Elevaire Systems
← Back to Insights
Securitysecurity awareness trainingphishingcompliancecyber insurance

Security Awareness Training That Actually Changes Behavior

Elevaire Systems·

Most companies between 25 and 200 employees already run some version of security awareness training. An annual module, a slideshow, a short quiz at the end, a completion certificate that gets filed away for the next audit or insurance renewal. It satisfies the box on a SOC 2 report or a cyber insurance application. It does very little to change what an employee actually does the next time a convincing email lands in their inbox.

That gap between "we have a training program" and "our people are harder to phish" is where most of the value in this category gets lost, and it's a gap the research now describes in specific, measurable terms.

Why the Checkbox Version Doesn't Work

The clearest evidence on this comes from a randomized controlled trial run at UC San Diego Health, presented at the 2025 IEEE Symposium on Security and Privacy. Researchers tracked more than 19,500 employees over eight months across ten separate phishing campaigns, comparing annual training, embedded "just in time" training delivered after a failed simulation, and a control group that received neither. The result: there was no correlation between how recently an employee had completed annual training and how likely they were to fall for a phishing attempt. Employees who had finished training within the past month performed no better than employees who were more than a year overdue. Embedded training, which is considerably more targeted than an annual module, reduced the likelihood of clicking a phishing link by only about two percentage points.

That finding lines up with how the National Institute of Standards and Technology structures its own guidance. NIST Special Publication 800-50, revised in September 2024, deliberately separates "awareness" (broad, ongoing communication meant to shape culture and behavior) from "training" (role-specific skill building) and "education" (deeper, career-oriented learning). A once-a-year module tries to do all three jobs at once and does none of them well. It's built to produce a completion record, not a behavior change, and the data now backs that distinction up directly.

None of this means training doesn't matter. It means the version most companies run isn't the version that works.

What the Data Says About the Cost of Getting This Wrong

The stakes for treating this as a formality rather than a real control keep rising. Verizon's 2025 Data Breach Investigations Report found that the human element, meaning errors, social engineering, or misuse, was a factor in roughly 60% of breaches analyzed. That figure has stayed consistent for several years running, which tells you this isn't a problem organizations are gradually solving with better technology alone.

IBM's 2025 Cost of a Data Breach Report adds the financial dimension. Phishing overtook stolen credentials as the single most common way attackers get in, responsible for 16% of breaches studied, at an average cost of $4.8 million per incident. Those breaches also took an average of 254 days to detect and contain, nearly nine months during which an attacker had access before anyone noticed. Generative AI has made the problem harder to defend against on the front end too: the report notes that tools now used by attackers have cut the time needed to write a convincing phishing email from as long as 16 hours down to a few minutes, which means the emails your employees see today are better written and more personalized than what a training program built five years ago was designed to catch.

A company with 25 to 200 employees isn't absorbing a $4.8 million loss the way an enterprise might. For a business at that size, one successful phishing attack that leads to a wire transfer, a ransomware event, or a client data exposure is often an existential event, not a line-item cost.

What Actually Moves the Needle

The organizations that do see measurable improvement share a few characteristics, and none of them is "a longer annual training module."

Frequency beats duration. CISA's guidance for small and mid-sized businesses recommends monthly awareness touchpoints and phishing simulations run at least quarterly, not once a year. A five-minute exercise every month builds pattern recognition in a way a single ninety-minute session never will, because the skill being trained is largely about noticing something is off in the moment, not recalling a policy from memory.

Feedback has to be immediate and specific. Programs that deliver a short, targeted lesson within 24 hours of an employee clicking a simulated phishing link consistently outperform programs that save all feedback for a quarterly report. The employee remembers the specific email they clicked, not an abstract category of threat, and the correction lands while that memory is still fresh.

Behavior change, not knowledge transfer, is the actual goal. Industry benchmarking data covering tens of millions of simulated phishing tests across small and mid-sized organizations shows click rates on simulated phishing emails falling substantially within the first few months of a sustained program and continuing to decline the longer the program runs, in sharp contrast to the near-zero effect measured for one-time annual training in controlled studies. The difference isn't the content, it's the repetition and the reinforcement.

Near-misses are treated as data, not embarrassment. CISA's guidance specifically recommends building a culture where employees report suspicious emails without fear of blame, and where security goals show up in regular team communication rather than living in a once-a-year memo. An employee who reports a suspicious email and is right is a working control. A program that only measures failures misses that entirely.

The table below summarizes the practical difference between the two approaches.

ElementCompliance-Driven ApproachBehavior-Driven Approach
FrequencyOnce per yearMonthly awareness, quarterly simulations
Feedback timingEnd-of-year summaryWithin 24 hours of a failed simulation
Primary metricCompletion rateClick-rate trend over time
Reporting cultureFailures tracked, near-misses ignoredNear-misses logged and reinforced

What Compliance Frameworks and Cyber Insurers Actually Expect

Security awareness training shows up as a requirement across nearly every framework relevant to a growing company, but the specifics vary more than most people assume.

