Cyber Security

Does Your Cyber Security Training Actually Work?

IT Club Editorial8 minutes read2 September 2026
WhatsAppEmail
Does Your Cyber Security Training Actually Work?

Keep up with IT Club

Add IT Club as a preferred source in Google Search.

Training completion is an activity measure, not proof of reduced risk. This practical guide explains what the 2026 KnowBe4 benchmarking data does and does not show, how to measure improvement and why awareness must sit alongside technical controls.

Every employee completes their annual cyber security training. The dashboard turns green. Someone downloads a certificate. The compliance box gets ticked.

Job done? Not necessarily.

The important question is not “Did everybody complete the training?” It is “Are they now less likely to fall for an attack, more likely to report one and better supported by the technology around them?”

The better test

Training delivered is an activity. Risk reduced is an outcome. A useful programme connects the two with a baseline, testing, reporting and a trend that management can understand.

  • Measure where the organisation started.
  • Train people in short, relevant and repeatable ways.
  • Test behaviour without creating a blame culture.
  • Learn from clicks, reports and near misses.
  • Improve both people and technology.
  • Repeat and show the trend.

What the 2026 data says

KnowBe4's 2026 Phishing by Industry Benchmarking Report is useful because it attempts to measure behaviour with simulated phishing tests rather than only counting course completions. Its public report summary says it analyses millions of simulated tests across 19 industries, four organisation sizes and seven global regions.

MeasureReported result
Before security awareness trainingGlobal average Phish-prone Percentage (PPP) of 33.2%
After a year of continuous trainingAverage PPP of 4.2%
Average changeAn 87% reduction in phishing susceptibility in the reported dataset

In plain English, the report's global baseline is roughly one in three participants interacting with the simulated phishing test before training. After a year of continuous training, the reported average is much lower.

These are KnowBe4's results from its own customer and programme dataset. They are strong evidence that sustained awareness, testing and reinforcement can materially improve phishing resilience, but they are not a randomised study of every employee and should not be presented as a guaranteed result for every organisation.

The public summary also presents baseline, 90-day and one-year benchmarks. It does not provide enough primary evidence for this article to repeat every figure circulating in third-party summaries, particularly claims about a 24-month result. Omitting an attractive number is better than turning an unverified statistic into a promise.

KnowBe4: 2026 Phishing by Industry Benchmarking Report

What PPP can and cannot tell you

Phish-prone Percentage, or PPP, is a useful measurement of a defined behaviour in a simulated test. It is not a complete risk score. It does not tell you whether a real attacker will choose your organisation, whether somebody will approve a fraudulent payment by phone or whether a technical control would have blocked the message before it reached an inbox.

The result can also be affected by who is included, how the tests are designed, which messages are used, how often people are tested and whether the participating organisations already have an active security awareness programme. A falling number is encouraging. It still needs context.

For an SME, the most useful comparison may not be a global benchmark. It may be your own trend: how many suspicious messages were reported, how quickly were they reported, which roles need extra support and what changed after the last test?

Do not confuse training with security

Training is one layer. NCSC guidance recommends a multi-layered approach: make it difficult for phishing to reach users, help users identify and report suspected phishing, protect the organisation when an attack gets through and respond quickly when something happens.

That is why a five-minute video cannot compensate for weak email controls, password-only access, excessive permissions or a payment process that accepts changed bank details without verification.

  • Email filtering and attachment or link protection.
  • DMARC, SPF and DKIM where appropriate for your domains and sending services.
  • Multi-factor authentication, with phishing-resistant options where proportionate.
  • Conditional access and sensible device or browser protection.
  • Endpoint protection, patching and least privilege.
  • A clear way to report suspicious messages quickly.
  • Payment verification and change-of-bank-details procedures.
  • An incident response route that people can use without fear.

Read: Why Your Business Needs DMARC

Read: Microsoft 365 Security Baseline Checklist

A simulation should not become a blame culture

People will occasionally make mistakes. A phishing simulation should improve organisational resilience, not create a league table for embarrassing staff.

