The training completion rate is 100%. The phishing simulation click rate three weeks later is 34%. The security budget was spent. The behaviour did not change.
At Metaluxo we design security awareness programmes for SMEs. The gap between “trained” and “secure” is well documented. This post covers what actually works — and why most programmes fail.
Why most training fails
It is too long. A 45-minute e-learning module overwhelms working memory. Staff retain the first 10 minutes and forget the rest.
It is too generic. A module designed for a bank does not resonate with a 15-person SaaS team. The scenarios are irrelevant.
It is too infrequent. Annual training creates a spike in awareness that decays to baseline within 4–6 weeks.
It is passive. Clicking through slides is not learning. It is compliance theatre.
What the research says works
A 2020 meta-analysis of security awareness training found four factors that predict behaviour change:
- Frequency: Interventions delivered monthly or biweekly outperformed annual programmes by a factor of three.
- Duration: Sessions under 10 minutes outperformed sessions over 30 minutes.
- Context: Scenarios based on real company incidents outperformed generic examples.
- Feedback: Immediate feedback on phishing simulations outperformed delayed reporting.
The conclusion: short, frequent, contextual, interactive training changes behaviour. Long, infrequent, generic, passive training does not.
A practical programme for a small company
Month 1: Phishing
- 5-minute video: how to spot phishing
- Phishing simulation sent 1 week later
- Immediate feedback for those who click
Month 2: Passwords
- 5-minute demo: password manager setup
- Quiz: which passwords are strong?
- Enforce password manager rollout
Month 3: Device security
- 5-minute checklist: lock screens, updates, physical security
- Self-assessment: rate your own device security
- Remediate gaps individually
Month 4: Incident reporting
- 5-minute scenario: “You clicked a suspicious link. What do you do?”
- Practice reporting through the real channel
- Reinforce that reporting is valued, not punished
Repeat quarterly. Add new scenarios based on actual incidents in your industry.
Metrics that matter
| Metric | Baseline | Target | Why it matters |
|---|---|---|---|
| Phishing simulation click rate | 30–40% | <10% | Measures actual vulnerability |
| Reported phishing emails | 2/month | 10+/month | Staff are engaged and vigilant |
| Password manager adoption | 40% | >90% | Reduces credential-based breaches |
| Incident reporting time | 48 hours | <4 hours | Faster response limits damage |
| Training completion | 100% | N/A | Completion alone is meaningless |
Common mistakes
- Punishing clicks. If staff fear punishment for failing a phishing simulation, they will stop reporting real incidents.
- One-size-fits-all content. Developers need different training than sales teams. Tailor scenarios.
- No executive participation. If the CEO skips training, everyone else notices.
- Ignoring remote workers. Remote staff face different threats. Include home network and BYOD scenarios.
At Metaluxo we design security awareness programmes for SMEs, typically delivering a 12-month curriculum with monthly micro-training and quarterly phishing simulations. If your training is not changing behaviour, book a free 30-minute consultation and we will rebuild it.
Common questions
How often should security awareness training happen?
Monthly micro-training is more effective than annual all-day sessions. The UK National Cyber Security Centre recommends short, frequent interventions.
What topics should security awareness training cover?
Phishing recognition, password hygiene, device security, incident reporting, and social engineering. Tailor to the threats your company actually faces.
How do we measure if training is working?
Track phishing simulation click rates, incident reporting volume, and password manager adoption. Behavioural metrics are more meaningful than completion rates.