In 2025, researchers at UC San Diego published an eight-month study of about 19,500 UC San Diego Health employees. People who had recently finished their annual security training failed phishing tests at about the same rate as people who hadn’t. That finding reshapes how cybersecurity training for employees should work, without making it any less necessary.
This guide covers what the research says, what a program that changes behavior looks like, how to run phishing simulations people learn from, and what HIPAA and the FTC Safeguards Rule expect you to keep on file.
Why your staff are still the main target
A convincing email, text or call can hand over a password, approve a fake invoice or install remote access software with no exploit needed. Attackers go after people because it is cheaper than breaking technology.
62%
of breaches in Verizon’s 2026 Data Breach Investigations Report involved a human element, up from 60% the year before.
The channels are shifting too. Verizon reports that in phishing simulations, the median click rate for mobile lures such as text messages and voice calls was 40% higher than for email. It also found that 45% of employees regularly use AI on their work devices, approved or not. Training that covers only email misses where many attacks now start, as our post on AI-driven phishing shows.
What the research says about cybersecurity training for employees
The UC San Diego study found no meaningful difference in phishing failure rates tied to recent annual training. The short lessons shown right after someone clicked a test reduced clicks by only about 2%, and most people spent a minute or less on them.

The UK’s National Cyber Security Centre makes the same point: no training package, including phishing simulations, can teach people to spot every phishing attempt. Some lures are simply very good.
So training has two jobs. The first is to lower the odds that someone falls for the obvious stuff. The second, and more important, is to make sure that when someone does click, they tell you right away so the damage can be contained.
What a good program covers
- Training in a new hire’s first week, before bad habits form.
- Short, regular lessons of a few minutes each instead of one long annual session.
- Phishing in every form: email, text messages, QR codes, fake login pages, voice calls and social media messages.
- Calling back on a known number to confirm any request to change bank details or send money.
- Unique passwords in a company password manager, and never approving an MFA prompt you didn’t start.
- Which AI tools are approved, and what data never goes into them.
- One simple way to report a suspicious message, and a named person to call.
Write the rules into a short policy handbook that every new hire signs and that you review at least once a year.
How we run phishing simulations
Training is required for every one of our clients. Phishing simulations run continuously and automatically, so there is no big annual campaign for people to brace for. When someone clicks, they get a short micro-training lesson on the spot, and the click is reported to the client.
The UC San Diego numbers are a fair caution about that kind of lesson: on its own it changes behavior only a little. That is why the client sees each click, why the simulations never stop, and why we pair training with technical controls that assume someone will eventually fall for a good lure.
If you run your own program on Microsoft 365, Attack simulation training in Microsoft Defender for Office 365 can run credential harvesting, malicious attachment, OAuth consent and QR code simulations. Microsoft says it requires Microsoft 365 E5 or Defender for Office 365 Plan 2, with a limited trial for E3.
Build a culture where people report mistakes
The NCSC is blunt that blaming users for clicking links doesn’t work, and that people who fear reprisals report late, if at all. Leaders should take the same training and talk about it. Thank people who report a real phishing email, or admit they clicked one, because they just helped protect the organization. Name one approachable person in each office whom staff can ask without feeling silly.
October is Cybersecurity Awareness Month. CISA’s 2026 campaign, Securing the Next 250, again urges people to report phishing, use strong unique passwords, turn on MFA and keep software updated, which makes it a good time to review your program.
What HIPAA and the FTC Safeguards Rule require
The HIPAA Security Rule requires covered entities and business associates to run a security awareness and training program for all workforce members, including management. Security reminders, protection from malicious software, log-in monitoring and password management are addressable parts of it. See how we support healthcare practices.
The FTC Safeguards Rule requires covered financial firms, including many accounting and tax practices, to give personnel security awareness training that is updated to reflect risks found in the risk assessment. More on IT for accounting and financial firms.
Either way, an auditor or investigator will want proof. Keep completion records, simulation results, policy acknowledgments and the dates you updated content. Our compliance services keep that documentation in one place.
Controls that catch what training misses
The UC San Diego researchers concluded that organizations should lean on technical safeguards such as two-factor authentication and password managers that fill in credentials only on the correct site. Assume someone will click, and make sure the click doesn’t become a breach:
- MFA on email, remote access and every cloud app that supports it, with number matching so a push bombing attack can’t wear someone down.
- A business password manager, so staff never type a saved password into a fake login page.
- Email filtering that removes most phishing before anyone sees it.
- Endpoint protection watched by a 24/7 security operations center, so a device that runs something malicious can be isolated quickly.
- Tested backups, so a bad click becomes an inconvenience.
All of this is part of our cybersecurity program, and training reaches beyond security in our guide to targeted IT training. If you aren’t sure how your team would handle a convincing phishing text tomorrow, book a 20-minute call and we’ll give you an honest read.
FAQ
Frequently asked questions
How often should employees get cybersecurity training?
Train new hires in their first week, then keep lessons short and regular, with phishing simulations running throughout the year. A single annual session showed little measurable effect in recent research.
Should we discipline employees who fail a phishing test?
No. Punishment teaches people to hide mistakes, and the UK NCSC warns that staff who fear reprisals report late or not at all. Coach privately and thank people who report.
What is a good phishing simulation result?
Look at how many people report the message and how quickly the first report arrives, as well as the click rate. A rising report rate means your team is acting as an early warning system.
Sources: Verizon 2026 Data Breach Investigations Report; UC San Diego Today: Cybersecurity training programs don’t prevent employees from falling for phishing scams, 2025; Ho et al., Understanding the Efficacy of Phishing Training in Practice, IEEE S&P 2025; UK NCSC: Phishing attacks, defending your organisation; Microsoft Learn: Get started using Attack simulation training; 45 CFR 164.308 (HIPAA Security Rule administrative safeguards); 16 CFR 314.4 (FTC Safeguards Rule elements); Industrial Cyber: CISA launches Securing the Next 250 campaign, October 2026; NIST SP 800-50 Rev. 1, Building a Cybersecurity and Privacy Learning Program, 2024.




