A new survey by Hornetsecurity has uncovered significant gaps in IT security training, with a quarter (26%) of organizations providing no form of training to their end-users and nearly a third (31%) of respondents reported that their training was unengaging or only slightly engaging.
The survey, which compiled feedback from industry professionals around the world, also reveals that fewer than 1 in 13 (8%) of organizations offer adaptive training that evolves based on the results of regular security tests. In a rapidly evolving cybersecurity landscape, where malicious threat actors are constantly devising new ways to infiltrate and harm, this is a significant business concern.
Engagement and effectiveness in IT security training
People represent the frontline of every company’s cybersecurity strategy. The most effective type of cyberattack is phishing, which preys on a person’s trust. Employees must therefore be equipped with the skills, understanding and confidence to spot malicious behaviours. Sadly, Hornetsecurity’s survey revealed that not only is there a significant gap in training, but training initiatives are seen to be ineffective. As noted above, 31% of respondents said that their training was unengaging or only slightly engaging.
Despite the low engagement levels, 79% of organizations believe their IT security awareness training to be at least moderately effective in combating cyber threats. However, nearly four in ten (39%) reported that the training does not cover recent or AI-powered cyber threats adequately. In a world where AI is expediting and increasing the scale of attacks, this is concerning says Hornetsecurity.
Post-incident adaptations and reporting gaps
The survey found that one in four organizations had suffered a cybersecurity breach or incident – 23% of which had occurred in the last year. Notably, 94% of these organizations took steps to strengthen their security by implementing additional controls post-incident. Yet, despite these efforts, 52% of respondents noted that end-users often ignore or delete identified email threats without reporting them, and 38% forget the training content, showing the need for ongoing and engaging training enhancements.
The survey highlighted that people are particularly interested in more effective post-training resources, which could help in retaining and applying the learned security measures. Another area for improvement is feedback on reported threats, with 28% stating the lack of feedback as a reason for not adhering to training protocols.
The need for updated training methods and content
A significant 45% of decision-makers in IT believe their current training programmes are outdated and ineffective against AI-powered attacks. This sentiment is echoed by 39% of general respondents, showing a critical need for training content that is both current and comprehensive.
Cyber insurance and preventative measures
Over half of the surveyed organizations (56%) now use cyber-insurance, indicating a growing reliance on financial safeguards against cyber incidents. Additionally, 79% of organizations attribute the prevention of cybersecurity incidents directly to their IT security training programmes, while 92% acknowledge that the training has enabled end-users to spot security threats across various media, not just email.
The study, Company IT Security Awareness, was conducted by Hornetsecurity in April 2024 and had more than 150 respondents.






