Human layer

What is Security Awareness Training?

The business guide to security awareness training. What it covers, what the evidence says works and the duty it now carries under Swedish law.

Key takeaways
  • The human element features in 62% of breaches, so people are the most attacked layer of any organisation (Verizon 2026 DBIR).
  • Security awareness training is now a legal duty in Sweden under Cybersäkerhetslagen and NIS2, with boards personally accountable.
  • Social engineering is the third most common breach pattern, and attacks increasingly arrive by phone and text as well as email.
  • Business email compromise caused $2.77 billion in losses reported to the FBI in the US in 2024.
  • A 2025 University of California, San Diego trial of 19,500 staff found annual and embedded training barely changed the phishing click rate.
  • In that trial, interactive training that people completed cut susceptibility by about 19%, but few finished it.
  • In the Twitter, MGM and Google and Facebook cases, the control that stopped the loss was a process or a technology, not staff spotting the attack.
  • Training works only when it is short, engaging, continuous and paired with a fast reporting culture.
  • Phishing-resistant multi-factor authentication and out-of-band payment verification catch the mistakes training will miss.
  • The goal is measurable behaviour change, and a programme should be judged on that.

Security Awareness Training, Defined

Security awareness training is the ongoing practice of teaching employees to recognise and safely respond to cyber threats aimed directly at them such as phishing, fraudulent phone calls and social engineering. It aims to change everyday behaviour so the people attackers target become a working part of the defence.

It matters because people are the most attacked layer of any organisation. Verizon’s 2026 Data Breach Investigations Report found the human element present in 62% of breaches, a figure that has barely moved in years. Attackers rarely need to defeat your firewall when they can persuade someone to open a door.

It is also no longer optional. Since 15 January 2026 Cybersäkerhetslagen, Sweden’s NIS2 law, has required security awareness training by law and holds company boards personally accountable. What used to be a yearly IT task is now a duty the board must oversee.

What a Security Awareness Programme Covers

A good programme is broader than a phishing test. It covers recognising phishing emails, fraudulent calls and text messages, using passwords and multi-factor authentication well, handling sensitive data and devices, spotting physical risks like tailgating and reporting anything suspicious the moment it appears.

Security Awareness Programme Covers

Programmes come in several formats. The familiar one is a mandatory annual module. Others include simulated phishing emails, short micro-learning nudges through the year, role-based training for finance or IT and quick drills on how to report. The formats matter less than whether people actually engage.

Two things pushed it up the agenda. Generative AI has made convincing scams cheap to produce at scale so the old advice to look for bad spelling no longer holds. And a wave of regulation led by NIS2, now names security awareness training as a specific control that organisations must have.

The Threats Training Has to Cover

Social engineering is a family of techniques that target people. Training has to cover the main ones because attackers move between them freely.

  • Phishing: Mass fraudulent emails that harvest passwords or plant malware
  • Spear phishing: A tailored email aimed at one person using real details to look genuine
  • Vishing: A phone call impersonating IT, a bank or a supplier to extract access or payment
  • Smishing: The same trick by text message often a link or a fake delivery notice
  • Quishing: A QR code leading to a credential-stealing page, common on posters and invoices
  • Business email compromise: A fake or hijacked email that authorises a payment or a bank-detail change
  • Pretexting: An invented backstory that makes an unusual request feel reasonable
  • MFA fatigue: Repeated login prompts sent until a tired user finally approves one
  • Deepfake and AI voice: A cloned voice or video of a known person on a live call

Email is still the most common channel for social engineering but it no longer has a monopoly. In Verizon’s 2026 DBIR, phone and text lures were clicked about 40% more often than email ones in simulation data and mobile-centric social engineering is rising fast . Two of these deserve their own guides. Read the eBuilder guides on business email compromise and AI-powered phishing for the detail.

The Business Impact

The human layer is where the money leaks out. Business email compromise alone caused $2.77 billion in losses reported to the FBI’s Internet Crime Complaint Center in the United States in 2024 across more than 21,000 complaints. Phishing was the single most reported crime the FBI logged that year.

The damage arrives through a few well-worn routes. A tricked payment sends money straight to a criminal. Stolen credentials open the way to ransomware and data theft. A leaked personal-data set then triggers breach-notification duties and fines. One human moment can start any of these.

