CybersecurityHuman factor

Cybersecurity awareness: why October should not be the whole programme

A year of awareness12 months. One continuous programme.

Every October brings European Cybersecurity Month. ENISA and the European Commission have supported this initiative for years, promoting campaigns, activities and awareness resources for citizens and organisations. 1

And every October, a familiar pattern plays out inside many companies. The security talk returns. An email reminds everyone of good practice. Perhaps a phishing simulation follows. Some organisations even organise activities throughout the month.

It is a useful opportunity to put cybersecurity back on the agenda. The problem arises when October accounts for almost the entire year's awareness programme.

Helping someone understand a risk is one thing. Helping them make a sound decision six months later, when they are busy and receive a convincing, carefully tailored email, is considerably harder. Recent research gives us a clearer picture of that difference.

At a glance

From training to behaviour

  • Course completion does not demonstrate behavioural change.
  • Practise real decisions, adapt to roles and give useful feedback.
  • Measure reporting, response time and trends, as well as clicks.
  • October creates visibility; the programme needs to continue all year.

Training helps. Changing behaviour is another matter

A 2025 meta-analysis in Computers & Security examined 69 studies of cybersecurity training for end users. The overall finding was positive, but separating the outcomes revealed an important difference.

Effects were larger for knowledge, attitudes and intentions than for observed behaviour. The overall effect was d = 0.75, rising to d = 1.02 for predictors such as knowledge and attitudes. For behavioural measures it fell to d = 0.36, with a 95% confidence interval of −0.09 to 0.80. Because that interval includes zero, the estimate does not establish a statistically significant behavioural improvement. It does not prove that all training is useless either. d is a standardised effect size, not a percentage reduction in risk. 2

69 studies · 2025Training effects, at a glance
Overall effectd = 0.75
Knowledge and attitudesd = 1.02
Observed behaviourd = 0.36

Standardised effect size (d), not risk reduction. Behaviour: 95% CI −0.09 to 0.80; includes zero. Study ↗

You do not need to remember the numbers. The practical point is that passing a course does not necessarily demonstrate that we will make the right decision when the real situation arises.

We can explain phishing, show examples and help someone score full marks in a quiz. None of that guarantees they will not enter their credentials on a fake page four months later after receiving a credible message at a busy moment.

Training still has a place. What needs to change is what we expect from it and how we measure it.

The problem with putting everything into an annual course

A separate review, published in Computers & Security in 2024, examined 42 studies of phishing training. Short-term effects were well documented, but evidence of sustained behavioural change was more limited. Training intensity, active learning and detailed feedback were among the design features associated with outcomes. 3

Learning a behaviour and maintaining it are not quite the same challenge. If we teach people to recognise fraud in January and never revisit it until the following January, we are asking a one-hour presentation to survive twelve months of work, emails, meetings, pressure and technological change.

That is why I find it difficult to call an annual course plus a test a complete awareness programme. It can be part of one, and may support internal or compliance requirements. But it should only be one part.

The value of training close to the decision

A 2026 study in the International Journal of Human-Computer Studies adds useful evidence. Madeira and Alves studied a public organisation: 4,457 employees participated in the quantitative work and 19 in interviews. They compared immediate feedback with no feedback, and mandatory with voluntary participation. This was not a direct comparison between immediate feedback and training delivered several weeks later.

They found that immediate feedback reduced subsequent phishing susceptibility. Mandatory participation increased engagement but could affect intrinsic motivation. These findings come from a particular setting, rather than guaranteeing the same outcome in every company. 4

As a design principle, they invite us to make use of the decision itself. Someone clicks a link in a simulation. We could record the event and assign a course weeks later. Or we could explain what just happened, which signals were available and what the person could have checked. The second option connects learning to a recent experience.

That brings us to an idea that deserves more attention: train people to make decisions, not just to understand concepts.

Someone in administration does not need a detailed understanding of DMARC to respond to a suspicious change of supplier bank account. They need to know the verification procedure. An employee does not need to understand every Microsoft 365 protocol to recognise an MFA request they did not initiate. A director does not need to become a social engineering specialist to know how to handle an urgent call apparently coming from another executive.

This is where training starts to connect with everyday work.

A phishing simulation should do more than count clicks

Phishing campaigns are among the best-known awareness tools. They are also easy to use badly. Sending an extremely convincing email, recording the clicks and presenting the percentage to management produces a metric. It does not necessarily improve security.