NCSC warns that no training package can teach users to spot every phishing attempt. It also points out that punishing people for clicking on messages sent by the organisation can create legal and cultural problems. A frightened employee is less likely to report a mistake quickly, exactly when the business needs information.

A better programme uses education, positive reinforcement, easy reporting, targeted additional help and management involvement. An employee who reports a suspicious message — even after clicking — may give the organisation time to revoke a session, reset credentials or warn colleagues.

NCSC: Phishing attacks — defending your organisation

AI changes the clues, not the principle

Generative AI can make it easier to produce natural language, better grammar, personalised messages, localised variants and convincing business context. That does not make phishing unstoppable. It does make old advice such as “look for bad spelling” less reliable.

People should practise recognising suspicious context and behaviour: an unexpected request, unusual urgency, a payment change, a credential request, an unfamiliar MFA prompt, a request to bypass process or a file-sharing page that does not fit the normal workflow.

The aim is not to turn every employee into a forensic analyst. It is to make safe interruption normal: stop, check using a trusted route and report the message when something does not fit.

The ten questions to ask your IT provider

If your MSP or IT provider supplies security awareness training, ask:

  1. 1What exactly are we trying to improve?
  2. 2What was our starting phishing susceptibility or risk level?
  3. 3Are you testing us as well as training us?
  4. 4How frequently are the tests and lessons delivered?
  5. 5Are the simulations realistic, proportionate and agreed with the right internal teams?
  6. 6Are results improving over time?
  7. 7Which teams or roles are consistently higher risk?
  8. 8What happens when somebody repeatedly struggles?
  9. 9Are we measuring reporting behaviour as well as clicking behaviour?
  10. 10Can you show management the trend and the changes made in response?

The question worth asking

“You charge us for security awareness training. Show us that it is working.”

A good provider should welcome that question. It should be able to show a baseline, explain the measure, discuss its limitations and connect the results to changes in training, processes and technical controls.

A simple maturity model

LevelWhat the organisation does
1 — Tick boxStaff complete an annual course.
2 — TestThe organisation runs proportionate phishing simulations.
3 — MeasureResults, reports and trends are recorded.
4 — ImproveTraining and controls change in response to findings.
5 — ResilientPeople, technology and processes work together, and management can see evidence of improvement.

You do not need to jump from level one to an expensive platform overnight. The first improvement may be a clear reporting button, a short payment-verification rule or a monthly conversation about what the last test taught you.

What good evidence looks like

  • Baseline — where did we start?
  • Action — what did we change?
  • Measurement — how are we testing it?
  • Trend — are results improving?
  • Response — what happens when somebody fails or reports a message?
  • Reporting — are employees increasingly reporting suspicious messages?
  • Technology — what reduces dependence on users spotting everything?
  • Business outcome — is the organisation becoming harder to attack successfully?

The last question matters most. A falling simulation click rate is useful, but the business outcome is broader: fewer exposed credentials, faster reporting, fewer payment mistakes and less opportunity for one human error to become a serious incident.

Training should be something your business gets better at

A certificate tells you somebody completed the training. A dashboard tells you the system recorded it. Neither necessarily tells you whether your organisation became safer.

If you are paying an IT provider for cyber security awareness, do not just ask whether the training was delivered. Ask for the evidence that it worked, ask what the limitations are and ask what changed beyond the training module.

Cyber security training should not be something your staff complete. It should be something your business gets better at.

Read next: When Your IT Provider Finds a Compliance Problem, Who Benefits From the Fix?

Sources and further reading

KnowBe4: 2026 Phishing by Industry Benchmarking Report

NCSC: Phishing attacks — defending your organisation

NCSC: Email security and anti-spoofing

NCSC: Cyber Essentials overview

ICO: Training and awareness

ICO: Security outcomes

Plain-English Takeaway

A certificate tells you somebody completed training. Evidence that your business is safer comes from a baseline, realistic testing, reporting behaviour, technical controls and a visible trend over time.

Enjoyed this article?

Follow The IT Club Briefing on WhatsApp for short daily technology updates and practical business insights.

Have a question we should answer?

Ask the IT Club Advisor