Blog Security Awareness

Safety training for employees: Why once a year is not enough and how to do it correctly

The human factor is responsible for 74 % of cyber incidents. Yet most companies rely on one-off annual training that employees forget within three weeks. There is a better approach, and this article will explain it to you.

19 January 2026 · 10 minutes reading · Security Awareness

Annual safety training is a ritual for many companies: a two-hour presentation by the IT department or an online course with a test at the end, confirmation of completion entered into the personnel system, and that's it for another 12 months. The result? Within three weeks, employees remember nothing essential, and the company ticks off its compliance checkbox.

Research in cognitive psychology clearly shows why this approach fails: without repetition and practical exercise, we forget 70% of new information within 24 hours and 90% within a week (Ebbinghaus forgetting curve). One-off training simply cannot change employee behaviour.

Why Traditional One-Year Training Fails

The problems are not just in the psychology of forgetting. The traditional approach also suffers from structural deficiencies:

Continuous Security Awareness Programme: A modern approach

Effective safety training is continuous, personalised and measurable. Three key pillars:

1. Micro-learning: Short, regular lessons

Instead of a single two-hour block, spread the content over short 3-5 minute lessons published regularly, weekly or fortnightly. Each lesson focuses on one specific topic or threat.

2. Phishing simulation: Learning from your own mistakes

Regular simulated phishing attacks are the most effective way to change employee behaviour. Key principles:

3. Gamification and positive motivation

Gamification boosts engagement and motivation to participate. Working elements:

Role-based training: Different content for different roles

The effective programme distinguishes between target groups and tailors content to their specific risks and context.

Measuring effectiveness: How to tell if training is working

Without measurement, you cannot tell if training investment delivers results. Key metrics:

Behavioural metrics (most important)

Process metrics

NIS2 and the obligation for security training

Article 21 of the NIS2 Directive requires obligated entities to implement measures including basic cyber hygiene practices and cybersecurity training. This is a legally binding obligation that you must be able to prove has been fulfilled.

What this specifically means for your business:

SecureOn.cz offers bespoke security awareness programmes, including phishing simulations, Czech-language micro-learning content, reporting for NIS2 compliance and effectiveness measurement. We would be happy to prepare a demo for you.

Conclusion: A safety culture, not a tick-box exercise.

The aim of security training is not to meet compliance requirements. It is to build an organisation where safety is a natural part of every employee's work. Where people naturally verify unusual payment instructions, report suspicious emails and protect login credentials.

This culture is not created by a single annual training session. It develops through a consistent, personalised and measurable education programme where employees see the purpose and value of safe behaviour. The investment pays off with the first prevented incident.

Do you need advice on cybersecurity?

Our experts are ready to assess your situation. The first consultation is free of charge.

Get a free consultation