Before launching a simulation, I would ask which behaviour we want to practise. Checking a domain before entering credentials? Verifying a bank account change through a separate channel? Rejecting an unexpected MFA request? Using the internal reporting mechanism correctly?

Once that is clear, a simulation becomes an educational exercise instead of a way to catch employees out. Measurement changes too.

Imagine two organisations. This is a hypothetical example, not a research finding. In the first, 5% interact with the simulated phishing email and only 1% report it. In the second, 8% interact but 45% report it.

Looking only at clicks makes the first organisation appear better. The figures alone do not establish that the second is safer either: message difficulty, the population and the definitions of each measure matter. But when a real attack arrives, having many people ready to report it quickly could be valuable.

I would therefore consider interaction, reporting, time to report, recurring techniques, repeated difficulty and changes after training together. The goal is not a green dashboard. It is to understand whether we are reducing risk and improving detection when something happens.

Keep a consistent denominator, separate clicks from credential submission, and compare campaigns with similar difficulty. Use group-level trends to guide support, without public individual rankings. Training also needs usable procedures and technical controls.

We do not all need to learn the same things

Most organisations need a common foundation: phishing, social engineering, authentication, information protection, devices and incident reporting. Beyond that, training should increasingly reflect each person's work.

Finance teams face payment fraud, fake invoices and supplier bank account changes. HR regularly handles personal information, documents and external messages. Developers need to pay attention to repositories, credentials, secrets, dependencies and AI tools used with code.

Executives may face highly targeted attacks and have specific responsibilities during an incident. IT staff have access and privileges that make impersonation especially consequential.

Giving everyone exactly the same material is easy to manage. It does not always manage risk well. Awareness should start with situations each group is likely to encounter.

Tools help. Someone still needs to design the programme

Security Awareness Training platforms can combine courses, microlearning, phishing campaigns, adaptive learning, gamification and metrics. The examples below link to the providers' own information. They are not a ranking or an independent comparative assessment.

The right choice depends on the organisation's size, languages, budget, integrations and intended programme.

Examples of tools and public resources
Solution or resource Main contribution When I would consider it
KnowBe4 Content library, simulations and campaign automation Programmes with substantial content and administration needs
Hoxhunt Simulations, microlearning and a behavioural focus Continuous programmes focused on phishing and behaviour
SoSafe Learning, simulations and human risk management Programmes combining learning and simulation
Proofpoint ZenGuide Awareness connected to the Proofpoint ecosystem Organisations already using the vendor's products
MetaCompliance Training, compliance and policy management Programmes combining awareness with compliance
Microsoft Attack Simulation Training Simulations and training through Microsoft Defender Organisations with the appropriate licences
CCN ÁNGELES Public training resources, videos and gamification Supplementing a programme with awareness materials

Inclusion does not constitute a specific recommendation. Evaluate capabilities, integrations, languages and costs against your own needs.

For organisations using Microsoft 365, there is another useful question before buying a platform: do we already have relevant capabilities?

Microsoft offers Attack Simulation Training with Microsoft Defender for Office 365 Plan 2, also included in subscriptions such as Microsoft 365 E5. It supports simulations, assigned training and results analysis through the Defender portal. Check the current licence requirements and the users you intend to cover. 5

It may meet some organisations' needs and fall short for others. Either way, it makes sense to review what you are already paying for.

Spain also has useful public resources. The CCN's ÁNGELES portal added awareness videos in April 2026 covering subjects including phishing, ransomware and deepfakes. In June it added gamified exercises and challenges on data leakage, CEO fraud, phishing, QR-code phishing and voice phishing. 6 · 7

These resources help, but no platform decides which behaviours matter to your organisation. Buying the tool before designing the programme can leave you with plenty of activity and data, but little clarity about what you are trying to improve.

October can make the programme more visible

This is where European Cybersecurity Month makes sense. For a few weeks we can increase visibility, involve management, launch campaigns and try different formats.

I would not try to teach every aspect of the company's security in four weeks. I would use the month to practise specific behaviours: phishing and social engineering; identity, MFA and account recovery; information protection and AI use; and what to do when we think something has happened.

A healthy security culture needs more than people who avoid mistakes. It also needs people who notice something unusual and report it quickly.

Employees should not feel that reporting a mistake will trigger a search for someone to blame. Entering credentials in the wrong place and immediately reporting it creates one situation. Hiding it for six hours out of fear creates a very different one. The culture around the programme matters as much as the material.

