Is mandatory cybersecurity training a waste of money?
Cybersecurity training for employees often feels like a box-ticking exercise, yet breaches keep happening because of human error. I've seen companies spend thousands on awareness programs, but the same phishing email still gets clicked weeks later. Maybe the real problem isn't awareness—it's that we're designing training that fights human nature instead of working with it. Should we abandon mandatory training and invest in technical controls like better email filtering and multi-factor authentication instead?