My organization's security training completion rate once reached 92%, but it has steadily declined over the past year. Some employees now have several hours of overdue material. I'm considering clearing the backlog and restarting the program, but that feels like rewarding people for not completing their assignments. What training cadence, enforcement approach, or content changes have worked for others?
5 Answers
A practical cadence is one main course of 20–30 minutes every six months, supplemented by occasional five-minute micro-training. Monthly training can also work if each item is genuinely brief. Track more than completion rates: look at phishing-reporting behavior, repeat failures, and whether employees are applying what they learned. A reset may improve the completion statistic, but it won’t fix the underlying issue unless the content, workload, and accountability change.
Before wiping anything, ask leadership why the training exists, who needs it, and what the risk would be if it stopped. Then get their explicit support. For motivation, shorter lessons, recognition, and light gamification can work well—for example, acknowledging employees who report simulated or real phishing attempts. Make it feel like a shared security effort rather than an IT punishment.
Management support is probably the biggest factor. Training needs to be mandatory, with managers informed about incomplete assignments and held responsible for getting their teams to participate. Without that backing, IT can keep sending reminders, but participation will eventually drop.
That’s likely part of the problem. Manager buy-in was never very strong, even when completion rates were high, so I’m going to raise that with leadership.
An hours-long backlog usually means the program has become too large or difficult to keep up with. Consider resetting the assignments as part of a genuine program upgrade, not simply forgiving missed work. Replace long videos with two- to five-minute micro-lessons, short quizzes, and coaching immediately after someone clicks a simulated phishing message. That timing is valuable because the person is already thinking about what they missed. Keep the feedback constructive and avoid embarrassing people, since you want employees to report suspicious messages instead of hiding mistakes. A small amount of training every month or two is usually easier to complete than a large annual requirement.
We were already using relatively short modules, but some employees are years behind because I didn’t recognize the decline early enough. Framing the reset as an improved, lighter program makes more sense than presenting it as a free pass.
Use clear consequences and deadlines. Some organizations notify the employee and their manager, then restrict access if required training remains incomplete. It may be inconvenient to enforce, but people take the deadline seriously when it has a real operational impact. The exact consequence should match your policies and leadership’s approval.

Those questions should help me make a stronger case to management. I also like the idea of recognizing people who report phishing simulations instead of focusing only on failures.