How often should you run security awareness training?

Monthly, quarterly or annually? What the 2026 benchmark data says about security awareness training frequency, and the cadence that keeps click rates down.

Short answer: security awareness training works as an ongoing monthly habit, not a once-a-year compliance event. The largest published dataset in the category — KnowBe4's 2025 benchmark of 67.7 million simulations across 14.5 million users in 62,400 organisations — shows why frequency matters: 33.1% of employees interact with a phishing simulation before any training, and only 4.1% after twelve months of ongoing training. Staff forget, attackers change tactics, and a single annual session does neither job.

Key takeaways

Why once a year is not a schedule

Annual training made sense when threats changed slowly. In 2026 they do not: AI-written lures, QR code phishing and deepfake voice calls now reach Australian inboxes between annual sessions. An employee trained in March faces attacks in November that did not exist when the course was written.

The decay is measurable. KnowBe4's 2025 data shows the share of staff who interact with a phishing simulation falls from 33.1% to roughly 5% within the first 90 days of ongoing training, then settles at 4.1% after a full year. The steep early fall comes from cadence: people see simulations repeatedly, click, receive a short lesson immediately, and stop clicking. Remove the cadence and the number climbs back toward one in three.

A monthly cadence that fits around real work

A workable rhythm for a small team looks like this:

The annual refresh still matters: insurers, auditors and frameworks such as the Essential Eight expect evidence of regular training. The mistake is treating it as the whole program.

Train on triggers as well as the calendar

Some of the most valuable training is not scheduled at all:

An automated platform handles all three. Cyber Aware's training enrols new starters automatically, delivers click-triggered refreshers after each phishing simulation, and rotates lessons monthly without anyone chasing spreadsheets.

How to tell your cadence is working

Frequency without measurement is a promise, not a control. Three numbers tell the truth:

  1. Click rate on simulations, trending month over month toward the 4.1% benchmark.
  2. Report rate — the share of staff who flag a suspicious email — which should climb as click rate falls.
  3. Repeat clickers — the same staff clicking again — which should shrink toward zero.

If click rate is flat after six months of monthly training, the content or the follow-up needs changing, not the calendar.

FAQ

Is annual security awareness training enough? It is the minimum many insurers and auditors ask for, but it is not enough to change behaviour. The benchmark data shows results decay without ongoing reinforcement, and 2026 scams evolve faster than an annual cycle.

How long should each session be? Short and regular beats long and rare: 5 to 10 minutes per month plus a simulation keeps training inside the working day instead of eating an afternoon.

When should new starters be trained? In their first week, before they rely on email for real work. New starters click at higher rates and are favourite targets for payroll and payment diversion scams.

What cadence do frameworks like the Essential Eight expect? Regular training with evidence. Monthly lessons and simulations with recorded results satisfy the intent; a single annual session does not.

Related guides

Ready to deploy

Same playbook.
Your brand.

Cyber Aware's Human Risk Score works the same way for every MSP partner - under your brand, on your cadence.