How often should staff do security awareness training?

Once a month is the 2026 standard for security awareness training: one short course plus phishing simulations. What a monthly cadence looks like in practice.

Monthly. In 2026 the working standard for security awareness training is one short course per staff member each month, backed by a steady phishing-simulation cadence — not a single compliance lecture every twelve months. The human element sits behind roughly 60% of data breaches (Verizon, 2025 DBIR), and the lures employees face change month to month, so reflexes taught last October are already out of date against what lands in inboxes this October.

TL;DR

How often should staff do security awareness training?

Once a month, with phishing simulations layered on top. A monthly session is short by design — a single story-driven course of a few minutes, plus the reminder emails and quiz results that keep it from being forgotten. The annual security lecture survives because it is easy to schedule, not because it works: it teaches 12 months' worth of material in one sitting and then gives that material 11 months to decay.

The difference is easiest to see side by side:

CadenceWhat it looks likeWhat it gets you
Annual lectureOne long session, then silence for 12 monthsA compliance tick-box; recall fades within weeks
QuarterlyFour touchpoints a yearBetter, but staff forget the material between sends
Monthly (recommended)One short course per month plus simulationsReflexes stay matched to the lures actually circulating

Why the monthly cadence beats the annual lecture

Lures change monthly. Over the past year the common templates have included fake Microsoft 365 sign-in pages, invoice fraud aimed at finance teams, WhatsApp "Hi Mum" impersonation, myGov and Medicare notices, and ASIC business name renewal scams. A programme that adds a new module every month can cover each of these as it appears; an annual curriculum cannot.

Recall decays faster than the calendar. People forget most of what they learn in a single session within weeks unless something reinforces it. Monthly training is spaced repetition in work clothes: the same reflexes — check the sender domain, verify the payment request by phone, report the suspicious email — get exercised again and again until they are automatic.

The attacker only needs one lapse. With the human element in roughly 60% of breaches, the cheapest attack against your business is the one message a busy person answers on a Friday afternoon. Frequency is what closes that gap, because the reflex has to be there on the day the real email arrives.

What a monthly cadence looks like in practice

A workable month runs like this:

  1. Enrol automatically. New hires land in the programme the day they start, picked up from Microsoft 365 or Google sync, a CSV upload or a signup link. Leavers are removed just as cleanly.
  2. Assign one course. Story-driven modules that dramatise a real event and end in a short quiz hold attention because each lesson runs minutes, not hours — awareness training built on story-based video lessons beats a 90-slide deck for the same reason a fire drill beats a fire poster.
  3. Simulate. Run a phishing campaign each month or quarter from a varied template library, with difficulty levels from "easy spot" to "hard to detect", ramping up as report rates climb.
  4. Remediate on fail. Anyone who clicks is auto-enrolled into the failed-phishing course. The click becomes a coaching moment instead of a shaming email, and the same learner is who your next campaign watches.
  5. Report. A monthly human risk report scores every learner from overdue courses, failed quizzes and phishing results, so "training happened" becomes "risk moved".

Run consistently, the results compound: twelve months of monthly training and simulated phishing cuts the share of staff likely to engage with a malicious email from 33.2% to 4.2% (KnowBe4, 2026 benchmarking report) — with the biggest gains arriving between month three and month twelve. No annual programme has ever produced that trajectory.

When a different cadence makes sense

Monthly is the default, not a rule without exceptions. High-exposure roles deserve more: finance teams handling payment approvals and executives who attract whaling campaigns should get short weekly micro-modules on top of the monthly course. Contractors and seasonal staff can sit on a lighter rhythm — onboarding training plus the annual refresher — as long as they are covered by the same simulations. What does not work is going lighter for everyone: the breach data has not rewarded annual training in a decade of MFA rollouts and mail filters.

Does monthly training mean more admin?

No — the cadence is a scheduling problem, and scheduling is what an awareness platform automates. Enrolment on arrival, a new course added each month, due and overdue reminders, remediation on fail and the client-facing report all run on a schedule you set once. A 20-person business runs the same monthly rhythm as a 500-person one; the only manual step is choosing, once a year, whether to escalate difficulty.

FAQ

How long should each monthly session take? Minutes. Short story-driven lessons with a quiz fit between meetings; the completion tracking matters more than the runtime.

How often should phishing simulations run? Monthly is ideal and quarterly is the floor. The simulations should vary templates and increase in difficulty as report rates improve.

Is annual training enough for compliance? It depends on the framework and the auditor, but auditors increasingly ask for evidence of ongoing activity — completion records, simulation results and reporting — not a certificate from last year.

Will staff get fatigued by monthly training? Fatigue comes from long, repetitive courses, not short relevant ones. A three-minute dramatised incident each month is easier to swallow than a two-hour annual catch-up.

How quickly will we see results? Expect the share of staff likely to click to fall from the global baseline of 33.2% to about 20.1% within 90 days of monthly training, and to 4.2% at twelve months (KnowBe4, 2026).

How do we know who needs extra help? The monthly human risk score ranks every learner from real behaviour — overdue courses, failed quizzes, phishing results — so follow-up goes to the people who need it, not to everyone equally.

One last thing

Watch your report rate, not just your click rate. Click rate tells you how many people took the bait; report rate tells you how many would raise the alarm on a real one. A team that clicks less but reports nothing is still blind — and cadence is what builds the reporting habit along with the spotting habit.

Related guides

Ready to deploy

Same playbook.
Your brand.

Cyber Aware's Human Risk Score works the same way for every MSP partner - under your brand, on your cadence.