Sweden has felt this directly. In August 2025 a ransomware attack on the supplier Miljödata disrupted services across roughly 200 of Sweden’s 290 municipalities. In January 2024 the Tietoevry attack took down payroll, health records and retail systems for days. The entry point was a supplier and its staff. Exotic zero-days did not feature.

There is a second cost that rarely gets counted. Training that people click through without reading spends real budget and buys little protection as the evidence set out below shows. A programme earns its budget only when it changes what people do. It is worth checking your own exposure too so run a free domain breach check to see whether staff credentials are already leaked.

Real-World Cases

In each of these breaches, what stopped the loss was a process or a piece of technology. Individual vigilance was not the deciding factor.

Twitter, 2020

In July 2020 attackers phoned Twitter staff posed as the company’s IT help desk and claimed to be fixing a VPN problem. They sent employees to a login page that mirrored the real one and captured the password and the multi-factor code as they were typed.

With that access they reached staff who controlled account tools and hijacked 130 high-profile accounts to run a bitcoin scam taking about $118,000. Regulated cryptocurrency firms blocked over 6,000 further transfers worth about $1.5 million, per the New York State Department of Financial Services.

A phishing-resistant multi-factor method such as a hardware security key, would have defeated the real-time credential theft. Tightly limiting who can reach internal account tools would have contained the rest.

MGM Resorts, 2023

In September 2023 the group known as Scattered Spider called the MGM Resorts IT help desk and talked their way into resetting an employee’s access. From there they reached the company’s identity systems and set off a ransomware attack.

The disruption ran for about ten days across the Las Vegas properties, took down room keys, slot machines and booking systems and, by MGM’s own account, cost around $100 million in the quarter. Roughly 37 million customers’ data was later reported exposed.

Here the weak point was the help desk. An identity check that a caller cannot talk their way past such as a callback to a registered number or a manager’s approval would have stopped the reset.

Real-World Cases

Google and Facebook, 2013 to 2015

Between 2013 and 2015 a man named Evaldas Rimasauskas set up a company in Latvia with almost the same name as Quanta Computer, a real supplier to both Google and Facebook. He sent the two firms fake invoices, contracts and signed letters.

Staff wired more than $100 million to accounts he controlled before the fraud was caught. Both companies recovered all or most of the money and Rimasauskas was sentenced to five years in prison in 2019, according to the US Department of Justice.

No amount of email awareness reliably stops a well-forged invoice. The control that works is a rule that any payment or change of supplier bank details is verified out of band, on a number already held before money moves.

Security Awareness Training and Compliance

For Swedish organisations, awareness training is no longer just good practice. Several regimes now require it and each expects evidence that it happens.

Under NIS2, transposed into Swedish law as Cybersäkerhetslagen (SFS 2025:1506) and in force since 15 January 2026, security awareness training is a named requirement. Article 21.2(g) lists basic cyber hygiene and security awareness training among the required measures.

Article 20 goes further. It makes the board responsible for approving and overseeing security measures and its members can be held personally accountable by supervisors. Fines reach up to 10 million euro or 2% of global turnover for essential entities.

When an incident does happen, NIS2 sets a tight reporting cascade to MCF (formerly MSB) of 24 hours, 72 hours and one month. That is far easier to meet when staff report fast which is itself a trained behaviour.

Financial entities face a stricter rule. DORA (Regulation (EU) 2022/2554) which has applied since 17 January 2025, requires under Article 13(6) that ICT security awareness and resilience training be compulsory for all staff and senior management, with the depth matched to each role. In Sweden it is supervised by Finansinspektionen.

GDPR treats training as part of protecting personal data. Article 39 lists staff awareness-raising and training among the data protection officer’s tasks and Article 32 requires appropriate security of processing. A breach must be reported to the Swedish authority IMY within 72 hours under Article 33.

ISO/IEC 27001, the main information security standard requires awareness directly. Control 6.3 of the 2022 version covers information security awareness, education and training and auditors will ask for evidence that staff have completed it.

The EU AI Act adds a newer duty. Since 2 February 2025, Article 4 of the AI Act (Regulation (EU) 2024/1689) has required organisations to ensure staff who use AI have sufficient AI literacy. As attackers use AI to build their scams, this sits naturally alongside security awareness.

What the Evidence Says About Training

Here is the uncomfortable part. A 2025 University of California, San Diego study ran an eight-month randomised trial across more than 19,500 staff, sending ten phishing simulations. It found no meaningful link between having recently done annual awareness training and whether someone fell for a phishing email.

