Does cybersecurity awareness training actually reduce incidents?
Cybersecurity awareness training in most companies is a box-ticking exercise that fails to change employee behavior. I've seen colleagues click phishing links within a week after completing a mandated module, and the metrics rarely go beyond completion rates. Do these annual sessions actually reduce real-world incidents, or do we just feel safer?