The evidence, for and against
8 studies · Download CSV
Training interventions had no significant effect on click rates or reporting rates, with negligible effect sizes. Phish Scale difficulty did predict behavior (7% clicks on easy emails vs 15% on hard), and in 36-55% of campaigns reports arrived before clicks, though training did not improve this.
Understanding the Efficacy of Phishing Training in Practice Ho et al., 2025 IEEE Symposium on Security and Privacy (SP)Recent completion of annual awareness training had no significant link to failing phishing simulations, and embedded training produced only tiny differences in failure rates. Most users spent minimal time on training pages, and for some content types more training was associated with higher later failure rates.
Measuring the Effectiveness of U.S. Government Security Awareness Programs: A Mixed-Methods Study Jacobs et al., HCI International 2023 (HCI in Business, Government and Organizations), Lecture Notes in Computer ScienceGovernment security awareness programs lean heavily on compliance metrics such as training completion rates and struggle to find other ways to judge whether behavior actually changed.
An investigation of phishing awareness and education over time: When and how to best remind users Reinheimer et al., Sixteenth Symposium on Usable Privacy and Security (SOUPS 2020)After an awareness program, employees identified phishing and legitimate emails significantly better right away and at four months, but the gain was gone by six months. Reminders based on videos and interactive examples worked best and lasted at least another six months.
Who Provides Phishing Training? Facts, Stories, and People Like Me Wash & Cooper, Proceedings of the 2018 CHI Conference on Human Factors in Computing SystemsFacts-and-advice training beat no training only when presented by a security expert, while story-based training worked much better when told by a peer. Who delivers training can strongly change security outcomes.
Cyber Security Awareness Campaigns: Why do they fail to change behaviour? Bada et al., International Conference on Cyber Security for Sustainable Society, 2015 (arXiv:1901.02672, posted 2019)Awareness campaigns fail when they only provide information: people must be able to understand and apply advice and be motivated to act, which requires attitude and intention change. Reviews persuasion techniques, including fear appeals, and lists factors behind campaign success or failure.
Going Spear Phishing: Exploring Embedded Training and Awareness Caputo et al., IEEE Security & PrivacyDifferently framed embedded training messages had no significant effect on whether people clicked later spear-phishing emails, and many people either clicked every link or none regardless of training. Employees largely did not read the training materials.
User Awareness of Security Countermeasures and Its Impact on Information Systems Misuse: A Deterrence Approach D'Arcy et al., Information Systems Research, 20(1)User awareness of security policies, SETA programs and computer monitoring each deterred intentions to misuse IS, working through perceived sanctions. Perceived severity of sanctions mattered more than certainty, and the effect varied with individuals' morality.