Skip to main content
Change Management8 min read

Security Awareness Training: What It Cannot Fix

September 14, 2026By Ajan Kanagalingam

GreyNoise reported this month that one threat actor used AI agents to compromise PaperCut servers at 395 organisations in 48 countries. Not one employee at any of them had a decision to make. No email arrived, nothing was clicked, and the most security-aware workforce in the world would have made no difference. That is the boundary worth drawing before you renew a training subscription.

Two categories of attack

Needs a person to actBypasses people entirely
Phishing and credential harvestingUnpatched internet-facing software
Invoice fraud and payment redirectionCompromise through a supplier or MSP
MFA fatigue and code handoverCredentials reused from another breach
Physical access and tailgatingMisconfigured services exposed by accident

Training addresses the left column and does nothing for the right one. Both columns produce real breaches at Canadian small businesses, so a security budget spent entirely on the left is half a budget. The right column is addressed by patching, configuration and access design, which we set out in vulnerability management without a security team.

The tells you were taught no longer exist

A decade of training taught people to spot bad grammar, awkward phrasing, generic greetings and obvious urgency. Every one of those signals was an artefact of attackers writing in a second language at scale, and generative tools removed all of them at once.

A message today can be fluent in English or French, reference a real project by name, match your house style, arrive from a plausible address, and follow up appropriately when ignored. Voice cloning has made the phone route viable for the same cost, which we covered in AI voice cloning and deepfakes as a business threat.

Training that still teaches detection is teaching a skill the attacker has already priced out. Worse, it sets people up to feel confident about a judgement they can no longer make reliably, and confident people verify less.

Teach procedures, not detection

Procedures survive convincing messages because they do not depend on judging the message.

Any change to payment details is confirmed by phone. On a number from your own records, never a number in the message. This one rule prevents the most expensive category of small business fraud, and it costs a two-minute call.

Urgency is the signal. Not the content, the pressure. Teach people that a request to move fast and skip the usual step is itself the thing to slow down for, whoever appears to be asking.

Reporting takes under a minute, and nobody gets blamed. A forward button and a named recipient. Businesses that punish the person who clicked find out about the next one hours later, which is the difference between an incident and a disaster.

A codeword for unusual requests from leadership. Slightly awkward, entirely effective against voice cloning, and free.

Measure the right number

Most programmes track click rate on simulated phishing. Track reporting rate alongside it, and weight it higher.

A workforce where 8% click but 60% report within ten minutes is in far better shape than one where 3% click and nobody says anything. Somebody will always click eventually, and what determines the outcome is how quickly you learn about it. Reporting rate is also the number that improves when you remove blame, which makes it a useful check on whether your culture is working.

Run simulations quarterly rather than annually, keep the teaching short, and use the results to decide what to cover next rather than to identify people to embarrass.

Where the money goes further

For a small business choosing between another year of training modules and one technical control, the control usually wins, because it works whether or not anyone was paying attention.

Enforced multi-factor authentication on email and remote access. A patching cadence for anything internet-facing. Offline backups you have actually restored from. Removing standing domain admin rights from daily-use accounts. Each of those addresses the right-hand column, and each is also on the cyber insurance questionnaire, which means the same spend buys you a better premium.

Keep the training. Make it short, make it about procedures, run it quarterly, and stop expecting it to cover risks it was never able to reach. The wider point about AI raising the volume of convincing attacks is in agentic ransomware.

Frequently Asked Questions

Does security awareness training actually work?

It works on attacks that need a person to do something: click a link, approve a payment, hand over a code, let someone through a door. Measured properly, training plus regular simulation reduces click rates over time. It has no effect at all on attacks that never involve a human, such as an unauthenticated attacker exploiting a vulnerability in software facing the internet. Both categories are real, and only one of them is addressed by a training module.

What kinds of attack does training not help with?

Anything that bypasses people entirely. Exploitation of unpatched internet-facing software, compromise through a supplier or managed service provider, stolen credentials reused from another breach where no phishing was involved, and misconfigured services exposed by accident. The PaperCut campaign reported by GreyNoise in September 2026 is a clean example: attackers used AI agents to exploit two vulnerabilities at 395 organisations, and no employee anywhere had a decision to make.

Has AI made phishing training more or less useful?

More necessary and less sufficient at the same time. The old advice relied on tells that generative tools have removed: bad grammar, awkward phrasing, generic greetings. Convincing messages in fluent English or French, referencing real projects, are now cheap to produce at volume, and voice cloning has made phone-based approaches viable. Training that still teaches people to look for spelling mistakes is teaching a signal that no longer exists.

What should we teach instead of spotting fake emails?

Verification procedures rather than detection skills. A rule that any payment change is confirmed by phone on a number from your own records, not from the message. A rule that urgency is itself the signal to slow down. A no-blame path to report something suspicious in under a minute. These work regardless of how convincing the message was, which matters now that convincing is the default.

How often should security awareness training happen?

Short and frequent beats long and annual. A ten-minute refresher each quarter, plus periodic simulated phishing with results used to guide teaching rather than to punish, holds attention better than an hour-long module once a year that everyone clicks through. Track your reporting rate as well as your click rate, since a workforce that reports quickly limits damage even when someone clicks.

Spend on the gap, not the subscription

We sort your exposure into what people can prevent and what they cannot, then recommend the control that closes the biggest gap for the least money.

Related Articles

Change Management

Training Your Workforce to Collaborate with AI, Not Fear It

Feb 10, 2026Read more →
Change Management

Why Your AI Rollout Keeps Failing — and What Change Management Can Fix

Feb 10, 2026Read more →
Change Management

An AI Governance Framework for a Small Business

September 10, 2026Read more →
AK
Ajan Kanagalingam
Founder & ChatGPT Consultant, ChatGPT.ca

Ajan leads the ChatGPT.ca team: 200+ custom GPT builds and automation projects for 50+ businesses across 20+ industries. Based in Markham, Ontario. PIPEDA-compliant solutions.

Stay ahead of AI in Canada

Weekly case studies, new tools, and ROI playbooks for Canadian SMEs. One email, zero spam.