Security awareness training has become a standard practice across enterprises, with virtually every organization requiring employees to complete some form of it. Yet despite this near-universal adoption, the actual value of these programs is far from settled. Whether they meaningfully reduce risk or simply check a compliance box is an open question.
The debate over effectiveness does not mean the practice is obsolete. Rather, it suggests that the current approach is due for a serious reassessment. The conversation is shifting from whether to run such training to how it should be designed, delivered, and measured to produce real security outcomes.
A rethink would likely involve moving beyond generic, one-size-fits-all modules toward more targeted and engaging methods. The goal is not to abandon training but to make it relevant enough to influence everyday employee behavior in a meaningful way.