Stop buying the annual compliance module and start buying ten minutes of your team’s attention four times a year. That is the honest version of the advice, and it is uncomfortable because the annual module is the thing most businesses already pay for. The largest controlled study of phishing training published so far found almost no measurable benefit from it. What does work is narrower, duller and much cheaper: make reporting a suspicious message trivially easy, make the technical controls carry the weight, and keep the teaching short, specific and tied to the jobs people actually do.

What the research actually found
In 2025 a team of researchers from UC San Diego, UC San Diego Health and the University of Chicago published the results of an eight-month randomised controlled trial across more than 19,500 employees of a large healthcare system. Staff were sent ten simulated phishing campaigns. Some had completed annual awareness training recently, some long ago. Some who failed a simulation were given embedded training on the spot; others were not.
The results were blunt. There was no significant relationship between how recently someone had completed annual training and whether they failed a simulation. Embedded training, the intervention the industry sells hardest, was associated with a 1.7% lower failure rate on later simulations. Engagement with the training material was minimal: most people who were served a training page spent a few seconds on it and left. The authors concluded that anti-phishing training in its commonly deployed forms is unlikely to offer significant practical value in reducing phishing risk.
Ho et al., IEEE Symposium on Security and Privacy, 2025Anti-phishing training programs, in their current and commonly deployed forms, are unlikely to offer significant practical value.
That is one study, in one sector, in one country, and it measured simulated phishing rather than real compromise. Treat it as a strong signal rather than a verdict. But it lines up with something most IT teams already suspect: the people who click are not ignorant, they are busy. A convincing invoice arriving at 4:50pm on a Friday beats a slide deck watched eleven months ago.
The numbers that justify doing anything at all
The case for doing something has not gone away. The UK Cyber Security Breaches Survey 2025/2026, run for the Department for Science, Innovation and Technology and the Home Office across 2,112 businesses, found 43% had identified a breach or attack in the previous 12 months. Phishing was by far the most prevalent type, reported by 38% of all businesses, and among those who were breached, 69% described phishing as the most disruptive incident they faced. More than half of breached businesses (51%) experienced phishing and nothing else.
Read those two paragraphs together and the shape of the problem appears. Phishing is everywhere, and four in five businesses do nothing deliberate about staff behaviour. The answer is not to do nothing, and it is not to buy the annual module either. It is to do the small number of things that survive contact with a busy Friday afternoon.
The cost side is well documented. IBM’s 2026 Cost of a Data Breach Report puts the global average cost of a breach at USD 4.99 million, a 12% rise on the previous year and the highest figure in the report’s history. IBM also found that roughly one in four malicious breaches were AI-enabled, and those cost around USD 6 million. Those averages are dominated by large organisations, so do not read them as your bill. Read them as the reason attackers keep investing in better lures.
Why the annual module fails
The annual module fails for three structural reasons, and none of them are about content quality.
- The gap between learning and use is eleven months. Nobody retains a decision rule for a year when they apply it zero times in between.
- It is framed as compliance. People complete it to clear a notification, not to learn. The UC San Diego study measured exactly this: training pages were opened and abandoned within seconds.
- It teaches signals that attackers have fixed. Bad spelling, odd greetings and dodgy sender names were useful tells in 2015. Generative tools removed them.
There is a fourth, softer reason. Annual training quietly moves responsibility onto the person at the keyboard. When the inevitable click happens, the organisation has a record showing the employee was trained, which makes the click look like a personal failing. That is the fastest way to guarantee the next person who clicks says nothing for two days. Silence is the expensive part, not the click.

What to teach, and what to stop teaching
Cut the curriculum down to the handful of decisions that actually cause losses in small and mid-sized businesses. Everything else is interesting rather than useful.
- Payment changes always get a callback. Any request to change bank details, by email or message, is verified by phoning a number you already hold. Not the number in the email.
- Approval requests that create urgency get slowed down. The pressure is the attack. Teach people that urgency is the signal, not the spelling.
- A login prompt that appears after clicking a link is treated as hostile. Navigate to the service yourself, or use the bookmark. This single habit defeats most credential harvesting.
- Unexpected MFA prompts get reported, never approved. Push fatigue works because approving is one tap and reporting feels like admin.
- Reporting is always the right answer. Including when you already clicked. Especially then.
Stop teaching people to hover over links and inspect domains. It is a skill that fails under time pressure and on a phone, and it puts the burden in the wrong place. Our guide to stopping phishing attacks on your business covers the filtering and authentication side, which is where most of the real reduction comes from.
Teach role-specific content instead of generic content. Finance needs the payment-change drill. Whoever owns your domain registrar and DNS needs to know what a transfer-auth email looks like. Developers need to know that a package name one character off the real one is a supply chain attack. Thirty people do not need the same twenty minutes.
Running simulations without making enemies
Simulations are the most resented part of this whole practice, and usually deserve it. The common failure is treating them as a trap: a realistic lure, a league table of who failed, and a manager conversation afterwards. That produces fear and under-reporting, which is worse than where you started.
Run them differently. Announce that simulations happen, without announcing when. Never name individuals in any report that leaves the IT team. Make the landing page for a failed test two sentences and a link, not a ten-minute course. And do not use lures built on bonuses, redundancies or payroll errors. You will win the test and lose the room, and the next real phish will go unreported because people assume it is another exercise.
| Approach | What the evidence says | Effort per person per year | What it actually changes |
|---|---|---|---|
| Annual compliance module | No significant link between recency of training and simulation failure (UC San Diego Health trial, 19,500+ staff) | 45-60 minutes | Produces an audit record. Little measurable behaviour change. |
| Embedded training after a failed simulation | 1.7% lower failure rate on later simulations; minimal engagement with the material | 5-10 minutes | A small real effect. Cheap enough to be worth keeping if it is brief. |
| Quarterly role-specific session | Not isolated in the trial; aligns with NCSC guidance to focus on the processes attackers abuse | 60-80 minutes | Changes specific procedures, such as verifying payment changes by phone. |
| One-click report button plus a no-blame rule | Not a training intervention; shortens detection time, which drives IBM’s breach-cost variation | 2 minutes, once | Turns staff into sensors. The highest-leverage item on this list. |
| Phishing-resistant MFA | Removes the value of a harvested password rather than the chance of the mistake | 15 minutes to enrol | Breaks the attack chain. Do this before you buy any training. |

