BLOG

How to get employees to engage with security training

Aug 14, 2026

Employees engage with security training when it is short, relevant to their actual role, delivered regularly rather than annually and free of blame. Engagement improves further when leadership takes part visibly, when feedback arrives at the moment of a mistake and when the content is useful in their personal life as well as at work.

Engagement is the quiet problem in most awareness programmes. The content is fine, the platform works and completion sits in the high nineties because chasing people is something IT teams have become very good at. Yet the click rates barely move, and everyone involved suspects that a large share of the workforce is opening modules in one window while working in another.

That is not a failure of willpower on the part of employees, but a design problem. Security training competes for attention with the actual job and it usually loses because it is longer than it needs to be, aimed at nobody in particular and framed in a way that makes people feel accused. Fix those three things and engagement follows.

Why do employees disengage from security training?

The most common reason is length, a forty five minute annual course asks for a block of time that most people do not have, so it gets deferred until the deadline and then rushed, nothing in that pattern produces knowledge retention.

The second is irrelevance, a warehouse supervisor sitting through a module on wire transfer fraud learns that this programme is not really about them and that impression carries over to the next module which might have been directly relevant. Generic content trains people to ignore the channel.

The third is tone, a great deal of security content is built on fear and on the assumption that the employee is the 'weakest link'. People disengage from material that treats them as a liability and worse, they become reluctant to report mistakes because the framing has told them mistakes are shameful.

The fourth is timing, training delivered in a quiet week has no connection to the moment when a convincing message actually arrives, without that connection, the knowledge stays theoretical.

What does engagement actually mean here?

It is worth defining, because completion rate is routinely mistaken for engagement and the two are not related. Completion means a module was opened and closed, engagement means attention was paid and something changed as a result.

The only reliable evidence of engagement is behavioural: Did the click rate on simulations fall? Did the reporting rate rise? Did the finance team start verifying payment changes by phone? Those are the signals worth tracking and our guidance on cyber security awareness training covers how to build reporting around them.

Keep it short and make it frequent

Short modules delivered regularly outperform long modules delivered annually on almost every measure, and this is the model NCSC has advocated for years. Five to ten minutes is enough to cover one idea properly and one idea properly covered beats six that are covered superficially.

Frequency does the work that length cannot because a topic revisited every few weeks builds a habit, whereas a topic covered once a year builds a memory that has faded by the following month. It also spreads the time cost across the year, which matters enormously in organisations where staff have no natural gaps in the day.

Make it relevant to the role

Segmentation is the fastest available improvement to engagement and it costs nothing beyond a little setup. Finance and procurement need depth on invoice fraud and payment diversion, because that is the attack that will be aimed at them. HR needs recruitment fraud and data handling, executives and their assistants need impersonation and whaling, since they are the highest value targets in the organisation. Frontline and operational staff need physical security, device handling and the basics done well.

Everybody needs the fundamentals, but almost nobody needs all of it. Assigning the whole library to the whole workforce is the surest way to teach people that the programme is not aimed at them. Our guidance on cyber security training for employees covers how to segment without creating administrative overhead.

Make it useful outside work

This is the most underused lever available, people care more about their own money, their own accounts and their family's safety far more than they care about an abstract corporate risk. Content that covers scams people actually encounter, such as fraudulent delivery texts, bank impersonation calls, marketplace fraud and account takeover, earns attention that a policy module never will.

The skills transfer directly and someone who has learned to distrust an urgent text about a missed parcel is applying the same instinct when an urgent email about an overdue invoice arrives at work. Framing security as something that protects them personally rather than something the organisation requires of them, changes the entire relationship with the programme.

Remove the fear

A blame free culture is not a soft option, but the single most practical thing you can do to improve both engagement and detection. Say plainly, in writing and from a senior name, that reporting a mistake will never be a disciplinary matter and that reporting something which turns out to be genuine is a good outcome.

Then behave consistently with it, report simulation results at team level rather than naming individuals and treat repeat clickers as a group needing support rather than sanction. When someone senior clicks a simulated link, handle it exactly as you would handle anyone else, because that is the moment the policy is actually tested and the organisation is watching.

