
The click rate of your last phishing simulation does not measure how well your company survives a real attack. It measures how convincing the simulation was.
Even so, security awareness training is one of the first items SMEs approve as soon as security comes up. Understandable: it is quick to buy, it produces numbers for reporting, and it feels like taking action. Hardly anyone asks the uncomfortable question. Which part of it protects, and which part is busywork?
Since last year there has been unusually good data on this. It is sobering, but useful. Once you know it, you distribute your budget differently.
What the largest field study found
Researchers from the University of Chicago and UC San Diego followed around 20,000 employees of a large healthcare provider over eight months and sent them ten realistic phishing simulations. They compared the formats sold here as well: the mandatory annual course and embedded training, which appears right after a bad click. The study is called "Understanding the Efficacy of Phishing Training in Practice" and was presented at the 2025 IEEE Symposium on Security and Privacy; a good German summary is available from IT-Administrator.
The results in short: the study found no significant correlation between the annual awareness course and later click behaviour. Embedded training lowered the failure rate by 1.7 percentage points on average. Only interactive modules that were fully completed reduced the risk of another click by around 19 percent. They were rarely completed in full, and static training pages showed no benefit at all.
Translated plainly: the format most companies buy, the annual course with a completion certificate, had no demonstrable effect on behaviour in this study. For your budget this does not mean training is forbidden. It means the burden of proof flips: the programme has to show what it delivers beyond curves.
The researchers' recommendation is uncomfortable for an entire industry: less weight on training, more on technical measures such as hardware-based multi-factor authentication and password managers.
A study is a study, and an American healthcare provider is not your business. But the finding matches what we observe in our mandates: click rates in simulations vary with the quality of the simulation, not with the date of the last course. And it explains something many IT managers know and rarely say out loud: the same workforce that dutifully passes the exercise still falls for the one well-made mail.
Why awareness gets bought anyway
Awareness training is the most convenient security purchase there is. It demands no change to processes and no intrusion into daily work. The auditor accepts it, the cyber insurer asks about it, and the dashboard delivers a curve every month that can be shown in a meeting.
The curve, however, suggests something it cannot prove: that a falling click rate in the simulation means rising resilience. The data does not support that connection. A falling click rate can equally mean the simulations were easier to spot, or that the workforce has learned to recognise exercise mails rather than attacks.
In our experience, the typical loss pattern in SMEs looks like this: the company has an awareness programme with respectable click numbers, and at the same time the accounting team transfers a supplier invoice to a new IBAN because the mail was flawless, the sender seemed familiar, and no call-back was required. The training worked, the way it is measured. The attack also worked, the way it is built. That both can happen at once is the core problem of the metric.
Add to that a timing problem. Classic training content teaches people to spot warning signs: clumsy language, forged sender addresses. Those signals are disappearing, because generative AI makes flawless, context-aware mails almost free. We covered this in more detail in Attackers at AI speed. A training that conditions people to look for typos prepares them for yesterday's attacks.
What training can deliver
This does not make awareness useless. It makes it the wrong lead actor.
There are three things a course can deliver in practice. First, the reporting routine. The greatest value of training comes after the bad click: the fast report. Whoever reports right after clicking turns a potential incident into an early warning, and IT can reset passwords and end sessions before anything happens. That only works if reporting is easy, goes to a place where someone looks, and is never punished. Concretely: a report button right in the mail client, feeding a mailbox someone reads the same day. A culture in which someone hides a bad click for two days costs more than any click rate.
Second, orientation for new employees: how do I report something, whom do I ask, which rules apply to payments. New people do not know the internal routines yet and are worse at spotting an unusual payment instruction as unusual. Half an hour of orientation in the first week covers that phase. That is onboarding, not an annual programme.
Third, the foundation for process discipline. The attacks that cost SMEs money run on trust: the payment instruction supposedly from the boss, the supplier with a new account number. Against a well-made deception, a rule helps more than a sharpened eye. A second-channel rule for payment approvals only works, though, if everyone has understood why it exists and that asking twice is routine, not distrust. Building that understanding is a legitimate training task, and it takes thirty minutes, not a platform.
One limit rarely gets said out loud: example beats course content. If management demands exceptions for itself, say no second factor on the boss's account because it is inconvenient, the organisation learns more from that exception than from any module.
What training cannot deliver: turning people into reliable spam filters. A company whose security depends on two hundred people never being distracted for a second on a Tuesday afternoon does not have a training problem. It has an architecture problem.
Three measures with more protection per franc
If the goal is phishing prevention rather than reporting, the list starts elsewhere.
- Phishing-resistant MFA. Passkeys or hardware keys, at minimum for email, finance systems and admin accounts. The difference from the code-per-app variant: stolen credentials and intercepted codes no longer work, no matter who clicked on what. It is one of the two measures the study authors recommend instead of buying more training.
- A password manager, rolled out properly. A password manager only fills in credentials on the real domain. On the fake one, the field stays empty, and that moment of irritation is more reliable than any trained eye. That is built-in phishing detection that never gets tired and needs no annual course.
- A second-channel rule for money and access. A supplier changing bank details, a payment approval above a defined threshold, a password reset requested by phone: always confirm through a second, independent channel, such as a call-back to the number you already know. Set the threshold so the rule survives daily work; a rule that triggers on every small payment gets quietly buried after three weeks. It costs nothing beyond an agreement in the team, and it stops exactly the attacks that are about money.
The comparison is worth doing in francs. Put the annual cost of your awareness platform next to the one-off cost of passkeys for the critical accounts, and then work out which item stops which attack. In our experience, that calculation rarely favours the platform. How to review such items systematically is covered in Consolidating security tools and in Right-sizing IT security.
And if your cyber insurer or a customer requires an awareness programme: a lean variant satisfies the requirement too. No questionnaire demands the most expensive platform on the market. A short onboarding module, a documented second-channel rule and a working reporting path meet the evidence requirement just as well, cost a fraction, and protect more. That is not a cost-cutting exercise, it is the order in which protection is built.
Before the next renewal
You do not have to cancel your awareness programme today. But it deserves the same standard as every other security item: which attack does it stop, and how do we know? Awareness rarely gets asked that question, because nobody wants to argue against training. Which is exactly why the item grows unwatched. Ask it three questions before the next invoice.
First: which concrete change in behaviour is the training supposed to produce, and how do we recognise it outside the simulation? "The click rate is falling" does not count as an answer.
Second: are phishing-resistant MFA and a password manager in place across the board? If not, why does the budget pay for the course first and the measure that demonstrably works second?
Third: is there a second-channel rule for payments and account changes, and has it ever been tested in daily work rather than only mentioned in a course?
If two out of three answers come with hesitation, you know where the next budget conversation has to start.
One question interests us here: how would you tell, in your own business, that a training has worked if you were not allowed to look at the click rate?
If you want to hold your security budget up against the protection it delivers, we are happy to do that together. An initial conversation is non-binding.