Reporting is the metric worth tracking
Click rate is the metric every vendor dashboard puts at the top, and it is close to useless on its own. A hard lure produces a high click rate; an easy one produces a low one. You can move the number either direction by changing the test, which means the number tells you about your test design rather than your risk.
Track three things instead. First, the report rate: what share of people who received a suspicious message told you about it. Second, time to first report, measured in minutes from delivery. Third, the share of real reported messages that turned out to be malicious, which tells you whether people are reporting thoughtfully or reflexively. A team where 30% of recipients report within fifteen minutes is in far better shape than a team with a 3% click rate and no reports at all.
A twelve-month plan that fits around real work
Here is the whole programme for a business of twenty to eighty people. It costs about four hours of everyone’s year and a few hours of yours.
- Week one. Deploy the report button in your mail client and write the no-blame rule down in one sentence. Tell everyone what happens when they press it, including who sees it and how fast.
- Week two. Turn on phishing-resistant multi-factor authentication for email, remote access and anything holding customer data. Our multi-factor authentication guide walks through the order to do this in.
- Month one. Twenty minutes with finance on the payment-change callback rule. Write the rule into the actual payment process, not into a policy document.
- Month four. First simulation. Measure report rate and time to first report. Publish only aggregate numbers.
- Month seven. Twenty minutes with whoever handles customer records on data access and sharing, and a tabletop walk-through of a ransomware morning. Our ransomware protection guide has the backup side.
- Month ten. Second simulation, different lure family. Compare report rates, not click rates.
- Month twelve. Thirty minutes reviewing what was reported during the year, what was real and what you changed as a result.
Notice how much of that is process and tooling rather than teaching. That ordering is deliberate. The Verizon 2026 Data Breach Investigations Report, drawing on more than 22,000 confirmed breaches, found that for the first time in nineteen editions the leading initial access route was exploitation of software vulnerabilities rather than stolen credentials, with credential abuse accounting for 13% of breaches. People are not the only door, and in 2026 they are not even the widest one.

What to do in the ten minutes after someone clicks
Write this down before you need it, because the ten minutes after a click decide how expensive the incident becomes. The person who clicked should have one instruction: tell the named contact immediately, whatever time it is, and do not try to fix it first.
- Reset the password and revoke active sessions and refresh tokens for that account. A password reset alone leaves a signed-in attacker signed in.
- Check for new mailbox rules, forwarding addresses and app passwords. Mailbox rules are the usual first move in business email compromise.
- Check whether the same credentials are used anywhere else, and kill those sessions too.
- Tell finance that an account is compromised before telling anyone else. Payment redirection is the monetisation step.
- Keep the original message. It is the best indicator of what else to search for.
Then say thank you, in public, to the person who reported it. That one sentence buys you more future reports than any module will. If you want help wiring up the reporting path, the controls and the quarterly rhythm, our cybersecurity services cover exactly this scope, delivered remotely.
Frequently asked questions
Should we stop phishing simulations entirely?
No, but change what you use them for. They are a useful way to measure whether people know how to report and whether the reporting path works under load. They are a poor way to grade individuals. Run two a year, publish aggregate numbers only, and keep the post-failure page to a couple of sentences rather than a course.
If training barely works, why does our insurer ask about it?
Because underwriters price on documented controls, and training is easy to document. Having a programme in place is often part of the questionnaire regardless of the research. The practical answer is to run something genuine and cheap, record that you ran it, and put the saved budget into the controls that reduce actual loss.
How much should a business of fifty people spend on this?
Far less than most quotes suggest. The report button is usually included in your mail platform, and phishing-resistant MFA is included in most business plans too. The real cost is four or five hours of internal facilitation a year. Spend on the controls first and on content only if there is money left.
What single change makes the biggest difference?
Phishing-resistant multi-factor authentication on email. It turns a harvested password from an incident into a nuisance. CISA makes the same point in its guidance on living off the land techniques: attackers increasingly use valid credentials rather than exploits, so making credentials insufficient on their own is the structural fix.
Does any of this apply if we are fully remote?
More so. Remote teams lose the informal check where you lean over and ask a colleague whether an email looks right. Replace it deliberately: a dedicated chat channel where anyone can paste a screenshot and ask, with no judgement and a fast answer. Cheap, and it catches a surprising amount.
If you want a security awareness programme that takes four hours of your team’s year and actually changes how payments get approved, we can set it up and run the first two quarters with you. Get in touch with Eudora Technology to talk about your project.
Sources
- Cyber Security Breaches Survey 2025/2026
- Understanding the Efficacy of Phishing Training in Practice
- Cybersecurity training programs don’t prevent employees from falling for phishing scams
- Cost of a Data Breach Report 2026
- 2026 Data Breach Investigations Report
- Phishing attacks: defending your organisation