Embedded training shows a tip right after someone clicks a test. It cut the click rate by only about two percentage points. Around three quarters of staff spent a minute or less on the training and roughly a third closed it at once. The researchers concluded that training as usually run does little to reduce phishing risk.

The same study found one bright spot. When people actually completed interactive training, their susceptibility fell by about 19%. The problem was that few finished it. So the lesson is simple. Training can work but only when it is good enough that people engage with it.

There is a second reason to be humble. You cannot reliably spot a modern attack by eye. AI-generated voices, cloned video and well-forged invoices pass human inspection, and the people fooled at MGM and Google were not careless. Vigilance alone is not a control you can depend on.

So what does hold up. Two things. Building a fast, blame-free way for people to report so a click becomes an alert within minutes. And technical and process controls that catch the mistakes training will always miss.

How to Build Security Awareness Training That Works

A programme that changes behaviour works on three fronts at once.

 Build Security Awareness Training That Works

People. Run short, frequent training rather than one annual module and make it interactive enough that staff finish it. Tailor it by role so finance learns invoice fraud and IT learns help-desk pretexting. Above all, reward reporting and never punish an honest mistake.

Process. Require a second out-of-band check for any payment or change of bank details. Give the help desk an identity test a caller cannot fake. Make reporting a suspicious message take one click with a fast, visible response when it does. Pressure-test the whole thing with realistic simulations and penetration testing.

Technology. Lean on it to carry the load people cannot. Deploy phishing-resistant multi-factor authentication so a stolen password is not enough. Filter email and web traffic to cut what reaches people in the first place. Apply least-privilege access so one compromised account cannot reach everything and back it with managed detection and response to catch what still gets through.

Run it this way and awareness training becomes a defence you can measure. eBuilder Security builds and runs Sweden-based security awareness training built on exactly this model. The training is short enough that people finish it and is backed by a reporting culture and the technical controls that catch what training misses.

Give people training worth their time and controls that forgive their mistakes and the human layer starts working for you.

Myths & Facts

Myth

Security awareness training stops phishing on its own.

One training session a year is enough.

Phishing simulations reduce risk by catching people out.

Only junior or non-technical staff need training.

If people just paid attention they would spot the attack.

Security awareness training is just a compliance checkbox.

Fact

Controlled trials show otherwise. A 2025 University of California, San Diego study of 19,500 staff found training as usually run barely changed the phishing click rate. It works only as one layer among technical controls.

A single annual module is skimmed by most people. In the same study around three quarters spent under a minute on it. Short, frequent and interactive training is what changes behaviour.

Gotcha tests do little to the click rate and can erode trust. Their real value is practising fast reporting, so a genuine click becomes an alert within minutes.

Executives, finance and IT are prime targets, through invoice fraud and help-desk impersonation. NIS2 also makes the board personally accountable for security.

Modern AI voices, cloned video and forged invoices pass human inspection. Verification and technical controls are what stop them.

NIS2, DORA, GDPR and ISO 27001 all require it, yet the evidence shows checkbox training does not reduce risk. The point is measurable behaviour change.

Test Yourself

Four real-world scenarios, then six knowledge questions. See how prepared you would be under pressure.

Scenario Simulation

  1. You get a phone call from someone saying they are from IT, asking you to confirm your login and approve a security prompt to fix a VPN issue.

    What do you do?

    • Give the details, since IT is calling
    • Hang up and call IT back on a number you already have
    • Approve the prompt to be safe
  2. Finance receives an email from a known supplier saying their bank details have changed, with a new account for the next invoice.

    What is the right first step?

    • Update the details and pay, the email looks genuine
    • Call the supplier on a number you already hold to confirm
    • Reply to the email to check
  3. A caller reaches the help desk saying they are a locked-out employee who needs their access reset urgently.

    What should the help desk do?

    • Reset the access quickly to help
    • Verify identity with a check the caller cannot fake, then decide
    • Ask for their staff ID number and reset if they know it
  4. You receive a text with a link about a missed parcel delivery, asking you to confirm your address and card.

    What do you do?

    • Tap the link and enter the details
    • Do not tap it and report it through your normal channel
    • Forward it to a colleague to check

Knowledge Test

  1. According to Verizon's 2026 report, roughly what share of breaches involve the human element?

    • About 22%
    • About 62%
    • About 92%

    The 2026 DBIR put the human element in 62% of breaches.

