Security Awareness Training, Defined
Security awareness training is the ongoing practice of teaching employees to recognise and safely respond to cyber threats aimed directly at them such as phishing, fraudulent phone calls and social engineering. It aims to change everyday behaviour so the people attackers target become a working part of the defence.
It matters because people are the most attacked layer of any organisation. Verizon’s 2026 Data Breach Investigations Report found the human element present in 62% of breaches, a figure that has barely moved in years. Attackers rarely need to defeat your firewall when they can persuade someone to open a door.
It is also no longer optional. Since 15 January 2026 Cybersäkerhetslagen, Sweden’s NIS2 law, has required security awareness training by law and holds company boards personally accountable. What used to be a yearly IT task is now a duty the board must oversee.
What a Security Awareness Programme Covers
A good programme is broader than a phishing test. It covers recognising phishing emails, fraudulent calls and text messages, using passwords and multi-factor authentication well, handling sensitive data and devices, spotting physical risks like tailgating and reporting anything suspicious the moment it appears.

Programmes come in several formats. The familiar one is a mandatory annual module. Others include simulated phishing emails, short micro-learning nudges through the year, role-based training for finance or IT and quick drills on how to report. The formats matter less than whether people actually engage.
Two things pushed it up the agenda. Generative AI has made convincing scams cheap to produce at scale so the old advice to look for bad spelling no longer holds. And a wave of regulation led by NIS2, now names security awareness training as a specific control that organisations must have.
The Threats Training Has to Cover
Social engineering is a family of techniques that target people. Training has to cover the main ones because attackers move between them freely.
- Phishing: Mass fraudulent emails that harvest passwords or plant malware
- Spear phishing: A tailored email aimed at one person using real details to look genuine
- Vishing: A phone call impersonating IT, a bank or a supplier to extract access or payment
- Smishing: The same trick by text message often a link or a fake delivery notice
- Quishing: A QR code leading to a credential-stealing page, common on posters and invoices
- Business email compromise: A fake or hijacked email that authorises a payment or a bank-detail change
- Pretexting: An invented backstory that makes an unusual request feel reasonable
- MFA fatigue: Repeated login prompts sent until a tired user finally approves one
- Deepfake and AI voice: A cloned voice or video of a known person on a live call
Email is still the most common channel for social engineering but it no longer has a monopoly. In Verizon’s 2026 DBIR, phone and text lures were clicked about 40% more often than email ones in simulation data and mobile-centric social engineering is rising fast . Two of these deserve their own guides. Read the eBuilder guides on business email compromise and AI-powered phishing for the detail.
The Business Impact
The human layer is where the money leaks out. Business email compromise alone caused $2.77 billion in losses reported to the FBI’s Internet Crime Complaint Center in the United States in 2024 across more than 21,000 complaints. Phishing was the single most reported crime the FBI logged that year.
The damage arrives through a few well-worn routes. A tricked payment sends money straight to a criminal. Stolen credentials open the way to ransomware and data theft. A leaked personal-data set then triggers breach-notification duties and fines. One human moment can start any of these.
Sweden has felt this directly. In August 2025 a ransomware attack on the supplier Miljödata disrupted services across roughly 200 of Sweden’s 290 municipalities. In January 2024 the Tietoevry attack took down payroll, health records and retail systems for days. The entry point was a supplier and its staff. Exotic zero-days did not feature.
There is a second cost that rarely gets counted. Training that people click through without reading spends real budget and buys little protection as the evidence set out below shows. A programme earns its budget only when it changes what people do. It is worth checking your own exposure too so run a free domain breach check to see whether staff credentials are already leaked.
Real-World Cases
In each of these breaches, what stopped the loss was a process or a piece of technology. Individual vigilance was not the deciding factor.
Twitter, 2020
In July 2020 attackers phoned Twitter staff posed as the company’s IT help desk and claimed to be fixing a VPN problem. They sent employees to a login page that mirrored the real one and captured the password and the multi-factor code as they were typed.
With that access they reached staff who controlled account tools and hijacked 130 high-profile accounts to run a bitcoin scam taking about $118,000. Regulated cryptocurrency firms blocked over 6,000 further transfers worth about $1.5 million, per the New York State Department of Financial Services.
A phishing-resistant multi-factor method such as a hardware security key, would have defeated the real-time credential theft. Tightly limiting who can reach internal account tools would have contained the rest.
MGM Resorts, 2023
In September 2023 the group known as Scattered Spider called the MGM Resorts IT help desk and talked their way into resetting an employee’s access. From there they reached the company’s identity systems and set off a ransomware attack.
The disruption ran for about ten days across the Las Vegas properties, took down room keys, slot machines and booking systems and, by MGM’s own account, cost around $100 million in the quarter. Roughly 37 million customers’ data was later reported exposed.
Here the weak point was the help desk. An identity check that a caller cannot talk their way past such as a callback to a registered number or a manager’s approval would have stopped the reset.

