Knowledge

What awareness training really achieves, in figures.

How effective is it to train people? Is it worth it? Research gives clear answers, and they are more emphatic than many expect.

Facts and figures Blog

68 %

of all data breaches run through people, mostly through social engineering or stolen login details.

Verizon Data Breach Investigations Report, 2024

Where technology stops

What technology cannot prevent.

Firewalls, virus scanners and spam filters catch a large share of attacks. Building and running the perimeter is and remains the job of IT. What it cannot prevent technically: a convincing email, a credible phone call, a fake login form. These attacks take the official route, with valid credentials and a plausible request. No further product helps against that — only practice: recognising the attack and knowing what to do next.

€289 billion

total damage from cyberattacks on German companies in 2025. Of that, 202 billion euros from purely digital attacks.

Bitkom Wirtschaftsschutz-Studie, 2025

87 %

of German companies report data theft, espionage or sabotage. 59 % feel their existence is threatened by cyberattacks.

Bitkom, 2025

80 %

of the organisations attacked in Germany are small and medium-sized businesses. "Too small for attackers" is no longer a protection strategy.

BSI Lagebericht, 2025

Effectiveness

What happens when you actually train people?

The question is fair: does it really help, or do people click anyway afterwards? The figures from studies with hundreds of thousands of participants are surprisingly clear.

Without training

33 %

of employees click on simulated phishing emails if they have never had awareness training. In Europe the figure is 32.5 %.

KnowBe4 Phishing by Industry Benchmarking Report, 2025

After 12 months of training

4 %

click rate after a year of regular training and phishing simulations. That is an 86 % reduction from the starting point.

KnowBe4, 2025

The progression in detail

Day 1

One in three employees clicks. That is the normal state without training — not a sign of particular carelessness, but of a lack of practice.

90 days

After three months of training the click rate falls by over 40 %. The training already shows a measurable effect.

12 months

The click rate is at 4 %, a reduction of 86 %. At this point the difference between trained and untrained teams is no longer subtle.

The forgetting curve

Why training once is not enough.

As early as 1885 the psychologist Hermann Ebbinghaus showed that people quickly forget what they have learnt if it is not repeated. Modern studies confirm his findings for the field of cybersecurity.

67 %

of what is learnt is forgotten after 24 hours

Murre & Dros, PLOS One, 2015

79 %

forgotten after one month without repetition

Murre & Dros, PLOS One, 2015

6 mo.

After six months without a refresher the training effect decays significantly

ISACA & various studies

The consequence: anyone who runs training once a year and then never brings it up again has, after six months, almost returned to the starting state. Training has to be repeated and combined with practical tests to have a lasting effect. ISACA recommends refreshers every four to six months, supplemented by regular simulations.

Costs & benefits

What it costs to do nothing.

Awareness training is often treated as a "soft" topic, but the figures on incident costs and savings are anything but soft.

$4.8 million

average cost of a phishing-caused data breach, worldwide. Included: forensics, legal costs, business interruption, reputational damage and regulatory fines.

IBM Cost of a Data Breach Report, 2025

$1.5 million

lower damage costs for organisations with an established awareness programme compared with those without. That corresponds to a reduction in average incident costs of over 30 %.

IBM Cost of a Data Breach Report, 2023

For perspective: awareness training for 50 employees costs under 2,500 € at secureIT. A single phishing data breach costs, on average, two thousand times as much. Even if training prevents just one incident in ten years, it has paid for itself many times over.

Germany

The threat landscape on your own doorstep.

The figures from the BSI (Germany's Federal Office for Information Security) and Bitkom show that German companies are not a sideshow but a prime target. Small and medium-sized businesses are especially affected.

BSI Lagebericht 2025
  • 119 new vulnerabilities per day, a 24 % increase on the previous year
  • 950 ransomware reports, 72 % of them with a data leak
  • 80 % of the organisations attacked were SMEs
  • The threat level remains "tense"
Bitkom 2025
  • Total damage: 289 billion euros
  • Phishing: 26 %, ransomware: 31 % of the damage
  • 87 % of companies affected
  • 59 % feel their existence is threatened
And today

In the last 7 days alone, the BSI issued 27 warnings about software that runs in businesses every day — 1 of them rated critical.

Affected this week are, among others, Fortinet, Cisco Application Policy Infrastructure Controller, Cisco Nexus und Cisco NX-OS. The annual figures above are a look back; this is live operation.

The current situation in detail →

Source: BSI warning and information service. As of 08.10.2026, 18:00.