Deliver feedback at the moment of the mistake

Timing beats volume, a sixty second explanation delivered the instant someone clicks a simulated link lands harder than a module delivered three weeks later, because it attaches to a decision the person genuinely made in that moment, rather than a hypothetical one from weeks ago.

This is what makes phishing simulations a teaching tool rather than a testing tool. Run them continuously at varying difficulty, pair every click with immediate and constructive feedback and keep that feedback short. The effect compounds: Our analysis of more than 400,000 platform users found untrained users are 8.8 times more likely to click a phishing email than trained users and repeated contextual reinforcement is what produces that gap.

Get leadership and champions visibly involved

Employees read participation, not policy. If the executive team is exempted from training and simulations, everyone knows what that means, and no amount of internal communication will undo it.

Ask leadership for specific and visible acts like taking the same training as everyone else and talking about it. Mention the behavioural trend in a leadership updates and tell the story when a real phishing campaign was caught early because somebody reported it, because one credible story of reporting being welcomed does more than a quarter of awareness messaging.

Then build a champion network, meaning one trusted person in each function or site who colleagues will actually ask when they are unsure about a message. Engagement spreads sideways between peers far more readily than it travels down from a central team.

Recognise progress rather than punishing failure

Share team level improvements and let departments see how they compare, framed as friendly competition rather than exposure. Social proof is a stronger motivator than instruction, so tell a team that 64% of their colleagues reported last month's simulation rather than telling them reporting is important.

Thank people who report, including the ones who report genuine messages. A short automatic acknowledgement costs nothing and turns reporting into an action with a visible result rather than a message disappearing into a mailbox.

How do you measure engagement?

Retire completion rate as the headline and keep it for the compliance file. Track the behavioural indicators instead: Simulation click rate over time, reporting rate over time, the ratio between the two, time to first report and the size of the repeat clicker group. Segment all of them by department, because an organisational average will hide the team that has stopped paying attention.

Add a short annual pulse survey asking whether people know how to report, whether they would be comfortable doing so after a mistake and whether the content feels relevant to their job. The answers usually explain the behavioural data before the behavioural data explains itself.

What about the people who still will not engage?

There will always be a small group, and the answer is targeted support rather than escalation. Identify repeat clickers from the data, then give them something different from what has already failed to work: A short conversation with their champion, a focused module on the specific scenario they fell for or a higher frequency of simulation with immediate feedback.

Where a behaviour keeps recurring across many people, treat it as a process problem rather than a people problem. If credential reuse persists, deploy a password manager. If payment fraud keeps getting close, mandate second channel verification. A risky behaviour you can design out is one you never need to persuade anyone about again.

Frequently asked questions

How long should a security training module be?

Five to ten minutes, covering one idea properly. Longer sessions get deferred and rushed. Frequency matters more than length, so several short modules across a quarter will outperform one long annual course.

How often should we train employees?

Monthly or every few weeks in short bursts, supported by continuous simulation. Annual training alone produces a spike of attention that decays within weeks and leaves most of the year uncovered.

Should security training be mandatory?

Yes for the compliance baseline, but mandating attendance does not produce engagement on its own. Relevance, brevity and a blame free tone are what turn a required module into one people actually pay attention to.

Do rewards and gamification work?

Modestly, and mainly through recognition rather than prizes. Team level comparisons and visible thanks for reporting sustain attention better than points and badges, which tend to lose their effect once novelty passes.

How do we engage staff who are not office based?

Deliver short mobile friendly content, avoid assuming a desk or a long uninterrupted slot and prioritise the topics that match their actual exposure such as device handling, physical security and personal scams. A champion on site matters more for these groups than any communication from head office.

Where to go next

Boxphish delivers short NCSC aligned training segmented by role, with continuous simulation and immediate feedback at the point of the mistake, reported on behaviour rather than completion. Book a demo to see how engagement looks when it is measured properly.

Ready to transform your cyber culture? Book a demo today!

Latest insights

Aug 26, 2026

Security awareness training vs security behaviour and culture programmes: What is changing and why

Employee cyber risks

Aug 11, 2026

Reducing human cyber risk: 6 proven tactics every CISO should adopt in 2026

Employees using cyber awareness training

Aug 26, 2026

How to get employees to engage with security training