged. Auditors see green checkmarks. Attackers see the same vulnerable behaviors.
The organizations that break this cycle share three characteristics: they train frequently (monthly or more), they train on scenarios relevant to each role, and they create consequences -- positive ones -- for the behaviors they want to reinforce.
What Actually Changes Behavior
Behavioral science offers a clear framework: frequency, relevance, and reinforcement.
Frequency means monthly touchpoints at minimum. These are not hour-long sessions. Five-minute micro-modules delivered weekly outperform annual marathons by a wide margin in every published study. The goal is keeping security thinking active in working memory, not buried in a completed-training archive.
Relevance means the content mirrors the actual threats each role faces. A finance team member needs wire fraud scenarios, not generic phishing examples. A developer needs dependency confusion and commit signing, not clean-desk policy. An executive needs deepfake voice call simulations, not password hygiene basics they have already heard fifteen times.
Reinforcement means the organization responds to behavior -- and here is where most programs fail catastrophically.
Punishing users who click phishing simulations trains them to hide incidents, not report them. The organizations with the best security cultures reward reporting speed, not click avoidance. When an employee reports a suspicious email in under two minutes, that should trigger recognition -- a Slack message, a leaderboard update, a mention in the team standup. When an employee clicks a simulation, the response should be immediate micro-training, not a disciplinary note. Fear-based programs produce silence. Silence is what attackers exploit.
Simulated Phishing Programs
Simulated phishing remains the most effective tool for measuring and improving actual security behavior -- when implemented correctly.
Building an Effective Program
Start with a baseline. Run your first campaign without prior announcement. Use a moderate-difficulty template (branded login page, plausible pretext, no obvious tells). Your baseline click rate will likely land between 15% and 30%. This is normal. Do not panic. Do not punish.
Establish a cadence. Monthly campaigns, varying in difficulty and vector. Rotate through email phishing, SMS (smishing), voice (vishing if your tooling supports it), and QR code attacks. Attackers do not limit themselves to email, and neither should your simulations.
Graduate difficulty over time. As your organization matures, increase sophistication: targeted spear-phishing using information from public profiles, thread hijacking simulations, and multi-stage campaigns that combine channels. If your click rate stays below 5% on easy templates, your program is not testing anything meaningful.
Measure reporting, not just clicking. The click rate tells you who failed. The report rate tells you who actively defended the organization. Track both. A 3% click rate with a 20% report rate is worse than a 5% click rate with an 80% report rate -- the second organization has a functional human detection layer.
Metrics That Matter
| Metric | Immature Program | Mature Program |
|---|---|---|
| Click rate | 15-30% | Below 5% |
| Report rate | 10-20% | Above 70% |
| Mean time to report | Hours or never | Under 5 minutes |
| Repeat clickers (3+ in 12 months) | 8-12% of staff | Under 2% |
| Campaign-to-campaign improvement | Flat | Measurable decline in clicks per quarter |
Role-Based Training
Generic awareness content fails because threat landscapes differ dramatically by role. An effective program segments training by actual exposure.
All personnel: Social engineering recognition, credential hygiene, phishing-resistant MFA enrollment, physical security, incident reporting procedures.
IT administrators and engineers: STIG compliance and secure configuration, privileged access management, supply chain attacks (dependency confusion, typosquatting), continuous monitoring responsibilities.
Software developers: Secure coding practices, SAST/DAST/SCA tooling interpretation, secrets management, code review for security, CI/CD pipeline security.
Finance and procurement: Business email compromise scenarios, wire transfer verification procedures, invoice fraud detection, vendor impersonation.
Executives and board members: Whale phishing (highly targeted attacks using public information), deepfake voice/video scenarios, identity governance responsibilities, regulatory liability.
Help desk and support staff: Identity verification procedures under social pressure (the MGM scenario), pretexting recognition, escalation protocols for suspicious requests.
For organizations pursuing CMMC Level 2 or NIST 800-171 compliance, role-based training is not optional -- it maps directly to the AT (Awareness and Training) practice family, and assessors expect evidence that training content varies by role and responsibility.
Measuring Effectiveness
Training programs without measurement are compliance theater. Effective measurement combines behavioral metrics (what people actually do) with compliance metrics (what the framework requires you to document).
Behavioral Metrics
Phishing simulation results over time, segmented by department, role, and difficulty tier. Look for trends, not snapshots. A single month's click rate means nothing; a six-month trendline means everything.
Incident reporting volume and speed. Counter-intuitively, a rise in reported incidents after launching a training program is a positive signal -- it means people are paying attention and feel safe reporting. A drop in reports with no corresponding drop in actual incidents is a danger sign.
Policy violation rates from continuous monitoring systems: unauthorized software installations, data handling violations, access policy exceptions requested.
Help desk security verification compliance. After the role-based training for support staff, are identity verification steps being followed consistently? Audit call recordings or ticket logs quarterly.
Compliance Metrics
Every framework with a training requirement expects specific evidence:
- Completion rates by module and timeframe (target: 100% within the defined window)
- Role-based coverage showing that specialized training reaches the correct populations
- New hire onboarding completion within the organizationally defined timeframe
- Recurrence evidence proving training is not just annual (for frameworks that require or recommend more frequent delivery)
- Content mapping showing which training modules satisfy which specific controls
For SOC 2 and ISO 27001 audits, the narrative matters as much as the numbers. Auditors want to see that training content is reviewed and updated based on the threat landscape, incident history, and organizational changes -- not recycled year over year.
