Is employee cybersecurity training a waste of money?
Cybersecurity training for employees is mostly a waste of money. I've seen our company spend thousands on phishing simulations, yet the click rate on fake emails barely dropped from 28% to 22% over two years. If people can't learn to spot a fake login page after repeated drills, maybe we should invest in better technical controls instead of endless awareness programs. But I'm not sure if the low retention is due to poor training design or human nature.