A short security awareness module takes most people three to ten minutes to complete; a full-length compliance course typically runs 45 to 60 minutes; and a structured programme — short monthly modules plus occasional phishing simulations — adds up to roughly 60 to 90 minutes of an employee's entire year. The duration question matters less for the calendar than for the outcome: shorter, repeated lessons are consistently shown to be completed more often and retained better than one long annual session.
TL;DR
- Microlearning modules run 3-10 minutes each; a monthly cadence costs under two hours per employee per year.
- Annual 45-60 minute courses suffer from the forgetting curve — most material fades long before the next session.
- A hospital study found phishing-simulation click rates fell across repeated campaign rounds, supporting frequent short exposure over one-off training.
- Cyber Aware's awareness training delivers 120+ story-driven modules designed for short completions inside a working day.
Typical completion times by format
| Format | Typical length | When it's used |
|---|---|---|
| Microlearning module | 3-10 minutes | Monthly topic refreshers |
| Phishing simulation lesson | 3-5 minutes | Auto-assigned after a simulated click |
| Onboarding course | 30-60 minutes | New-starter induction |
| Annual compliance course | 45-60 minutes | Regulator or insurer requirements |
| Tabletop / workshop session | 60-90 minutes | Incident-response rehearsal |
For planning purposes, a practical rule: budget ten minutes per microlearning module, allow an hour for onboarding, and expect the annual compliance block — if your industry still requires one — to consume most of its hour per person, once a year.
Why duration matters more than it looks
Completion collapses as length grows. Anyone who has run an LMS knows the pattern: short modules assigned monthly are finished by nearly everyone; a 45-minute annual course sits in inboxes for weeks. The completion gap between short and long formats is one of the most replicated observations in workplace learning, and it matters because uncompleted training has a retention rate of exactly zero.
The forgetting curve erodes long courses first. Memory research going back to Ebbinghaus shows rapid initial forgetting that repetition flattens. A single annual session fights that curve with one repetition per year. Short modules repeated monthly align repetitions with the decay curve instead of racing it.
Behaviour decays after training too. A large study of nearly 20,000 healthcare employees across eight months of phishing simulations found that the protective effect of annual security awareness training faded measurably in the months after completion — employees who had recently completed training failed simulations less, and the effect weakened as time passed (Grantho et al., IEEE S&P 2025). The implication is direct: if your only training is annual, its effect is decaying for most of the year.
Repetition in simulation beats one-off instruction. In a hospital phishing-simulation case study, click rates fell significantly across successive rounds of campaigns (published in PMC) — for custom lures, from 55% in the first round to 21% in the second. Repeated, spaced exposure is itself the training mechanism.
How long your programme should be per person
For a small or mid-sized business, a defensible annual time budget looks like this:
- 12 monthly micro modules at 5-8 minutes: roughly 60-95 minutes a year.
- A short lesson after each simulated click (only for those who click): 3-5 minutes per event, typically once or twice a year per person.
- One onboarding hour for new starters, above the baseline.
Total: around two hours per employee per year, spread across the calendar — and none of it requiring anyone to block out an afternoon. That cadence is also what phishing programmes like Cyber Aware's simulations assume: a monthly rhythm where the training arrives in small doses the team actually finishes.
What stretches completion time (and what to do about it)
- Long single courses. Break 45-minute content into topic modules; completion climbs when each sitting has a visible end.
- Vague deadlines. Courses with due dates and a reminder cadence get finished; open-ended assignments drift for months.
- No relevance. Generic material reads as noise. Role-relevant scenarios (finance sees invoice fraud, executives see impersonation) hold attention and shorten the felt duration.
- Dead channels. Email-only nudges are easy to ignore. Completion improves when the platform follows up automatically rather than an admin chasing.
Measuring it properly
Duration is an input, not an outcome. Two numbers tell you more than any single completion stat:
- Average time-on-course. A five-minute module finished in 40 seconds by most of the team is a sign of click-through, not learning — good platforms flag abnormally fast completions.
- Behavioural trend. Phishing-simulation click rate over time is the outcome measure; if it is falling quarter over quarter while time-on-course stays normal, the duration you chose is working.
Both live in your human risk reporting, which is also what auditors and insurers increasingly ask to see: not that training happened, but that it changed something measurable.
FAQ
How long is a typical security awareness training course? A microlearning module runs 3-10 minutes; a phishing-simulation remediation lesson is about 3-5 minutes; a full onboarding or annual compliance course typically runs 45-60 minutes.
How much total time should an employee spend on security training per year? For most small and mid-sized teams, roughly 60-95 minutes of training plus 3-5 minutes per simulation lesson — achievable with a monthly microlearning cadence rather than one long annual session.
Is a long annual course better than short monthly ones? For retention and behaviour, no. The forgetting curve erodes annual training within months, and studies of repeated phishing simulations show click rates falling with spaced exposure — something an annual event cannot produce.
Do shorter modules actually get completed? Yes — completion is the main practical advantage of microlearning; short modules fit into a working day, while long courses sit overdue and inflate backlog metrics.
Can training be too short to matter? A module can be too short to change understanding, which is why the healthy signal is a normal completion time paired with improving simulation results — and why abnormally fast completions should be flagged rather than celebrated.
How do we prove completion time to an auditor? Export time-on-course and completion data from your platform; human risk reporting is built to export exactly that per learner and per course.
One last thing
The right question is not "how long should training be?" but "how often does it repeat?" A three-minute module that appears twelve times a year beats a sixty-minute course that appears once — in completion, in retention, and in the click-rate trend you can actually show an auditor.