Join Doppel at Black Hat USA 2026 to win The Bigger Carry-On suitcase from Away
Research

Cybersecurity Awareness Training: A Complete Guide

What cybersecurity awareness training covers in 2026, how to build a program that changes behavior, and how to measure whether it's working.

Deepfake Simulations for Security Awareness: What It Is and How to Do It Right

Many enterprises run some form of cybersecurity awareness training, and yet attackers now target the human layer more than any other part of the attack surface. The human element appeared in 60% of breaches in the 2025 DBIR, roughly the same share as the prior year.

Generative AI has changed the social engineering behind that statistic: attackers now produce clean, personalized lures at scale across email, voice, SMS, chat, and video calls, and a cloned voice or face can put a trusted identity behind the request. A program that teaches employees to spot a typo once a year tests only a fraction of what they actually face.

This guide covers what cybersecurity awareness training is, the topics a complete program covers, how to build one that changes behavior, and how to measure whether it's working.

Key takeaways

  • Cybersecurity awareness training builds the workforce's ability to recognize and refuse social engineering across the human layer.
  • A complete program combines training content, simulations, reinforcement, and a reporting path so employees can act as sensors for the security team.
  • Generative AI, deepfakes, and multi-channel attacks make annual, inbox-only training insufficient for the attacks employees now face.
  • Strong programs measure per-employee risk, reporting speed, reporting rate, and behavior trends over time.
  • Human risk management turns awareness training into a continuous loop of live-threat simulations, targeted reinforcement, and measurable risk reduction.

What cybersecurity awareness training is

Cybersecurity awareness training builds a workforce's ability to recognize and refuse social engineering, the attacks that target people directly while technical controls defend systems. It is the primary control for the human layer, and the terms "cybersecurity awareness training" and "security awareness training (SAT)" name the same discipline.

Awareness training defends the human layer

Employees are the decision point social engineering exploits, which is why the human layer needs a control built for it. Social engineering bypasses controls regardless of an organization's technical maturity. An attacker can compromise a workflow simply by convincing a help desk agent to reset an MFA token on request.

What a cybersecurity awareness training program includes

A program covers four working parts:

  1. Training content, which teaches employees what current attacks look like.
  2. Simulations, which tests whether the training transfers to behavior under pressure
  3. Reinforcement, which keeps the lessons live between formal sessions
  4. A reporting path, which turns employees into sensors that feed the security team

Programs need all four parts to test knowledge, test behavior, and capture the signal employees generate.

Where awareness training fits alongside technical controls

Awareness training covers the residual human risk that technical controls cannot close. Technical controls reduce exposure, but attackers still exploit human decisions across identity, payment, and support workflows.

Attackers still bypass MFA in live campaigns, and adversary-in-the-middle attacks routinely steal session tokens from accounts that already use MFA. The human decision is where the attack lands, and that is where awareness training has to work.

Why cybersecurity awareness training matters more in 2026

The case for awareness training has sharpened because generative AI has rebuilt social engineering into cheap, convincing, multi-channel attacks that reach employees faster than technical controls adapt.

The economics now favor the attacker, the lures have lost the tells employees once learned to spot, and a single campaign moves from an email to a phone call to a video meeting.

AI made convincing lures cheap and available at scale

Generative AI removed production costs that once limited social engineering. AI tools can now create tailored lure content quickly and at scale, and AI-automated phishing emails achieved click-through rates of 54%, compared with 12% for standard phishing attempts.

The foundational training advice to watch for typos and bad grammar now carries less value. GenAI now produces convincing lures without the spelling and grammatical mistakes that once revealed phishing.

Attacks now reach employees across voice, sms, chat, and video

A modern campaign rarely uses one channel. Attackers layer phone calls from a supposed bank representative, a confirming email, and a text with a secure link. The sequence builds credibility even if one method fails. Attackers use Microsoft Teams as part of coordinated multi-channel attacks.

A mail-bombing burst arrives first, then an attacker posing as IT support places a Teams call to the target. Collaboration channels are attractive for impersonation because employees use them for real-time work and internal requests. A program that tests only the inbox leaves much of this attack surface untested.

Deepfakes put a trusted voice and face behind the request

Employees can no longer treat voice and video verification as sufficient assurance. 62% of organizations experienced a deepfake attack involving social engineering or automated-process exploitation in the 12 months prior to mid-2025.

Employees have become attackers' primary target

The human layer is where attacks often land first because attackers go where trust and authority are easiest to manipulate. Social engineering attacks often turn one compromised identity into broader organizational risk.

In one documented case, attackers escalated privileges rapidly without deploying malware. They entered through the system's users.

What a complete cybersecurity awareness training program covers

A complete program spans seven topic areas that together cover the social engineering employees face and the everyday habits that limit damage when an attack lands: phishing and multi-channel social engineering, deepfakes and AI-generated impersonation, business email compromise and payment fraud, passwords and phishing-resistant MFA, data handling and responsible AI use, physical and device security, and threat reporting and incident response.

Each area maps to a documented threat pattern employees encounter in real workflows.

