How to get staff to actually complete security awareness training

Completion, not content, is where awareness programmes fail. Practical fixes for deadlines, auto-enrolment and manager visibility that lift completion above 95%.

Assignment is easy; completion is the hard part. Most awareness programmes do not fail because the content is bad — they fail because a third of the team never finishes the course, the deadline passes quietly, and the completion report is quietly not opened again. The stakes are real: before training, roughly one in three employees interacts with a phishing email, and KnowBe4's 2025 Phishing by Industry Benchmarking Report measured that global baseline phish-prone rate at 33.1%. Getting those people through training is the whole point of the programme. Here is what actually moves completion rates.

Why staff do not complete training

Almost never out of malice. The usual causes:

Notice what is not on that list: the training itself. Fix the mechanics first; polish the content second.

Make it short enough to finish

The single biggest completion lever is course length. Modules of 5-10 minutes fit between meetings and actually get finished; anything over 30 minutes gets bookmarked and forgotten. Split one long annual course into twelve short monthly modules and completion usually rises without any other change — the unit of work becomes small enough to do immediately.

Platform design matters here. Cyber Aware's security awareness training is built around short modules precisely because completion is the metric that predicts whether phishing click rates fall — the benchmark data shows click rates drop by about 40% within 90 days only when people are actually completing the ongoing training.

Set a deadline with a grace period

A hard due date plus a short grace window beats both extremes. The pattern that works:

  1. Assign the module on the 1st of the month.
  2. Send reminders at day 7 and day 21 — from a named person or the platform, not a no-reply address.
  3. Close the module on day 25, with a visible escalation for the remaining few.

One predictable rhythm per month outperforms irregular campaigns, because staff learn the pattern: this is the training week, I do it, it is done.

Auto-enrol from your directory

Manual enrolment is where new starters and contractors get lost. Sync enrolment from Google Workspace or Microsoft 365 so every active account is in the programme from day one, and leavers drop out automatically. No spreadsheet, no gaps, and the completion percentage stops being silently deflated by people who left the company in March.

Make progress visible — to managers, not just IT

Completion moves when the line manager sees their own team's number. An IT admin emailing “your team is at 61% complete” changes behaviour in a way a global reminder never will. The practical version: a dashboard that splits overdue courses by team, sent weekly to each manager for their own people.

This is where human risk reporting earns its keep — it turns overdue modules, failed quizzes and phishing simulation clicks into a per-person and per-team view, so the conversation with a manager is “four people on your team have not completed” rather than a company-wide nag.

Pair completion with the phishing programme

Training completion and phishing simulation performance reinforce each other. A monthly phishing simulation gives every completed module a reason to exist — staff see a realistic email, report it or click it, and the follow-up micro-module lands while the lesson is fresh. Teams that only complete courses without ever being tested regress; teams that are tested monthly keep the habit.

One tone rule: a failed simulation should trigger a two-minute refresher, never a public shaming. Punishing clicks teaches staff to hide clicks, which destroys the reporting culture you are trying to build.

What to do about the stubborn last 10%

Every organisation has a residual group — usually senior people and field staff — who will not complete through normal channels. Escalate in order:

  1. Direct reminder from their own manager, naming the specific outstanding module.
  2. A five-minute calendar hold booked by the manager, so the training occupies real time.
  3. For the last few, a one-on-one walk-through — 10 minutes of someone's time closes more gaps than a month of reminders.

Do not chase 100% forever. A stable 95%+ with the remainder actively escalated is a healthy programme; a permanent 70% that nobody reacts to is not a programme at all.

What good looks like by day 90

If completion is stuck below 80%, the problem is almost always deadline mechanics or manager visibility, not the content.

FAQ

How long should each module be?

5-10 minutes. Short modules get finished; long courses get bookmarked. Split one annual hour into twelve monthly segments.

How many reminders should we send?

Two to three per cycle, from a named sender, spaced across the month. More reminders than that trains people to ignore the sender.

Should completion be mandatory?

For roles with access to email, payments or client data — yes, with manager escalation. Mandatory-with-support consistently outperforms optional, because optional programmes quietly select out exactly the people who most need the training.

Do completion certificates matter?

They matter as evidence for insurers, clients and frameworks — dated completion records are increasingly asked for at renewal and in security questionnaires. But treat them as the byproduct, not the goal; the goal is the click rate moving.

How do we handle senior staff who won't complete?

Have their direct report or the CEO's office send the reminder — a peer or superior request closes most executive gaps where a system email never will.

One last thing

Before redesigning anything, pull one number: your current completion rate on the most recent module. If it is under 80%, fix deadlines, enrolment and manager visibility first — no content change will compensate for modules nobody opens.

Sources

Ready to deploy

Same playbook.
Your brand.

Cyber Aware's Human Risk Score works the same way for every MSP partner - under your brand, on your cadence.