What NIS2 says about it: the European NIS2 Directive explicitly obliges affected companies to carry out regular cybersecurity training. The GDPR requires "organisational measures", and staff awareness is one of them. Training is not a recommendation but a legal requirement. More on NIS2 and GDPR →

Findings

Five principles that separate effective training from box-ticking.

Not all training works the same. Research shows clear patterns of what works and what merely ticks a compliance box without changing behaviour.

01

Train first, then test.

A phishing test without prior training only measures that people click, and improves nothing. Training before the test turns the test into an exercise rather than a trap. Acceptance in the team rises because no one feels tricked.

secureIT: every phishing run requires a completed awareness training first. No course, no test.

02

Short and regular rather than long and one-off.

Short modules of 5–10 minutes, repeated regularly, build stronger retention than hour-long annual sessions. This is confirmed both by the forgetting curve and by the field studies from SANS and ISACA.

secureIT: the training consists of short, self-contained lessons. Repeat test runs can be booked as often as you like, without buying the training again.

03

Practice rather than theory.

Simulated phishing attacks are the most effective way to anchor what has been learnt. Organisations with regular simulations cut real phishing incidents by up to 50 %. The effect comes not from knowledge alone, but from the experience of recognising an attack under realistic conditions.

secureIT: three realistic phishing simulations per run, spread over five working days. Not an announced test, but emails that arrive in the normal working day.

04

Make mistakes reportable, not punishable.

The greatest danger after a click is not the click itself, but the silence that follows. Teams that report a wrong click immediately limit the damage. Teams that fear consequences keep quiet about the incident, and a single click becomes a security breach.

secureIT: the analysis shows group statistics, not individual names. No one is exposed. Whoever clicked immediately sees an explanatory page: not a reprimand, but an explanation.

05

Make the change measurable.

67 % of organisations cannot demonstrate the value of their awareness training because they do not measure results. Without measurement, training stays an expense; with measurement, it becomes a demonstrable improvement.

secureIT: the Cockpit shows click rates, completion rates and the trend over time. Every run provides data, and the certificates document who was trained and when.

The goal

Recognise, report, carry on.

No one needs to become a security system. It is about a skill needed everywhere today, at work and privately: noticing that something is off, saying so briefly, and then carrying on as normal. Anyone who knows what to watch for, and dares to report what is suspicious, gives IT the head start it needs for everything that follows.

Before

Employees do not recognise attacks, report nothing, and IT learns of incidents only once the damage has already been done. A typical company generates only around 4,000 data points a year with pure compliance training — too few to spot patterns.

After

Trained employees actively report suspicious emails. In a documented case study the number of reported phishing attempts rose 6.5-fold. The click rate fell from 16 to 4 %, and IT was able to detect and stop real attacks early.

Hoxhunt / Monster Energy, LyondellBasell

The point is not that no one clicks any more. That is unrealistic. The point is that the rate becomes so low that a single click can be caught, because the rest of the team recognises and reports the attack. And because the person who clicked says so at once, instead of hiding it.

Sources

Studies and reports

The figures on this page come from the following regularly published reports and studies:

  • Verizon Data Breach Investigations Report (DBIR): annual analysis of real data breaches worldwide, 2024
  • KnowBe4 Phishing by Industry Benchmarking Report: click rates before and after training, 2025
  • IBM Cost of a Data Breach Report: incident costs and influencing factors, 2023 and 2025
  • Proofpoint State of the Phish: user behaviour and awareness trends, 2024
  • SANS Security Awareness Report: maturity model and best practices, 2024/2025
  • BSI report on the state of IT security in Germany: threat landscape and vulnerabilities, 2025
  • Bitkom economic protection study: damage statistics for German companies, 2025
  • Murre & Dros, PLOS One (2015): replication of the Ebbinghaus forgetting curve
  • ISACA: recommendations on training frequency
  • ENISA NIS360 (2024): sector analysis of awareness levels in the EU
Quick check

Are you affected by NIS2?

Five short questions, with the result shown instantly. Nothing is stored.

To the NIS2 quick check

Convinced? Then get started.

The free self-test shows you in two weeks how vulnerable your own inbox is. For your team it starts at 49 € per person, a one-off payment with no subscription.

Free self-test See prices
Blog

From my own practice.

Attacks explained rather than described: how specific scams work, what is currently going around and what really helps day to day.

Set up in an hour, trained in a week.

Create a free account, add your team, unlock the course. You only pay when you start. Would you rather see what a test email looks like first? The self-test is free.

Add your team Test it yourself first