What awareness training really achieves, in figures.
How effective is it to train people? Is it worth it? Research gives clear answers, and they are more emphatic than many expect.
68 %
of all data breaches run through people, mostly through social engineering or stolen login details.
Verizon Data Breach Investigations Report, 2024
What technology cannot prevent.
Firewalls, virus scanners and spam filters catch a large share of attacks. Building and running the perimeter is and remains the job of IT. What it cannot prevent technically: a convincing email, a credible phone call, a fake login form. These attacks take the official route, with valid credentials and a plausible request. No further product helps against that — only practice: recognising the attack and knowing what to do next.
€289 billion
total damage from cyberattacks on German companies in 2025. Of that, 202 billion euros from purely digital attacks.
Bitkom Wirtschaftsschutz-Studie, 2025
87 %
of German companies report data theft, espionage or sabotage. 59 % feel their existence is threatened by cyberattacks.
Bitkom, 2025
80 %
of the organisations attacked in Germany are small and medium-sized businesses. "Too small for attackers" is no longer a protection strategy.
BSI Lagebericht, 2025
What happens when you actually train people?
The question is fair: does it really help, or do people click anyway afterwards? The figures from studies with hundreds of thousands of participants are surprisingly clear.
33 %
of employees click on simulated phishing emails if they have never had awareness training. In Europe the figure is 32.5 %.
KnowBe4 Phishing by Industry Benchmarking Report, 2025
4 %
click rate after a year of regular training and phishing simulations. That is an 86 % reduction from the starting point.
KnowBe4, 2025
The progression in detail
Day 1
One in three employees clicks. That is the normal state without training — not a sign of particular carelessness, but of a lack of practice.
90 days
After three months of training the click rate falls by over 40 %. The training already shows a measurable effect.
12 months
The click rate is at 4 %, a reduction of 86 %. At this point the difference between trained and untrained teams is no longer subtle.
Why training once is not enough.
As early as 1885 the psychologist Hermann Ebbinghaus showed that people quickly forget what they have learnt if it is not repeated. Modern studies confirm his findings for the field of cybersecurity.
67 %
of what is learnt is forgotten after 24 hours
Murre & Dros, PLOS One, 2015
79 %
forgotten after one month without repetition
Murre & Dros, PLOS One, 2015
6 mo.
After six months without a refresher the training effect decays significantly
ISACA & various studies
The consequence: anyone who runs training once a year and then never brings it up again has, after six months, almost returned to the starting state. Training has to be repeated and combined with practical tests to have a lasting effect. ISACA recommends refreshers every four to six months, supplemented by regular simulations.
What it costs to do nothing.
Awareness training is often treated as a "soft" topic, but the figures on incident costs and savings are anything but soft.
$4.8 million
average cost of a phishing-caused data breach, worldwide. Included: forensics, legal costs, business interruption, reputational damage and regulatory fines.
IBM Cost of a Data Breach Report, 2025
$1.5 million
lower damage costs for organisations with an established awareness programme compared with those without. That corresponds to a reduction in average incident costs of over 30 %.
IBM Cost of a Data Breach Report, 2023
For perspective: awareness training for 50 employees costs under 2,500 € at secureIT. A single phishing data breach costs, on average, two thousand times as much. Even if training prevents just one incident in ten years, it has paid for itself many times over.
The threat landscape on your own doorstep.
The figures from the BSI (Germany's Federal Office for Information Security) and Bitkom show that German companies are not a sideshow but a prime target. Small and medium-sized businesses are especially affected.
- 119 new vulnerabilities per day, a 24 % increase on the previous year
- 950 ransomware reports, 72 % of them with a data leak
- 80 % of the organisations attacked were SMEs
- The threat level remains "tense"
- Total damage: 289 billion euros
- Phishing: 26 %, ransomware: 31 % of the damage
- 87 % of companies affected
- 59 % feel their existence is threatened
In the last 7 days alone, the BSI issued 27 warnings about software that runs in businesses every day — 1 of them rated critical.
Affected this week are, among others, Fortinet, Cisco Application Policy Infrastructure Controller, Cisco Nexus und Cisco NX-OS. The annual figures above are a look back; this is live operation.
The current situation in detail →Source: BSI warning and information service. As of 08.10.2026, 18:00.
What NIS2 says about it: the European NIS2 Directive explicitly obliges affected companies to carry out regular cybersecurity training. The GDPR requires "organisational measures", and staff awareness is one of them. Training is not a recommendation but a legal requirement. More on NIS2 and GDPR →
Five principles that separate effective training from box-ticking.
Not all training works the same. Research shows clear patterns of what works and what merely ticks a compliance box without changing behaviour.
Train first, then test.
A phishing test without prior training only measures that people click, and improves nothing. Training before the test turns the test into an exercise rather than a trap. Acceptance in the team rises because no one feels tricked.
secureIT: every phishing run requires a completed awareness training first. No course, no test.
