Rethinking Cyber Training: One Size Fits None

Rethinking Cyber Training: One Size Fits None

Cybersecurity awareness training framework — micro-learning and phishing simulation

Most cybersecurity training programs follow the same logic: roll out identical e-learning modules to all employees, once a year, and tick the box. This approach has one virtue: it is simple to deploy and cost-effective. It has one major flaw: it does not work.

Not because the tools are poor. Because the starting question is wrong.

E-learning is not the problem. One-shot is.

Let us be direct: e-learning modules do not deserve their bad reputation. The problem is not the format. It is how it is used. A twenty-minute video, delivered once a year, with no follow-up, no repetition, no anchoring in daily practice, trains no one. It informs, perhaps. It transforms, never.

70% of knowledge acquired in one-shot training disappears within 24 hours. This is not a pedagogical opinion. It is a cognitive mechanism documented by Ebbinghaus, a German psychologist, and confirmed by decades of neuroscience research. Memory does not retain what it encounters once. It retains what it practices regularly, across varied contexts.

Well-designed micro-learning responds precisely to this constraint. Short modules, accessible at any time, built in sequences that revisit and deepen previously covered material, with knowledge checks and reminder notifications: this spaced repetition mechanism is the only serious answer to the forgetting problem. It is also the only realistic approach for populations whose availability is constrained by their workload. The real enemy of the training budget is not e-learning. It is the off-the-shelf video, generic and decontextualised, that nobody really watches and that leaves no lasting learning process and therefore no lasting behavioural reflex.

Memory retention over time
Based on Ebbinghaus's forgetting curve research
No review Single review at D+1 Spaced micro-learning (3 sessions)
No review: retention drops to 30% in 24h. With spaced micro-learning: retention maintained above 80% at 30 days.
One-shot training
−70%
of knowledge lost within 24h
Single review at D+1
~55%
retention at 30 days
Spaced micro-learning
>80%
retention at 30 days

The more novice the learner, the more they need to be active

There is a pedagogical principle that cybersecurity awareness programs almost systematically ignore: the relationship between a learner’s level of mastery and the most effective learning format is the opposite of common intuition. It is not the expert who needs to participate actively. It is the novice.

An employee with no cybersecurity background placed in front of a lecture-style video has no frame of reference to evaluate what they hear. That same employee placed in a situation, confronted with an attack scenario that requires them to act and observe the immediate consequences, builds a memorable experience that the video would never have produced.

This is why phishing simulation is the most powerful pedagogical tool available for non-expert populations. Receiving a simulated phishing email, clicking on it, being immediately redirected to a contextualised explanation of the warning signs they missed: this sequence creates an emotional memory that ten theoretical modules will never produce. The surprise, delivered with care and without punishment, is the most effective attention trigger there is.

Beyond phishing, crisis management exercises are the other major lever of experience-based awareness. Being confronted, in a simulated scenario, with an ongoing ransomware attack, a decision to notify the relevant authority within an hour, a crisis unit to activate without prior preparation: this type of exercise transforms an abstraction into a lived reality. Yet 80% of organisations consider themselves insufficiently prepared for a cyber crisis. They are right. And preparation cannot be improvised. It must be anticipated.

Executives first. Always.

Leading by example is fundamental. 70% of the engagement gap between teams is explained by the behaviour of their manager. This figure, drawn from Gallup research, applies with remarkable precision to cyber training. An employee whose management never mentions cybersecurity, never relays awareness campaigns, never signals that the subject matters, will not durably change their behaviour, regardless of the quality of the modules delivered to them.

The executive is not simply a recipient of training. They are its indispensable ambassador. Without their visible commitment, the program remains a compliance exercise that everyone goes through without conviction.

Training an executive, however, is precisely where the format must change. A board does not need a quiz on spotting a fraudulent email. It needs to understand cyber risk in the language it knows best: investment and business impact. The DICT model, covering Availability, Integrity, Confidentiality and Traceability of information systems, provides that framework. A loss of availability means operations stop and customers go unserved. A confidentiality breach means a mandatory notification to the data protection authority, an alert to the national cybersecurity agency within 24 hours for entities subject to NIS2, and direct exposure for financial institutions under DORA. Measured against these impacts, the cost of a structured awareness program is no longer an expense. It is a behavioural insurance premium.

An executive who has internalised this reasoning no longer manages their awareness program with a residual budget. They manage it with a risk reduction objective, and they become its primary relay.

Target the formats, target the populations, measure the right indicators

An effective awareness program is not uniform. It distinguishes populations according to their actual risk exposure, their level of maturity and their role in the defence chain.

Employees exposed to common attack vectors progress with micro-learning and regular simulations. Serial clickers, those who continue clicking despite repetition, need a virtual classroom in a small group, led by an expert, to work through the cognitive mechanisms that make them vulnerable. High-risk functions, including finance, HR and management, deserve scenarios built around their real situations. Executives require an immersive, in-person format anchored in the governance and compliance challenges specific to their role.

Finally, the click rate on phishing simulations, as useful as it is, is not the only indicator that matters. What genuinely measures organisational maturity is the reporting rate: the proportion of employees who, when faced with a suspicious email, actively raise the alert rather than simply not clicking. This shift, from passive target to active participant in collective defence, is the real objective of any ambitious program.

Training everyone the same way, once a year, with the same videos, is an expense. Building a targeted, continuous program, driven by repetition and measured against the right indicators, is an investment. The difference between the two is measured, after two years, in incidents avoided.

Stroople builds high-impact cyber training programs, ready to deploy and auditable by supervisory authorities. Designed around a Qualiopi-certified pedagogical framework, they adapt to every population, every budget constraint and every regulatory requirement. Let’s talk about your program.

Share:

X
LinkedIn
Managed SOC

Stroople Managed SOC 24/7 Offering

A managed solution for your cybersecurity that protects, detects and responds. 24/7.

Learn more