Verizon’s 2026 Data Breach Investigations Report put the human element behind 62 percent of confirmed breaches. That’s the highest the figure has been in years, and it’s climbing while every vendor in the industry sells AI-powered detection.
Somebody clicked. A password went into the wrong page. A call that sounded exactly like the CFO ended in a wire transfer before lunch. None of that gets stopped by better firewall rules.
Most companies are still fighting this with a video from January. Forty minutes, a quiz at the end, done for the year. That model runs straight into the forgetting curve: most of what people learn in a single sitting fades within weeks without something to reinforce it. An annual session was already thin by the time anyone actually needed it.
The annual model was built for a slower attacker
Five years ago, phishing training meant one thing: spot the suspicious email, check the sender, don’t click the link. That still matters, but it covers a shrinking share of how people actually get compromised now.
The FBI’s 2025 Internet Crime Report put AI-enabled fraud losses at 893 million dollars for the year, and investigators think the real number is higher, since plenty of victims never trace the loss back to AI at all. Voice cloning tools that used to require a film studio now run on a laptop. A finance manager gets a call that sounds exactly like the CEO, urgent tone and all, asking for a wire transfer before end of day. The verification habit employees were trained on, checking a sender’s email address, doesn’t even apply here.
There’s a technical version of this shift too, and it matters for anyone still training staff to rely on multi-factor authentication as the safety net. Adversary-in-the-middle phishing kits don’t steal a password anymore. They steal the session token after MFA has already succeeded, so the sign-in log shows a completely normal login. The employee did everything right by the old training. The attacker walked in anyway.
Gartner’s cybersecurity predictions put a number on what happens when training keeps up with this instead of lagging behind it: organisations combining generative AI with an integrated, behaviour-focused security programme are projected to see 40 percent fewer employee-driven incidents by 2026. That’s not a small difference. That’s the gap between a programme that produces a certificate and one that changes what people actually do under pressure.
Continuous beats annual, and the data backs it up
KnowBe4’s 2026 global benchmarking report found that organisations running a consistent training programme cut phishing susceptibility by 79 percent within a year. The same report tracked a 17 percent spike in phishing volume since late 2025. Training has to move at the same speed the attacks are moving, which an annual calendar entry cannot do.
What replaces it in practice: short monthly content instead of one long session, phishing simulations on a rolling schedule instead of a single test, and a nudge that lands right after someone does something risky rather than three months later in a scheduled refresher. It doesn’t need to be elaborate. It needs to show up often enough that the forgetting curve never gets the chance to win.
Click rate is the wrong number on the dashboard
Ask most security teams for their top metric and they’ll say click rate. It’s the easiest number to report and the easiest one to misread.
A team whose click rate drops while its report rate also drops is not improving. It’s learning to hide mistakes. That usually traces back to how failed simulations get handled. Publicly call someone out for clicking a test email, and the next real phishing attempt gets deleted quietly instead of reported, because reporting now feels like confessing.
Report rate and reporting speed are the numbers worth watching instead. Some platforms now build a human risk score by department, which turns “92 percent of staff completed the training” into something closer to “the finance team’s risk score fell after three months of targeted simulation work,” the kind of sentence a board can actually act on. One of those tells you something. The other just proves a video got watched.
All of it depends on a no-blame culture underneath it. A quick, judgment-free conversation after a failed simulation keeps people willing to raise their hand next time. A formal write-up teaches them to stay quiet.
Where to actually start
Pick a handful of engaged staff across departments, not just IT, and give them slightly deeper training and a direct line to the security team. Programmes that do this scale further than any single security lead managing awareness alone. Onboarding is worth a specific mention here too: security habits built into someone’s first week tend to stick for years, and it’s the cheapest moment in the entire employee lifecycle to get this right. Most companies still skip it in favour of squeezing a slide deck into an already packed induction.
This is the gap iConnect’s security awareness training is built to close for organisations across the UAE.
If your current programme is still one annual video and a certificate, that’s worth a straight conversation before the next audit asks for evidence you don’t have.