The Knowledge Gap: what security awareness training achieves

gabriel_b1 pts1 comments

The Knowledge Gap | SafeInstinct Whitepaper

Whitepaper · 2026

The Knowledge Gap

Why 62% of breaches still run through employees, what security awareness training actually achieves, and how to build a human-risk programme that survives evidence.

62% of breaches involve the human element<br>$5.29M average cost of a breach that starts with a voice or text lure<br>6 mo until trained phishing-detection skill returns to baseline

An evidence review for security leaders &middot; 36 cited sources &middot; free to read in full, no sign-up

Download the PDF<br>Discuss it with us

Executive summaryThe problem is not that employees don't care. It is that what we teach them does not survive contact with the attack.

Security awareness training is now near-universal, mandated by at least eight major regulatory<br>regimes, and funded in almost every enterprise security budget. Over the same period, the share of breaches<br>involving a human being has not fallen. In the 2026 Verizon dataset it rose — from 60% to 62%.1<br>That gap between effort and outcome is the subject of this paper.

What the current evidence shows<br>The human element is stable at roughly six in ten breaches , and the attack surface<br>around it has widened. Third-party involvement in breaches jumped from 30% to 48% in a single year,<br>which means an organisation now inherits the knowledge gaps of its suppliers.1<br>The channel has shifted from the inbox to the phone line and the help desk. In<br>Mandiant's 2025 incident casework, voice phishing was the second most common initial infection vector at<br>11%, while email phishing fell to 6% — down from 22% in 2022.7 Unit 42 found 36% of<br>all incidents began with social engineering, and two-thirds of those targeted privileged accounts.6<br>The most rigorous studies of phishing training find little to no behavioural effect.<br>A randomised trial across 19,500 employees found no significant relationship between completing annual<br>mandated training and clicking a phishing link; embedded "teachable moment" training reduced future<br>clicking by about 2%.14 An independent reproduction at a different firm, with 12,511<br>employees, found no significant improvement in either click rate or reporting rate.15<br>What training does achieve, it loses within six months. Measured phishing-detection<br>sensitivity roughly doubles immediately after training and is statistically indistinguishable from the<br>pre-training baseline by month six — unless a reminder is delivered, which restores and sustains it.17<br>Cost is moving in the wrong direction. The global average breach cost reached<br>US$4.99M in 2026, and a breach that begins with a vishing or smishing lure averages $5.29M — the<br>highest-cost entry point of any vector IBM measures.3<br>A new exposure class arrived faster than any training cycle. Regular AI use on<br>corporate devices tripled from 15% to 45% of employees in one year, 67% of it through non-corporate<br>accounts — while 58% of workers report having received no security training on AI use at all.1, 11

None of this argues for abandoning employee education. It argues that the dominant delivery model —<br>an annual compliance module plus a punitive phishing simulation — is measuring completion rather than<br>capability, and that the published evidence does not support the outcomes attributed to it. The<br>organisations that reduce human risk treat it as a control domain with owners, telemetry, and a decay<br>schedule, not as a training obligation with a due date.

Sections 1 through 4 establish the exposure. Section 5 examines what the peer-reviewed literature<br>actually finds about awareness training, including the counter-evidence. Sections 6 through 9 set out a<br>compliance baseline, seven design principles drawn from that evidence, a measurement set that replaces<br>click rate, and a twelve-month sequence a security leader can put in front of a board.

"Anti-phishing training programs, in their current and commonly deployed forms, are unlikely to offer<br>significant practical value in reducing phishing risks."<br>Ho et al., IEEE Symposium on Security and Privacy, 2025 — randomised trial, 19,500 employees

Section 01The human element has not moved in five years

A stable statistic in a market that has spent heavily to change it.

The Verizon Data Breach Investigations Report is the closest thing the industry has to a<br>longitudinal, multi-contributor breach census. Its 2026 edition analysed more than 31,000 security incidents<br>and more than 22,000 confirmed breaches across 145 countries.1 Its headline number for<br>human involvement — errors, misuse, stolen credentials, and social engineering combined — was 62%, described<br>in the report as a slight increase on the prior year's 60%.

This figure has hovered in the same band for half a decade. It has done so through a period in which<br>security awareness training became a mandatory control under PCI DSS, NYDFS Part 500, DORA and NIS2; in which<br>simulated phishing became standard practice; and in which the global market for awareness products...

training security phishing human from awareness

Related Articles