Annual safety training is a ritual for many companies: a two-hour presentation by the IT department or an online course with a test at the end, confirmation of completion entered into the personnel system, and that's it for another 12 months. The result? Within three weeks, employees remember nothing essential, and the company ticks off its compliance checkbox.
Research in cognitive psychology clearly shows why this approach fails: without repetition and practical exercise, we forget 70% of new information within 24 hours and 90% within a week (Ebbinghaus forgetting curve). One-off training simply cannot change employee behaviour.
Why Traditional One-Year Training Fails
The problems are not just in the psychology of forgetting. The traditional approach also suffers from structural deficiencies:
- Outdated informationthreats evolve rapidly. Training created in January is obsolete by December. Attackers currently exploit topical events (fake phishing emails themed around current news, tax returns or pandemics).
- Generalities. One training session for everyone: from receptionists to the IT director, cannot be relevant to each individual. The finance department faces different threats (BEC fraud) than developers (supply chain attacks) or managers (spear phishing).
- Inactivity. Passive consumption of presentations or clicking through an online course does not create real habits. Safe behaviour must be practised in situations close to reality.
- Missing measurements. Without ongoing measurement, you cannot determine whether the training had any impact on employees' actual behaviour.
Continuous Security Awareness Programme: A modern approach
Effective safety training is continuous, personalised and measurable. Three key pillars:
1. Micro-learning: Short, regular lessons
Instead of a single two-hour block, spread the content over short 3-5 minute lessons published regularly, weekly or fortnightly. Each lesson focuses on one specific topic or threat.
- Shorter content has a significantly higher completion and retention rate.
- Regularity builds habits and keeps safety top of mind.
- Topics can be updated quickly. You respond to current threats (a new phishing campaign, a vulnerability in popular software).
- Platforms such as KnowBe4, Proofpoint Security Awareness or Cofense offer libraries of micro-learning content in Czech.
2. Phishing simulation: Learning from your own mistakes
Regular simulated phishing attacks are the most effective way to change employee behaviour. Key principles:
- Run simulations at least monthly, ideally every two weeks, with varying themes and difficulty levels.
- An employee who clicks on a simulated phishing email immediately receives short educational content: not another annual training course, but a specific explanation of what they should have recognised.
- Do not treat drills as a way to "catch people out": the aim is education, not punishment. A culture of blame destroys the willingness to report actual incidents.
- Monitor trends: is the click-through rate falling? Is the reporting rate of suspicious emails rising? These are key metrics.
3. Gamification and positive motivation
Gamification boosts engagement and motivation to participate. Working elements:
- Department rankings (not individuals) for phishing reporting rates and course completion.
- Badges and certificates for achieving a certain level of security awareness.
- Security "Challenge of the Month": a contest element with a small reward.
- Positive reinforcement: praise the employee or team that correctly reported a suspicious email.
Role-based training: Different content for different roles
The effective programme distinguishes between target groups and tailors content to their specific risks and context.
- Management and leadershipspear phishing, BEC (Business Email Compromise) frauds, deepfake frauds (fake voice messages from the CEO), security while travelling, liability for cyber risks.
- Finance and Accounting Departmentfraudulent payment orders, fake invoices, and identity verification when suppliers change their bank account details.
- IT and developerssecure programming practices, development tool security, supply chain risks, privileged access management.
- Customer support and receptionvishing (telephone fraud), physical security, tailgating, social engineering.
- New employeesa more intensive onboarding programme: the first 90 days are a critical window when people still do not know what is normal in the given company.
Measuring effectiveness: How to tell if training is working
Without measurement, you cannot tell if training investment delivers results. Key metrics:
Behavioural metrics (most important)
- Phishing susceptibility ratepercentage of employees who click on a simulated phishing email. Industry benchmark: under 5% after 12 months of the programme.
- Reporting ratepercentage of employees who report a suspicious email. A rising reporting rate is a positive indicator of culture.
- Time to reporthow quickly employees report suspicious activities: speed is key to limiting the impact of a real attack.
Process metrics
- Completion rate of micro-learning lessons (target: above 85 %).
- Results of knowledge tests before and after the training cycle.
- The number of security incidents reported by employees, if it is rising, this indicates greater awareness, not necessarily more incidents.
NIS2 and the obligation for security training
Article 21 of the NIS2 Directive requires obligated entities to implement measures including basic cyber hygiene practices and cybersecurity training. This is a legally binding obligation that you must be able to prove has been fulfilled.
What this specifically means for your business:
- Document your training programme: content, frequency, target groups, and results achieved.
- Keep records of completed training for each employee.
- Include management in the programme, company leadership bears personal responsibility for NIS2 implementation and must be trained.
- Adapt training to current threats, static content that does not change fails to meet the spirit of the requirement.
SecureOn.cz offers bespoke security awareness programmes, including phishing simulations, Czech-language micro-learning content, reporting for NIS2 compliance and effectiveness measurement. We would be happy to prepare a demo for you.
Conclusion: A safety culture, not a tick-box exercise.
The aim of security training is not to meet compliance requirements. It is to build an organisation where safety is a natural part of every employee's work. Where people naturally verify unusual payment instructions, report suspicious emails and protect login credentials.
This culture is not created by a single annual training session. It develops through a consistent, personalised and measurable education programme where employees see the purpose and value of safe behaviour. The investment pays off with the first prevented incident.