By itself, briefly and temporarily. A single five-minute video reliably moves awareness, but the way memory works means the effect decays within days unless something reinforces it. What changes behaviour over months is the format rather than the runtime: short modules delivered on a spaced schedule, paired with practice - which in security means phishing simulations with immediate feedback. Five minutes is the right dose; one five-minute video is the wrong programme.
TL;DR
- A one-off video produces awareness, not habit: the forgetting curve erodes most new information within days.
- Spaced, repeated microlearning measurably improves retention - published summaries of the research report retention gains of roughly 20-60% over massed, one-off training.
- Security behaviour is proven by what people do with real or simulated emails, not by quiz scores.
- Five minutes is the right length when it repeats on a cadence and is followed by coaching on click.
- Measure behaviour - click and report rates over time - not video completion.
Why the question is really about 300 seconds of ROI
Every training decision in a small business is a trade against people's time. Five minutes per employee sounds trivial until you multiply it by headcount and frequency - and until you ask what the five minutes bought. An annual hour-long session that nobody remembers by February bought one hour per employee. A five-minute module that employees actually finish bought five minutes and a message they saw to the end.
So the real question is not "is five minutes enough?" but "what makes five minutes stick?" - and the research on that is clearer than most training vendors suggest.
The forgetting curve problem
People forget most of what they learn in a single session within days. This is the Ebbinghaus forgetting curve, and it is the core problem with one-off security training: the annual compliance video is fighting a decay curve it cannot win. Content reviewed once is largely gone within a week; content revisited at intervals consolidates into long-term memory.
Summaries of the spaced-learning research report the same direction of effect: a Harvard Business Review-cited study found spaced learning improves long-term retention by around 25% compared with massed (crammed) learning (microlearning for security - research summary), and analyses of microlearning in workplace training report retention improvements from the low twenties up to 60% depending on the study and the comparison (the power of microlearning in security awareness). Treat the exact numbers as study-dependent - but every credible source points the same way: repetition beats duration.
Australian government guidance agrees on the cadence, if not the classroom theory: the ACSC's small business advice is to "provide time for regular training" and make it part of induction for new staff (ACSC small business guidance) - regular beats heroic.
What five minutes can and cannot do
What a five-minute video can do well:
- Deliver one idea completely. One threat, one behaviour, one clear example. Microlearning works because it does not try to cover a whole syllabus at once.
- Show, not describe. A real-looking fake invoice or a real CEO-fraud email on screen teaches recognition faster than a bullet list ever will.
- Fit inside a workday. Completion rates collapse as runtime grows. Short modules get finished, and an unfinished hour of training has a retention rate of zero.
- Slot into a trigger moment. A five-minute module assigned the moment someone clicks a simulated phish lands when the lesson is relevant - which is the strongest learning context there is.
What it cannot do:
- Create a habit in one exposure. Habits need repetition and practice. One video is one exposure.
- Cover edge cases. Sophisticated business email compromise needs scenario depth that five minutes cannot carry - which is fine, because not everyone needs that module every month.
- Replace a response process. Knowing what a phish looks like matters less than knowing what to do next. Reporting behaviour is trained by making reporting one click away, not by watching longer videos.
The practice loop: where five minutes actually changes behaviour
The strongest reinforcement in security training is not another video - it is a safe rehearsal. That is the role of phishing simulations: a realistic fake email arrives in the real inbox, the employee either spots it or clicks it, and both outcomes feed a five-minute lesson. The click becomes the enrolment trigger for exactly the kind of short, timely module this article is about.
Run that loop monthly and the arithmetic is persuasive: one simulation plus roughly five minutes of follow-up per employee per month is about an hour a year of training time - comparable to the traditional annual session, but delivered in twelve spaced doses instead of one decaying block.
Building a five-minute cadence that works
- Monthly rhythm, not annual. One short module per month, topics rotating across the threats that actually hit your sector.
- Pair every simulation with its lesson. Click or report, everyone gets the two-minute debrief; clickers get the slightly longer coaching module.
- Vary the difficulty. Start with easy-to-spot phishes and escalate, so recognition develops rather than plateaus.
- Keep the reporting path visible. Every module ends with the same instruction: report it, here is the button.
- Track behaviour, not completion. Your human risk reporting should trend down on clicks and up on reports over months - that trend, not video watch-time, is the programme's evidence.
How to tell if your five minutes is working
Three signals, in order of reliability:
- Report rate rising over months. Reporting is the behaviour that stops real breaches, and it is trainable with short, repeated reinforcement.
- Click rate falling toward a stable floor. It will not reach zero - a persistent low rate on the hardest templates is normal and healthy, not a failure.
- Coaching engagement. If clickers actually complete their follow-up modules, the loop is working; if they ignore them, the five minutes is being wasted somewhere upstream.
If none of these move after two or three months, the problem is usually the cadence or the content fit - not the five-minute length. Before switching platforms, compare what you actually need against the options (compare awareness training platforms); often the fix is a tighter simulation-to-lesson loop rather than more content.
Common mistakes
- One video, once a year. Maximum exposure, minimum retention, no practice loop.
- Judging success by completion rates. Completion measures attendance; behaviour measures learning.
- Shaming the clickers. Fear suppresses reporting, which is the behaviour you most need.
- Same template every month. People learn the template, not the threat. Rotate and escalate.
- Five minutes of video with no follow-up action. Awareness without a next step decays fastest of all.
FAQ
Can a single five-minute video change behaviour at all? Temporarily, for simple recognition behaviours. Without spaced reinforcement, most of the effect decays within days - which is why the format works as part of a cadence rather than as an event.
Is five minutes enough for real security training? Five minutes per topic, repeated monthly, outperforms an annual hour on every retention measure in the research. Depth can come from a small number of longer modules for high-risk roles like finance.
What does the research actually show about microlearning? Published summaries consistently report better retention from spaced, short-form learning than from massed sessions, with gains in the 20-60% range depending on the study. The direction is consistent even where the exact percentages vary.
How often should we run short training? Monthly is the standard cadence for awareness training paired with phishing simulations; fortnightly suits higher-risk teams.
What should we measure? Click rate trend, report rate trend, and coaching completion. Those three numbers are the programme.