One possible October plan · editorial proposal, not the official ECSM calendar
  1. Week 1

    Phishing and fraud

    Verify a bank account change through another channel.

  2. Week 2

    Identity and MFA

    Reject and report an unexpected authentication request.

  3. Week 3

    Information and AI

    Decide which data may be shared and through which tools.

  4. Week 4

    Incident reporting

    Practise where to report, what to include and whom to contact.

NIS2 and its implementing rules: from training to a programme

There is also a regulatory dimension. Article 21(2)(g) of NIS2 includes basic cyber hygiene and cybersecurity training among risk-management measures. Article 20(2) requires Member States to ensure that management bodies of essential and important entities receive training, and to encourage those entities to offer similar training to employees regularly. The obligations of a particular company depend on its scope and the applicable national rules. 8

Implementing Regulation (EU) 2024/2690 does not apply to every NIS2 entity. Its scope covers DNS providers, TLD registries, cloud computing, data centres, content delivery networks, managed services, managed security services, online marketplaces, search engines, social networking platforms and trust service providers.

For entities within that scope, Annex sections 8.1 and 8.2 are more specific. They require an awareness programme scheduled over time, repeated activities and coverage of new employees, with planned updates reflecting changing threats and risks. Awareness effectiveness must be tested where appropriate. Roles requiring security expertise need regular, relevant training whose effectiveness must be assessed. 9

That is a useful distinction between “we delivered training” and “we have an awareness programme”. The second statement requires continuity, context and measurement.

What should an awareness programme look like?

There is no calendar we can copy into every organisation. A twenty-person company does not need the same programme as an international group. An industrial business and a software company will not need identical scenarios either.

What I would keep is a common sequence:

risk desired behaviour activity practice feedback measurement adjustment

First decide which situations concern you. Then identify what people should do when those situations arise. Choose training, simulations, exercises or communications to support that behaviour. Finally, check whether the approach is working.

The tool comes afterwards. October can be one of the most visible points in the cycle, but something needs to happen before and after it.

From risk to practice

Supplier payment fraud: agree on verification through a previously known contact, rehearse a bank account change request, explain the decision and review whether the check was actually followed in subsequent cases.

What I would like to know at the end of the year

If all we know in December is that 98% of employees completed their training, we know that almost everyone finished the course. That is useful information, but it does not tell us what happened to the behaviours we wanted to practise.

Are people reporting phishing faster? Do the same techniques still work? Does everyone know where to report a concern? Do some groups need a different approach? Are bank account changes being verified before approval? Are AI tools being used within the organisation's rules?

Those answers begin to tell us something about awareness. They also help us decide what to do next year.

October lasts a month. Awareness should last longer.

European Cybersecurity Month is a useful opportunity to return to conversations that can get buried under projects, meetings and everyday work. Let's make use of it with workshops, simulations, exercises and campaigns.

But if security disappears from the conversation in November until the following October, we are likely wasting part of that effort.

The evidence points to improvements in knowledge and attitudes, with more uncertainty about sustained behavioural change. Practice, repetition and feedback deserve careful design and evaluation; they are not a promise of automatic results. 2, 3

When all we know is how many people finished a course, we are measuring training.

When we understand how they make decisions, what they report and where problems persist, we begin to measure awareness.

At ACBSEC we design sessions, workshops and awareness programmes around each organisation’s risks: from management and technical training to employee activities and practical social engineering exercises. Explore training and awareness services.

Sources and further reading

1. ENISA · European Cybersecurity Month

2. Assessing the effect of cybersecurity training on End-users: A Meta-analysis (2025)

3. Exploring the evidence for email phishing training: A scoping review (2024)

4. Madeira & Alves · Designing effective phishing awareness training: The role of feedback and engagement strategies (2026)

5. Microsoft Learn · Attack Simulation Training

6. CCN · ÁNGELES: awareness videos, April 2026

7. CCN · ÁNGELES interactive exercises, June 2026

8. NIS2 · Articles 20(2) and 21(2)(g)

9. Implementing Regulation (EU) 2024/2690 · scope and Annex 8.1–8.2

Reviewed on 19 September 2026. Product capabilities and licensing may change; the table links to vendor documentation. The programme examples are editorial proposals.

← All articles

Keep reading

Training and awareness

What should your team do differently?

Tell me which decisions create risk in your organisation. We can turn them into practical training, exercises and a programme you can evaluate.

Talk about training