Short and regular rather than long and one-off.
Short modules of 5–10 minutes, repeated regularly, build stronger retention than hour-long annual sessions. This is confirmed both by the forgetting curve and by the field studies from SANS and ISACA.
secureIT: the training consists of short, self-contained lessons. Repeat test runs can be booked as often as you like, without buying the training again.
Practice rather than theory.
Simulated phishing attacks are the most effective way to anchor what has been learnt. Organisations with regular simulations cut real phishing incidents by up to 50 %. The effect comes not from knowledge alone, but from the experience of recognising an attack under realistic conditions.
secureIT: three realistic phishing simulations per run, spread over five working days. Not an announced test, but emails that arrive in the normal working day.
Make mistakes reportable, not punishable.
The greatest danger after a click is not the click itself, but the silence that follows. Teams that report a wrong click immediately limit the damage. Teams that fear consequences keep quiet about the incident, and a single click becomes a security breach.
secureIT: the analysis shows group statistics, not individual names. No one is exposed. Whoever clicked immediately sees an explanatory page: not a reprimand, but an explanation.
Make the change measurable.
67 % of organisations cannot demonstrate the value of their awareness training because they do not measure results. Without measurement, training stays an expense; with measurement, it becomes a demonstrable improvement.
secureIT: the Cockpit shows click rates, completion rates and the trend over time. Every run provides data, and the certificates document who was trained and when.
Recognise, report, carry on.
No one needs to become a security system. It is about a skill needed everywhere today, at work and privately: noticing that something is off, saying so briefly, and then carrying on as normal. Anyone who knows what to watch for, and dares to report what is suspicious, gives IT the head start it needs for everything that follows.
Before
Employees do not recognise attacks, report nothing, and IT learns of incidents only once the damage has already been done. A typical company generates only around 4,000 data points a year with pure compliance training — too few to spot patterns.
After
Trained employees actively report suspicious emails. In a documented case study the number of reported phishing attempts rose 6.5-fold. The click rate fell from 16 to 4 %, and IT was able to detect and stop real attacks early.
Hoxhunt / Monster Energy, LyondellBasell
The point is not that no one clicks any more. That is unrealistic. The point is that the rate becomes so low that a single click can be caught, because the rest of the team recognises and reports the attack. And because the person who clicked says so at once, instead of hiding it.
Studies and reports
The figures on this page come from the following regularly published reports and studies:
- Verizon Data Breach Investigations Report (DBIR): annual analysis of real data breaches worldwide, 2024
- KnowBe4 Phishing by Industry Benchmarking Report: click rates before and after training, 2025
- IBM Cost of a Data Breach Report: incident costs and influencing factors, 2023 and 2025
- Proofpoint State of the Phish: user behaviour and awareness trends, 2024
- SANS Security Awareness Report: maturity model and best practices, 2024/2025
- BSI report on the state of IT security in Germany: threat landscape and vulnerabilities, 2025
- Bitkom economic protection study: damage statistics for German companies, 2025
- Murre & Dros, PLOS One (2015): replication of the Ebbinghaus forgetting curve
- ISACA: recommendations on training frequency
- ENISA NIS360 (2024): sector analysis of awareness levels in the EU
Are you affected by NIS2?
Five short questions, with the result shown instantly. Nothing is stored.
Convinced? Then get started.
The free self-test shows you in two weeks how vulnerable your own inbox is. For your team it starts at 49 € per person, a one-off payment with no subscription.
From my own practice.
Attacks explained rather than described: how specific scams work, what is currently going around and what really helps day to day.
Geotracking attacks: risks and safeguards
Geotracking technologies make it possible to track the location of a device or a person in real time. While this technology is used for legitimate purposes such as navigation or...
Read more →
Using a smartphone camera unnoticed to spy
1. How does the attack work? Attackers use social engineering to lure you to a prepared website that claims to show a video or some interesting content...
Read more →
Unlocking smartphones without knowing the PIN?
With a Flipper Zero, for example, you can unlock an Android smartphone. A security risk: 4-digit number PINs. Attackers could take over unsecured devices, execute...
Read more →
Hardware keyloggers, or how to get hold of any password in no time
CAUTION: one of the biggest invisible dangers to your IT security. Hardware keyloggers are tiny devices that look inconspicuous at first glance but pose a considerable...
Read more →
How to spoil attackers' plans by email
How to spoil attackers' plans by email: switch off automatic resource downloads. Emails are one of the most common methods cybercriminals use to spread malware...
Read more →
Email hacking via the SMTP protocol
We rely on emails being transmitted securely. Various service providers are responsible for this, depending on the route our emails take from sender to recipient...
Read more →
Why a (cloud) backup does not protect you from a ransomware infection
Sadly, numerous examples of successful encryption attacks (ransomware = ransom) show, as happened recently to a well-known bicycle manufacturer...
Read more →