Employees should get cybersecurity training at least once a year, but annual training alone isn’t enough. A practical cadence is training during onboarding, a short lesson every month, a simulated phishing test every month or quarter and a fuller annual refresher. Short and frequent beats long and rare.
Most owners we talk to around Dallas-Fort Worth already know their people are part of the security picture. The question is how much training is enough without turning it into a chore nobody takes seriously. We’ve seen both extremes. One office runs a single 45-minute video every January and calls it done. Another floods inboxes with so many fake phishing tests that staff stop opening email from anyone they don’t know, including customers. Neither one works very well. Here’s a cadence that does, and why it matters more than it used to.
Why does employee cybersecurity training matter?
Because most breaches still involve a person somewhere in the chain. The Verizon 2025 Data Breach Investigations Report found the human element in about 60 percent of breaches. That includes clicking a phishing link, falling for a fake invoice, reusing a password or sending a file to the wrong person.
The tactics keep shifting, too. Verizon’s 2026 report found that social engineering by text message and phone call succeeds about 40 percent more often than email phishing. It also found employee use of unapproved AI tools jumped from 15 percent to 45 percent in a single year. A training program built around 2019-era email scams misses a lot of today’s risk.
Is cybersecurity everyone’s responsibility, or just IT’s?
It’s everyone’s, and that’s not a slogan. Your IT provider can filter email, patch systems and lock down accounts. It can’t stop the bookkeeper from approving a wire transfer after a convincing phone call, or the new hire from typing their Microsoft password into a fake login page at 4:45 on a Friday.
We think of it like a building’s fire safety. Facilities installs sprinklers and alarms, but everyone still needs to know where the exits are and not to prop open the fire door. Good managed security handles the sprinklers. Training handles the habits. Leadership has to own both, because staff take their cues from what the boss treats as important. If the owner skips the training, everybody notices.
What percentage of breaches are caused by human error?
The figure most often cited is Verizon’s: roughly 60 percent of breaches involve a human action, whether an honest mistake or someone being tricked. That number has stayed in the same range for several years. It’s worth framing carefully with your team. The point isn’t that employees are the problem. Attackers target people because people are busy, helpful and trusting, which are the same traits that make them good at their jobs. Training helps them pause at the right moment.
How often should employees get cybersecurity training?
Here’s the cadence we recommend for most organizations with 20 to 150 people.
| When | What | Time it takes |
|---|---|---|
| First week on the job | Security basics, password and MFA setup, how to report something suspicious | 30 to 45 minutes |
| Monthly | One short lesson on a single topic (texts, fake invoices, AI tools, QR codes) | 3 to 10 minutes |
| Monthly or quarterly | Simulated phishing email, with instant coaching for anyone who clicks | Seconds, unless they click |
| Annually | Full refresher, policy review and signed acknowledgment | 30 to 60 minutes |
| As needed | Quick alert when a new scam is circulating locally or targeting your industry | 2 minutes |
The research supports frequency over volume. In KnowBe4’s 2025 benchmarking report, covering 14.5 million users, the share of untrained employees who clicked a simulated phish started at 33.1 percent. After 90 days of regular training and testing it fell by 40 percent. After 12 months it was down to 4.1 percent. That’s a vendor’s own data, so read it with that in mind, but the direction matches what we see in practice.
The NIST guidance on building a cybersecurity learning program makes a similar point. Training should be ongoing and adjusted to the roles and risks in your organization, not a once-a-year checkbox.
Do some roles need more training than others?
Yes. Anyone who moves money, changes vendor banking details, manages payroll or has administrator access should get extra, role-specific training at least quarterly. These are the people attackers research by name. Executives belong on that list too, even though they’re usually the hardest to schedule.
Are there legal or insurance requirements for training?
Often, yes, depending on who you are.
- Cyber insurance: many carriers ask about security awareness training and phishing tests on applications and renewals. A vague answer can affect your premium or coverage.
- Texas local governments: Texas Government Code 2054.5191 requires employees and officials who use a computer for at least 25 percent of their duties to complete DIR-certified cybersecurity training every year, with compliance certified to DIR by August 31. The Texas Association of Counties notes that county staff now also complete an AI training. Our local government page covers how we support cities and water districts.
- Healthcare: HIPAA requires workforce training, and Texas adds training within 90 days of hire and at least every two years. Our post on HIPAA facts for small practices has the details.
- Financial services and others: the FTC Safeguards Rule, PCI DSS 4.0.1 and CJIS all include security awareness training requirements.
What should security awareness training cover in 2026?
- Phishing by email, text, phone and Teams messages
- Fake invoices and requests to change payment or banking details
- Multifactor authentication prompts you didn’t request
- Safe use of AI tools like Microsoft Copilot, and what not to paste into public chatbots
- Password managers and passphrases
- Working securely from home or on the road
- How and where to report something suspicious, with no blame attached
That last point matters more than any single topic. If people are afraid of getting in trouble, they’ll quietly delete the suspicious email after they’ve already clicked it. We’d much rather hear “I think I messed up” within five minutes than discover it five weeks later.
How do you make training stick?
Keep it short, keep it relevant and keep it local when you can. A lesson about a fake toll-road text lands differently with people who drive the tollways around the metroplex every day. Share real examples of attempts your own team caught. Celebrate the reporters, not just the clickers. And measure two numbers each quarter: the click rate on simulations and the report rate. A rising report rate is one of the best signs your culture is moving in the right direction.
Frequently asked questions
How often should employees have cybersecurity training?
At minimum once a year, plus training at onboarding. Most organizations get better results with a short monthly lesson and phishing simulations every month or quarter.
How long should security awareness training be?
Monthly lessons work best at 3 to 10 minutes. Onboarding and the annual refresher can run 30 to 60 minutes. Shorter, frequent sessions are remembered better than one long annual video.
Do small businesses need security awareness training?
Yes. Small businesses are frequent targets because they often have fewer controls, and one employee mistake can affect the entire company. Training is one of the lowest-cost risk reductions available.
How often should you run phishing simulations?
Monthly or quarterly works for most organizations. Vary the style and difficulty, and give anyone who clicks short, immediate coaching rather than punishment.
Is annual cybersecurity training required in Texas?
For state agencies and local governments, yes. Texas Government Code 2054.5191 requires annual DIR-certified training for employees and officials who use a computer for at least 25 percent of their duties. Private businesses may face requirements through HIPAA, PCI, the FTC Safeguards Rule or their cyber insurer.
How The Fulcrum Group helps
We help North Texas organizations build security awareness into everyday operations instead of treating it as an annual event. Through SPOT Managed Security Services and SPOT Managed IT Services, that includes simulated phishing, short training content, reporting that leadership can actually read and the technical controls that catch what training misses. We’ll help you pick a cadence your team will stick with.
If you’d like to talk through where your team stands, Schedule a Discovery Call.