The HIPAA Security Rule does not specify an exact training frequency in its current form. What it requires is that training be ongoing, provided to the workforce at reasonable intervals, and reinforced through periodic security reminders between formal sessions, not delivered once and left alone. A proposed update to the Security Rule would move toward a more explicit twice-a-year cadence, which signals where regulatory expectations are heading even before it's finalized.

SOC 2's Trust Services Criteria, under the sections covering competence and communication of security responsibilities, don't dictate a specific curriculum or simulation frequency either. In practice, auditors have converged on a de facto standard: annual training for the full workforce, plus onboarding training for new hires within a defined window, typically 30 days. Anyone whose role touches access, incident response, vendor management, or customer data is expected to be covered, not just a technical team.

Cyber insurance underwriters have moved further and faster than either compliance framework. Mid-market applications increasingly ask not just whether training exists, but whether it includes active phishing simulation, and whether the organization can show a documented trend, not just a single point-in-time completion rate. A program built around real repetition and measurable improvement doesn't just reduce risk. It's also becoming the difference between a straightforward renewal and a coverage gap.

Building a Program That Actually Works

A practical program for a company in the 25-200 employee range doesn't need to be complicated. It needs four things in place, in this order:

  1. A monthly cadence, not an annual event. Short, five-to-ten-minute touchpoints beat a single long session every time. The goal is pattern recognition built over repetition, not a transcript of policy language.
  2. Quarterly phishing simulations with immediate, specific feedback. Simulations without fast feedback teach almost nothing, per the research above. The correction has to land within a day of the failed click, tied to the specific email the employee saw.
  3. A documented trend, not just a completion log. Track click-rate and report-rate over time, by department if the organization is large enough to make that meaningful. This is the evidence a SOC 2 auditor, a HIPAA compliance review, or a cyber insurance underwriter actually wants to see.
  4. A reporting culture with no penalty for a false alarm. Employees who flag something suspicious, correctly or not, should hear that it was the right call to check. A team that stops reporting because they're afraid of looking foolish is a team that stops being a control.

None of this requires a large budget or a dedicated security hire. It requires someone accountable for running it as an ongoing program rather than an annual compliance task, which is precisely the kind of ownership gap that tends to open up at this stage of growth.

Frequently Asked Questions

How much does a real security awareness training program cost?

Most simulation-and-training platforms suited to a 25-200 employee organization run somewhere between $2 and $6 per user per month, depending on the vendor and whether phishing simulation is bundled in. For a 100-person company, that's typically $2,400-$7,200 a year in platform cost, well below the $4.8 million average cost of a phishing-driven breach cited in IBM's 2025 report. The larger cost is usually internal time: someone has to own scheduling, review results, and follow up with repeat offenders, which is where many programs quietly stall out even after the platform is purchased.

Does this replace what our IT provider or MSP already does?

No, and it isn't meant to. Most managed service providers handle the technical side of security, patching, endpoint protection, email filtering, backups, but a documented, behavior-focused awareness program is a distinct discipline that requires its own cadence, its own metrics, and someone reviewing results and adjusting the program over time. Your MSP keeps the technical environment running. A well-run awareness program is a governance function that sits alongside it, not a replacement for it.

How is this different from the annual training we already run for compliance?

The content might look similar on the surface, but the design is different in ways that matter. A compliance-driven program is built to produce a completion certificate once a year. A behavior-driven program is built around monthly touchpoints, quarterly simulations, feedback delivered within a day of a mistake, and a tracked trend over time. Both can satisfy an auditor's checkbox. Only one of them actually reduces the odds that an employee clicks the next real phishing email.

What size company actually needs this beyond the compliance minimum?

Any organization handling client data, financial transactions, or protected health information benefits from moving past the annual minimum, but the case gets stronger specifically in the 25-200 employee range. That's typically where a company has enough systems and enough people that an informal "everyone just knows to be careful" approach stops covering the risk, but hasn't yet reached the size where a dedicated security function exists to own it formally.

How do we get started without over-investing before we know it's working?

Start with a baseline: run one unannounced phishing simulation before making any changes, and use the resulting click rate as your starting point. From there, move to monthly awareness content and quarterly simulations, track the trend for two quarters, and adjust based on what the data actually shows for your organization rather than assuming the vendor's default cadence is right for your team. A fractional IT leader can help set that baseline, choose a platform sized to your organization, and make sure the program is actually being reviewed rather than running unattended.

Who should own this program internally if we don't have a security team?

Ownership matters more than headcount. In most organizations this size, the program works best when it reports through IT leadership but is reinforced by department managers, since employees respond differently to a message that comes from their own manager than one that arrives from a platform nobody recognizes. What has to be avoided is the default outcome: a platform gets purchased, the first round of training goes out, and then nobody is accountable for the second, third, or fourth round. That's how a real program quietly reverts back to the annual-checkbox version it was meant to replace.

About Elevaire Systems

Elevaire Systems provides fractional Chief Information Officer (CIO), Chief Technology Officer (CTO), and Chief Information Security Officer (CISO) leadership, along with infrastructure modernization, intelligent automation, and compliance strategy for growing organizations.

Ready to Put This Into Practice?

Schedule a free consultation and let's talk through what this means for your organization specifically.

Schedule a Free Consultation