
A security awareness program is a permanent, plannable process that systematically builds, trains, and measures the security consciousness of the workforce. The difference from the classic annual training course lies in continuity: Instead of imparting knowledge once a year that quickly fades again, a program combines short, recurring learning units with practical exercises and clear metrics. If you are looking for the basics, you will find them in the article What is security awareness?; this article shows which building blocks an effective program consists of. The Data Protection & Information Security category brings together further articles on the topic.
The effort is worthwhile because the human factor is involved in most security incidents – according to ENISA, phishing, at around 60%, is one of the most common initial attack vectors (Threat Landscape 2025). At the same time: Designing a program yourself, continuously supplying it with content, managing the frequency, and evaluating the results ties up considerable internal resources. How this effort can be reduced with standardized formats without losing effectiveness is addressed at the end of this article.
The most important lever is frequency. People quickly forget what they have learned if it is not repeated – an effect illustrated by the "forgetting curve" described by Hermann Ebbinghaus. Specific percentages on this (such as "after one day, half is forgotten") circulate frequently but are more illustrative than precisely proven. The principle is undisputed: distributed, repeated learning anchors knowledge permanently, one-off training courses do not.
In practice, this means: short learning units of a few minutes, spread over the year (microlearning), instead of a mandatory event lasting several hours. Small units are easier to integrate into everyday work, are postponed less often, and keep the topic present. The background in learning psychology is called spaced repetition: Content that is repeated at increasing intervals is transferred more reliably to long-term memory than knowledge crammed once.
In addition, accompanying campaigns, short reminders, posters, or event-related notices – for example after a real wave of attacks – keep attention high. The dramaturgy over the year is important: a thorough basic training course as the start, followed by a steady stream of small impulses. This keeps the effort per session low, while the overall effect grows through repetition.
A practicable annual rhythm can look like this: a detailed basic training course to begin with, then a short learning unit on a focus topic every month and a phishing simulation every quarter. What matters is not perfect timing, but that a reliable, recurring rhythm emerges at all, one that the organization can sustain permanently – better small, consistent steps than an ambitious plan that peters out after two months.
A program is only as good as its topics. A core that covers the most common attack surfaces has proven effective:
The content should be role- and risk-oriented: Anyone who deals a lot with payments needs more on Business Email Compromise; employees without a fixed screen workstation – for example in production or care – need short formats that can be accessed on mobile devices instead of long desktop courses. Management, in turn, bears special responsibility and is a preferred target of attacks, which is why it receives its own tailored content. A brief needs analysis at the beginning – which roles work with which risks – saves a lot of readjustment later and ensures that nobody is bored with irrelevant content and that everyone experiences the training as relevant to them.
Just as important as the selection is being up to date: Threats change quickly. Topics such as AI-supported phishing, deepfakes, or QR code fraud should be added regularly so that the training does not miss reality. This ongoing content maintenance is one of the biggest cost drivers – courses must be revised regularly so that they remain relevant and do not train on yesterday's state of knowledge.
Knowledge shows in behavior. Phishing simulations – controlled, harmless test emails – make visible how the workforce really reacts and give those affected an immediate learning opportunity: Anyone who clicks on a simulation immediately receives a short explanation of how the fake could have been recognized. At the same time, they provide the data basis for measuring success.
A staged process makes sense: A first, unannounced campaign establishes the baseline, followed at intervals by further campaigns with increasing difficulty – from the crude mass email to targeted, personalized spear phishing. The purpose is important: Simulations serve learning, not exposing individuals; results are ideally aggregated and evaluated without personal sanctions. When introducing them, co-determination and data protection aspects must be taken into account – such as involving the works council and data-minimizing evaluation – which require separate consideration in detail.
For simulations to work instead of causing frustration, implementation is key: transparent communication in advance that such tests will take place, factual rather than punitive follow-up, and a clear, simple reporting channel through which genuine suspected cases can also be reported with one click. This turns the test into a learning opportunity that strengthens the reporting culture instead of undermining it. Anyone who clicks should report it – not hide.
Without metrics, a program remains a gut feeling. Three KPIs have become established:
What matters is reading the metrics in context: A falling click rate with a simultaneously rising reporting rate is the real picture of success – the workforce falls for scams less often and reports more actively. A low click rate alone can be deceptive if hardly anyone reports. That is why the three KPIs should always be considered together and over time as a trend, not as a snapshot.
