Serious question. Is anyone actually happy with their security awareness training?
We’re revisiting ours and it feels like we’re just running the same playbook every year. Mandatory video. Quarterly phishing sim. Report goes to leadership. Repeat.
Click rates go down a bit. Cool. But I’m not convinced it translates to real-world behavior when something non-obvious hits their inbox.
Half the org treats phishing tests like a game. The other half just speed-clicks through training to get it done.
For those of you running this at scale:
Is there anything that actually changes behavior long term?
[link] [comments]
SOCIAL SHARE CARD GENERATOR