this post was submitted on 21 Oct 2025
176 points (97.8% liked)

Cybersecurity - Memes

3508 readers
1 users here now

Only the hottest memes in Cybersecurity

founded 2 years ago
MODERATORS
 

Sometimes I wonder whether all this "security awareness training" has any effect at all.

you are viewing a single comment's thread
view the rest of the comments
[–] nymnympseudonym@piefed.social 2 points 1 week ago (1 children)

You say that but do you have any objective data?

I'd love to see studies of phishing success in orgs that do vs. do not have regular trainings.

I bet it works like PSA advertising. It's stuff everyone should know and 98% of people already do. But it also helps keep the issues closer to conscious awareness and is actually educational for the 2%

[–] cron@feddit.org 6 points 1 week ago (1 children)

There is a 2025 study that was widely reported:

In summary, our results confirm the ineffectiveness of current phishing training approaches while offering a refined study design for future work.

arXiv:2506.19899

[–] nymnympseudonym@piefed.social 2 points 1 week ago

training interventions showed no significant main effects on click rates (p=0.450) or reporting rates (p=0.417), with negligible effect sizes

Thank you. I stand corrected, and with my Bayesian priors updated.