  • Phishing and multi-channel social engineering. Email phishing plus voice phishing, smishing, QR-code phishing, and chat-based lures.
  • Deepfakes and AI-generated impersonation. Cloned voice and video of executives, colleagues, and vendors.
  • Business email compromise and payment fraud. Out-of-band verification of payment, banking, and data-change requests.
  • Passwords and phishing-resistant MFA. Credential hygiene, FIDO2 and passkeys, and MFA fatigue attacks. Enterprises can deploy FIDO/WebAuthn authentication today as a widely available phishing-resistant standard.
  • Data handling and responsible AI use. Classifying sensitive data and recognizing what not to paste into public AI tools.
  • Physical and device security. Tailgating, clean-desk habits, lost or stolen devices, home and travel networks, malicious USB drops, and juice jacking on public charging ports.
  • Threat reporting and incident response. How and when to report, so employees become sensors for the security team.

These topics connect everyday decisions to the social engineering patterns employees actually encounter.

How to build a cybersecurity awareness training program that changes behavior

Training changes behavior only when it runs continuously, mirrors the channels and lures employees actually face, and adapts to each person's risk. An effective program rests on four practices working together: continuous delivery, multi-channel simulation, simulations drawn from live attacker activity, and risk-based targeting.

Each practice addresses a way that annual, email-only, generic-template programs leave employees untested.

1. Run training and simulations year-round

Annual training does not reliably reduce phishing failures: in a large health-system study, employees were about as likely to click a bad link soon after their course as much later.

Replace the annual module with a continuous cadence, and add just-in-time microlearning the moment an employee acts on a risky message, when the lesson is most relevant and most likely to stick.

2. Simulate every channel employees are attacked through

A simulation program that runs only on email tests one channel of a multi-channel threat. Extend phishing simulations to voice, SMS, and meeting platforms so the program reflects the full attack surface. Multi-channel simulation should cover email, voice, SMS, Microsoft Teams, Zoom, Telegram, and WhatsApp. Simulations should also mirror how attackers move within a single campaign: a voice call that pivots to an SMS or email follow-up when the target pushes back tests the layered sequence employees actually face.

Expect engagement rates on non-email channels to run high in the first deployments, because most programs have never tested employees on voice, SMS, or meeting platforms before. The high rates reflect a measurement gap that closes as employees build muscle memory across channels, and that first run gives the security team its first true multi-channel risk baseline.

3. Draw simulations from live attacker activity

Stock templates test generic threats. Base scenarios on the lures currently hitting the company and its industry. Email remains a leading source of attacker activity against financial services and fintech brands, alongside steady activity across social and messaging platforms. That shift toward multi-channel campaign design is what a year-old template library would miss.

Live adversary simulations test the attack employees will see this quarter.

4. Target training by role and individual risk

Route scenarios by exposure to role-specific threats. Finance trains on payment fraud, executives on deepfakes and vishing, and IT and help desk on credential theft. Then give repeat clickers progressive content automatically.

Repeat clickers pose a disproportionately higher risk, and routing reinforcement to them without analyst intervention is how a program scales personalized intervention across a large workforce.

How to measure whether awareness training is working

Completion rates and one-time click rates measure activity. Risk reduction shows up in behavior trends, reporting speed, and per-employee outcomes. A program proves its value by tracking how employee behavior changes over time and how quickly the workforce reports the attacks that reach it.

These measures turn a training calendar into evidence a security leader can take to the board.

1. Move past completion rates and single-click rates

Completion and click rates reward activity and obscure whether risk actually fell. Most organizations still use completion rates and click rates as primary measures, yet completion tells you nothing about whether anything sank in. Click rate carries a specific flaw: it reflects the difficulty of the last simulation and can blur each user's risk.

Measure whether employees behave differently when a live threat reaches them.

2. Track per-employee risk and behavior over time

Per-employee risk is the right unit of measurement, because risk has many dimensions, spans every channel, and only shows up in actual behavior over time. A per-employee profile combines a risk score, repeat-offender trends, response speed, data submission rate, and a per-channel breakdown.

A frequent clicker who never submits carries a different risk than an infrequent clicker who submits when engaged, and a single rate cannot tell them apart. Risk modeling that surfaces this picture across every channel the program covers lets the security team target further training to the highest-risk users and teams.

3. Treat reporting speed and rate as core metrics

How fast and how often employees report real lures is a leading indicator of resilience. The sooner people report a suspected incident, the faster security teams can respond, and the people who report represent the most resilient of the workforce. Strong reporting can signal a healthier culture even when simulations still generate clicks, because reporting is the active defense behavior that triggers incident response.

Low reporting can also reveal friction in the process when employees lack a one-click reporting tool or fear punishment.

Train for the attacks employees actually face

Judge an awareness program by one question: does it reduce human risk against the attacks employees actually face? Annual modules and email-only click rates leave that question unanswered. The teams that pull ahead in 2026 will run cybersecurity awareness training as continuous human risk management.

Request a demo to see the closed loop run against the attacks targeting your organization now.

Learn how Doppel can protect your business

Join hundreds of companies already using our platform to protect their brand and people from social engineering attacks.