Connecting Training to Security Metrics
The ultimate test of a training program is whether it moves your security metrics in the right direction. Correlate training delivery with:
- Reduction in successful phishing compromises (real, not simulated)
- Decrease in mean time to detect social engineering attempts
- Reduction in security incidents with a human-error root cause
- Improvement in audit findings related to the AT control family
If your training program has been running for 18 months and these metrics are flat, the program needs structural change -- not more of the same content delivered the same way.
Compliance Requirements by Framework
| Framework | Control Reference | What Assessors Expect |
|---|---|---|
| NIST 800-171 | 3.2.1, 3.2.2 | Role-based training + awareness for all users |
| CMMC Level 2 | AT.L2-3.2.1, AT.L2-3.2.2 | Evidence of role-based delivery, not just completion |
| FedRAMP | AT-2, AT-3, AT-4 | Annual minimum + role-based + training records |
| HIPAA | 164.308(a)(5) | Periodic security updates + procedures for guarding PHI |
| SOC 2 | CC1.4, CC2.2 | Ongoing awareness + communication of responsibilities |
| PCI DSS v4.0 | 12.6.1-12.6.3 | Annual + upon hire + at least every 12 months |
| ISO 27001 | A.6.3 | Awareness program appropriate to policies and role |
Organizations operating under multiple frameworks -- which is most organizations at any meaningful scale -- face overlapping training requirements. A well-designed program maps training modules to multiple controls simultaneously, avoiding redundant delivery while maintaining framework-specific evidence trails.
Key Takeaways
- Annual training satisfies the minimum compliance bar but does not change behavior. Monthly micro-training with simulated phishing does.
- Measure reporting speed and rate, not just click avoidance. A high report rate is more valuable than a low click rate.
- Role-based training is a requirement for CMMC, NIST 800-171, and FedRAMP -- not a nice-to-have.
- Reward reporting. Punishing clicks creates a culture of silence that attackers exploit.
- Connect training metrics to actual security outcomes. If incidents with human-error root causes are not declining, the program is not working.
- Training evidence must map to specific controls. "Everyone completed the module" is insufficient for modern assessments.
Frequently Asked Questions
How often should we run simulated phishing campaigns?
Monthly is the minimum effective cadence for most organizations. More mature programs run bi-weekly or even weekly campaigns at varying difficulty levels. The key is consistency -- irregular campaigns create spikes of awareness followed by long troughs of complacency. Vary the attack vector (email, SMS, voice, QR code) and difficulty tier each month to prevent pattern recognition that does not transfer to real attacks.
Does security awareness training actually reduce breaches?
Yes, but only when delivered as a sustained behavioral program rather than an annual compliance event. Published data from organizations with mature programs (monthly training, simulated phishing, positive reinforcement) shows phishing susceptibility rates dropping from 25-30% to under 5% within 12-18 months. More importantly, report rates climb above 70%, meaning the organization gains a distributed human detection capability that complements technical controls.
What training is required for CMMC Level 2 assessment?
CMMC Level 2 maps to NIST 800-171 practices 3.2.1 (security awareness for all users, including social engineering risks), 3.2.2 (training personnel to carry out their assigned security-related duties), and 3.2.3 (recognizing and reporting potential indicators of insider threat). Assessors expect evidence that training is role-appropriate, delivered at a defined frequency, tracked with completion records, and updated based on the current threat environment. A single generic annual module will likely result in a finding. Demonstrating monthly delivery with role-based content significantly strengthens your assessment posture.
How do we handle employees who repeatedly fail phishing simulations?
Resist the instinct to escalate to disciplinary action. Repeat clickers (three or more failures in a twelve-month period) typically fall into two categories: people who need fundamentally different training delivery (visual learners getting text-only content, for example) and people whose job pressure overrides their security judgment (high-volume email roles where speed is rewarded). Address the root cause: one-on-one coaching, adjusted workflow, or additional technical controls (email banners, link sandboxing) that reduce reliance on individual judgment for that population.
Can we use the same training content across all compliance frameworks?
You can use shared content, but you must map it explicitly to each framework's specific controls and maintain separate evidence trails. A module on phishing recognition might satisfy NIST 800-171 3.2.1, SOC 2 CC1.4, PCI DSS 12.6, and ISO 27001 A.6.3 simultaneously -- but your evidence collection system needs to document that mapping. Assessors from different frameworks will ask different questions about the same training program, and your documentation must answer each one on its own terms.
How Advisedly Helps
Advisedly maps security awareness training delivery to specific control requirements across 500+ compliance frameworks, tracking completion evidence at the individual and role level, flagging overdue or missing training before it becomes an audit finding, and generating the role-based coverage reports that CMMC assessors and SOC 2 auditors expect to see. For organizations managing training alongside continuous monitoring, vulnerability management, and policy lifecycle, the platform ensures training evidence integrates with your broader compliance posture rather than living in an isolated spreadsheet. Contact begin@advisedly.ai to build a training program that changes behavior and satisfies your assessors.
<!-- LI hook: A 10-minute phone call cost MGM $100M. Annual training didn't help. -->