It is important to set realistic goals: Pushing a click rate to zero overnight is neither feasible nor necessary. A step-by-step goal makes more sense – for example, noticeably lowering the baseline in the first year and increasing the reporting rate in parallel. In addition, it is worth looking at soft indicators such as the participation rate in learning units or the number of voluntary reports of genuine suspected cases, which show whether the security culture is actually taking hold and not just the obligation being fulfilled.
How much this can develop is shown by the 2025 phishing benchmark report from the provider KnowBe4 (based on more than 14 million users): The average click rate was initially 33.1%, fell by around 40% after three months of training and to 4.1% after twelve months. These figures come from a provider with its own interests and are to be understood as a guide, not as official statistics – but the order of magnitude matches industry experience that continuous training significantly reduces the click rate.
How often is enough? There is no universally applicable statutory frequency. A rhythm of initial training during onboarding, annual refreshers, and accompanying microlearning over the year, supplemented by regular simulations, has proven effective. What makes sense is maturity-level thinking in stages: At the beginning come the basics, a first baseline measurement, and establishing a simple reporting channel. In the intermediate stage, role-specific content, regular simulations, and first metric targets are added. In the mature stage, security is part of the corporate culture: Reports are a matter of course, managers lead by example, and the program is readjusted based on data.
The goal shifts over time – from "building knowledge" to "making secure behavior a habit". It is important to assess your own maturity level realistically and to aim for the next stage instead of lumping every organization together. A small team with a first baseline faces different tasks than a corporation with an established reporting process – the next sensible step is different in each case.
At the same time, awareness is part of recognized frameworks: ISO/IEC 27001 requires awareness raising and training, and within the scope of NIS-2, "basic training and awareness-raising measures" are among the minimum measures (Section 30 (2) of the BSI Act (BSIG)). A documented program thus contributes directly to regulatory requirements and, in the event of an inspection or audit, provides proof that awareness raising is carried out in a planned and recurring manner.
Many programs fail not because of a lack of will but because of avoidable mistakes. The most common:
It is striking that most of these mistakes are organizational rather than technical in nature. They can be avoided with clear responsibilities, a fixed editorial plan for the content, and visible support from the management level – the latter often has a stronger effect than any single training module because it signals that security is a matter for the top. Anyone who avoids these points is halfway there – the rest is consistent, lasting implementation.
The building blocks show: An effective program is less a question of good will than of ongoing implementation – maintaining content, keeping up the frequency, running simulations, evaluating KPIs, and providing follow-up training. Anyone who does not want to handle this ongoing effort entirely internally can fall back on standardized formats.
A note on our own behalf: This is exactly where ready-made solutions come in. Bridgly bundles microlearning, up-to-date content, phishing simulations, and evaluation in standardized awareness and information security training courses that can be rolled out via a learning platform and verified with documentation – without a program having to be designed internally from scratch. The building blocks described thus result in a program that can be operated with manageable internal setup effort and evaluated using the metrics mentioned.
There is no fixed statutory frequency. A three-part rhythm has proven effective: initial training during onboarding, an annual refresher, and accompanying microlearning spread over the year, supplemented by regular phishing simulations. What matters is less the exact timing than continuity – a reliable, recurring rhythm that the organization sustains permanently has a stronger effect than infrequent large events.
The most common are three metrics: the phishing click rate (Phish-prone Percentage), the reporting rate of suspicious messages, and the time-to-report. They are only meaningful in combination – a falling click rate with a simultaneously rising reporting rate shows that knowledge is actually turning into secure behavior. Considered individually, each of these figures can be deceptive and should therefore always be read as a trend.
Microlearning consists of short, focused learning units of a few minutes that are spread over the year and repeated at increasing intervals. They counteract the forgetting curve, are easier to integrate into everyday work than long individual training courses, and keep the topic of security permanently present instead of dealing with it once a year in a mandatory event lasting several hours.
They are a widespread and, in principle, permissible instrument but touch on co-determination and data protection. As a rule, the works council must be involved, and the evaluation should be data-minimizing and without personal sanctions – the goal is learning, not exposing individuals. The specific design should be legally reviewed on a case-by-case basis and properly documented.
Insights into the future of digital learning, with a focus on AI, compliance, and modern training solutions. Discover the latest posts and articles to gain practical insights into legally compliant, efficient, and automated corporate training.
Note: Some text, images, and videos on this website were generated using artificial intelligence.
All content is for informational purposes and has been carefully reviewed from a journalistic perspective, but does not claim to be exhaustive or legally binding.