Google and Facebook, 2013 to 2015
Between 2013 and 2015 a man named Evaldas Rimasauskas set up a company in Latvia with almost the same name as Quanta Computer, a real supplier to both Google and Facebook. He sent the two firms fake invoices, contracts and signed letters.
Staff wired more than $100 million to accounts he controlled before the fraud was caught. Both companies recovered all or most of the money and Rimasauskas was sentenced to five years in prison in 2019, according to the US Department of Justice.
No amount of email awareness reliably stops a well-forged invoice. The control that works is a rule that any payment or change of supplier bank details is verified out of band, on a number already held before money moves.
Security Awareness Training and Compliance
For Swedish organisations, awareness training is no longer just good practice. Several regimes now require it and each expects evidence that it happens.
Under NIS2, transposed into Swedish law as Cybersäkerhetslagen (SFS 2025:1506) and in force since 15 January 2026, security awareness training is a named requirement. Article 21.2(g) lists basic cyber hygiene and security awareness training among the required measures.
Article 20 goes further. It makes the board responsible for approving and overseeing security measures and its members can be held personally accountable by supervisors. Fines reach up to 10 million euro or 2% of global turnover for essential entities.
When an incident does happen, NIS2 sets a tight reporting cascade to MCF (formerly MSB) of 24 hours, 72 hours and one month. That is far easier to meet when staff report fast which is itself a trained behaviour.
Financial entities face a stricter rule. DORA (Regulation (EU) 2022/2554) which has applied since 17 January 2025, requires under Article 13(6) that ICT security awareness and resilience training be compulsory for all staff and senior management, with the depth matched to each role. In Sweden it is supervised by Finansinspektionen.
GDPR treats training as part of protecting personal data. Article 39 lists staff awareness-raising and training among the data protection officer’s tasks and Article 32 requires appropriate security of processing. A breach must be reported to the Swedish authority IMY within 72 hours under Article 33.
ISO/IEC 27001, the main information security standard requires awareness directly. Control 6.3 of the 2022 version covers information security awareness, education and training and auditors will ask for evidence that staff have completed it.
The EU AI Act adds a newer duty. Since 2 February 2025, Article 4 of the AI Act (Regulation (EU) 2024/1689) has required organisations to ensure staff who use AI have sufficient AI literacy. As attackers use AI to build their scams, this sits naturally alongside security awareness.
What the Evidence Says About Training
Here is the uncomfortable part. A 2025 University of California, San Diego study ran an eight-month randomised trial across more than 19,500 staff, sending ten phishing simulations. It found no meaningful link between having recently done annual awareness training and whether someone fell for a phishing email.
Embedded training shows a tip right after someone clicks a test. It cut the click rate by only about two percentage points. Around three quarters of staff spent a minute or less on the training and roughly a third closed it at once. The researchers concluded that training as usually run does little to reduce phishing risk.
The same study found one bright spot. When people actually completed interactive training, their susceptibility fell by about 19%. The problem was that few finished it. So the lesson is simple. Training can work but only when it is good enough that people engage with it.
There is a second reason to be humble. You cannot reliably spot a modern attack by eye. AI-generated voices, cloned video and well-forged invoices pass human inspection, and the people fooled at MGM and Google were not careless. Vigilance alone is not a control you can depend on.
So what does hold up. Two things. Building a fast, blame-free way for people to report so a click becomes an alert within minutes. And technical and process controls that catch the mistakes training will always miss.
How to Build Security Awareness Training That Works
A programme that changes behaviour works on three fronts at once.

People. Run short, frequent training rather than one annual module and make it interactive enough that staff finish it. Tailor it by role so finance learns invoice fraud and IT learns help-desk pretexting. Above all, reward reporting and never punish an honest mistake.
Process. Require a second out-of-band check for any payment or change of bank details. Give the help desk an identity test a caller cannot fake. Make reporting a suspicious message take one click with a fast, visible response when it does. Pressure-test the whole thing with realistic simulations and penetration testing.
Technology. Lean on it to carry the load people cannot. Deploy phishing-resistant multi-factor authentication so a stolen password is not enough. Filter email and web traffic to cut what reaches people in the first place. Apply least-privilege access so one compromised account cannot reach everything and back it with managed detection and response to catch what still gets through.
Run it this way and awareness training becomes a defence you can measure. eBuilder Security builds and runs Sweden-based security awareness training built on exactly this model. The training is short enough that people finish it and is backed by a reporting culture and the technical controls that catch what training misses.
Give people training worth their time and controls that forgive their mistakes and the human layer starts working for you.