  2. What did the 2025 University of California, San Diego trial find about annual awareness training?

    • It barely changed the phishing click rate
    • It stopped almost all phishing
    • It doubled reporting overnight

    The trial found no meaningful link between recent annual training and failing a phishing test.

  3. In the studied cases, what usually stopped the loss?

    • Staff spotting the attack by eye
    • A process or technical control
    • Antivirus software

    Verification, help-desk checks and phishing-resistant MFA were the controls that made the difference.

  4. Which Swedish law makes security awareness training a legal duty?

    • Cybersäkerhetslagen
    • GDPR only
    • No law requires it

    Cybersäkerhetslagen, Sweden's NIS2 law, has required it since 15 January 2026.

  5. What is the most reliable way to handle a request to change supplier bank details?

    • Pay if the email looks genuine
    • Verify out of band on a number already held
    • Reply to the email to confirm

    Out-of-band verification stops business email compromise, which cost Google and Facebook over $100 million.

  6. Which approach best reduces human-layer risk?

    • One annual training module
    • Short continuous training plus reporting and technical controls
    • Telling staff to be more careful

    The evidence favours engaged, continuous training paired with a reporting culture and technical backstops.

Take It with You

Share the Summary PDF with Your Team

A short distilled brief in PDF: key findings, red flags and action steps.

Download summary PDF

Why Training Matters

Security awareness training is not a formality. It is how you defend the layer attackers aim at most, and since January 2026 it is a duty Swedish organisations carry by law.

The evidence is clear that only well-designed training changes behaviour. eBuilder Security builds and runs Sweden-based security awareness training that people engage with, sits alongside phishing simulations and a reporting culture and is backed by the technical controls that catch what training misses.

Frequently Asked Questions

What is security awareness training?

Security awareness training is the ongoing practice of teaching staff to recognise and safely handle cyber threats aimed at them, such as phishing, fraudulent calls and social engineering. Good programmes go beyond a yearly module to change everyday behaviour, using short, role-based and interactive sessions backed by a fast way to report anything suspicious.

What is the purpose of security awareness training?

The purpose of security awareness training is to reduce the risk that employees are tricked into giving attackers access, money or data. Because the human element features in 62% of breaches, per Verizon's 2026 report, the aim is to turn the most targeted layer into an active part of the defence and to meet legal duties like NIS2.

Is security awareness training legally required in Sweden?

Yes. Since 15 January 2026, Cybersäkerhetslagen, Sweden's NIS2 law, has required security awareness training as a specific measure, and it holds company boards personally accountable. Financial firms face a stricter version under DORA, and ISO 27001 and GDPR also expect staff to be trained and the training evidenced.

Does security awareness training actually work?

It helps, but only when done well. A 2025 University of California, San Diego trial of 19,500 staff found that annual and after-the-click training barely changed the phishing click rate, while interactive training people completed cut susceptibility by about 19%. It works best paired with a reporting culture and technical controls.

How often should security awareness training be done?

More often than once a year. The evidence favours short, frequent sessions over a single annual module, because most people skim a long yearly course. A practical rhythm is brief monthly or quarterly training, occasional phishing simulations and immediate reporting drills, adjusted to each role and refreshed as threats change.

What topics should security awareness training cover?

Security awareness training should cover the online threats staff actually encounter. These include phishing, fraudulent calls and texts, business email compromise, passwords and multi-factor authentication, safe data handling and how to report an incident. As attackers now use AI, add deepfake voice and video scams and tailor the depth to each role.

What is the difference between a security awareness programme and a phishing simulation?

A security awareness programme is the whole effort to change how staff handle risk, including training, policies, reporting and measurement. A phishing simulation is one tool inside it, a safe fake phishing email used to practise spotting and reporting. Simulations alone do little and work best as part of a wider programme.

Who in the organisation needs security awareness training?

Everyone with access to systems or data needs it, from the front desk to the board. Attackers deliberately target finance, HR, IT and senior leaders, because they can approve payments or hold wide access. Under NIS2, board members must follow training themselves and can be held personally accountable for security.

You Understand the Risk.
Now See Where You Stand.

Book a 30-minute briefing with one of our analysts, or run the free breach check first to find out what attackers already know about your organisation.

Book a 30-Min Briefing
No sales pitch, just a straight assessment

How eBuilder Security Can Help

Awareness is the first layer. These are the services that turn it into measurable protection.