Every major cybersecurity report published in the last decade has converged on the same uncomfortable conclusion: the weakest link in most organizations’ security posture isn’t a firewall configuration or an unpatched server. It’s a person, at their desk, clicking a link that looked legitimate enough not to question.
The Data Behind the Human Factor
According to Verizon’s 2026 Data Breach Investigations Report — now in its 19th year and drawing on analysis of more than 31,000 real-world security incidents across 145 countries, making it one of the largest and most authoritative datasets in the industry — the human element was present in 62% of confirmed breaches, up from 60% the year before. Social engineering specifically remained the third most common attack pattern overall, accounting for 16% of confirmed breaches and over 5,300 individual incidents in the dataset.
What makes this finding particularly striking is that it isn’t new or improving. As one detailed analysis of the report put it: “Despite a decade of awareness training budgets, simulated phishing programs, and security culture initiatives, the line continues to bend in the wrong direction” (see Breacher.ai’s breakdown of the 2026 DBIR’s social engineering findings). The same analysis notes a meaningful shift in how these attacks succeed: phone-based social engineering attacks are now succeeding 40% more often than email-based attempts, and “pretexting” — building a false but convincing scenario to manipulate a target — has been promoted to a primary initial access vector for attackers, not just a supporting technique.
This matters enormously for how organizations think about their security training. A security awareness program built primarily around “don’t click suspicious email links” is already fighting the last war if attackers are increasingly succeeding through phone calls and elaborate pretexts instead.
Why Social Engineering Works — and Why Technology Alone Can’t Stop It
Social engineering succeeds because it exploits psychology, not software vulnerabilities. A convincing phone call from someone claiming to be from IT, a well-timed email that mimics a real vendor invoice, a fabricated urgent request from someone impersonating an executive — these attacks are effective precisely because they’re designed to bypass a person’s normal skepticism through urgency, authority, or familiarity, not because they exploit a coding flaw a security patch could fix.
This is exactly why firewalls, spam filters, and endpoint protection — while genuinely necessary — cannot fully solve this problem on their own. No technical control can perfectly distinguish a legitimate urgent request from a fabricated one; only a trained, alert employee can apply that judgment in the moment. This is fundamentally a training and awareness problem sitting inside what looks, on the surface, like a pure IT security problem.
What Effective Security Awareness Training Actually Requires
1. Recognition training, not just policy documents. Employees need to recognize the actual patterns of social engineering — unusual urgency, requests to bypass normal verification steps, pressure to act before “checking with anyone” — not just memorize a written policy they’ll forget within weeks. Recognition is a trained skill, built through repeated, realistic examples, not a one-time read-through of a security handbook.
2. Coverage across all the channels attackers actually use. Given that phone-based social engineering is now outperforming email-based attempts, training that only covers phishing emails is training against yesterday’s threat. Effective programs need to address vishing (voice phishing), pretexting over the phone, and increasingly, AI-generated deepfake audio and video impersonation — a genuinely new and growing risk category.
3. Realistic, low-stakes practice. Simulated phishing exercises — sending realistic but harmless test emails and tracking who clicks — remain one of the most effective training techniques precisely because they create a real, memorable moment of “I almost fell for that” without any actual consequence. The same principle can extend to simulated phone-based pretexting exercises as organizations mature their programs.
4. Consistent, tracked, repeated training — not an annual checkbox exercise. A single annual security awareness session, completed once and forgotten, does very little against a threat landscape that evolves constantly. Regular, shorter refreshers — tracked for completion, updated as new attack patterns emerge — build durable awareness far more effectively than an infrequent, lengthy training event.
5. Clear, blame-free reporting culture. Employees who suspect they’ve been targeted — or who realize after the fact that they may have fallen for an attempt — need a fast, low-friction way to report it without fear of punishment. Delayed reporting, often driven by embarrassment, is one of the most common reasons a minor incident escalates into a serious breach.
Why This Belongs in Your LMS, Not Just Your IT Department
Security awareness training has a structural problem in a lot of organizations: it’s frequently owned entirely by IT or information security teams, delivered through a disconnected, standalone tool that employees interact with once a year and otherwise ignore. This is precisely the wrong home for a training program that needs to be continuous, trackable, and consistent across an entire workforce.
A Learning Management System is a far better home for this content, for reasons that mirror why it’s the right infrastructure for any other compliance-critical training:
- Consistent delivery across the whole organization — every employee, regardless of department or location, receives the same core recognition training, rather than security awareness varying by which manager happened to prioritize it.
- Trackable completion for audit and compliance purposes — when a regulator, auditor, or cyber-insurance provider asks whether your organization actually trains employees on social engineering risks, a real completion record is a very different answer than “we sent an email about it once.”
- Easy content updates as the threat landscape shifts — given how quickly attack patterns evolve (the rise of voice-based attacks and AI-generated deepfakes being clear recent examples), training content needs to be updatable in place, not locked into a static annual presentation.
- Integration with broader compliance and onboarding content — security awareness fits naturally alongside other mandatory training (data protection, workplace policies) that new hires and existing employees need to complete on a recurring basis, all tracked through the same system.
This connects directly to the broader compliance and data-protection responsibilities many organizations now carry. For a deeper look at how Nigerian organizations specifically should think about the intersection of AI tools, employee training, and regulatory compliance, see our companion piece: AI Governance in Corporate Learning in Nigeria.
Building a Practical Security Awareness Program
Start with a baseline. Run an initial simulated phishing (and where feasible, simulated pretexting) exercise to understand your organization’s actual current vulnerability, rather than assuming.
Segment training by role and risk. Finance and HR staff who regularly handle sensitive requests or payment approvals face different social engineering risks than the average employee, and benefit from role-specific scenario training addressing those particular threats.
Make reporting genuinely easy and blame-free. A single-click “report suspicious message” option, paired with a clear organizational stance that reporting a near-miss is rewarded rather than punished, dramatically improves how quickly a real attempt gets flagged.
Track trends over time, not just point-in-time completion. An LMS that shows improving simulated-phishing click rates over successive quarters gives a genuine measure of whether training is working — a far more meaningful signal than a single completion percentage.
Update content as attack patterns shift. Given the documented rise in phone-based and AI-assisted social engineering, a training program still focused exclusively on email phishing from several years ago is already behind the actual threat.
Frequently Asked Questions
How often should security awareness training actually happen? More often than once a year. Short, frequent refreshers (monthly or quarterly micro-modules, combined with ongoing simulated phishing exercises) build lasting recognition far more effectively than a single lengthy annual session, and allow content to be updated quickly as attack patterns shift.
Isn’t social engineering primarily an IT problem to solve with better technical controls? Technical controls (spam filtering, call authentication, multi-factor authentication) genuinely help and should absolutely be in place — but the Verizon DBIR data makes clear that the human element remains present in the majority of breaches even with those controls active. Technology reduces the volume of attempts that reach an employee; it can’t fully replace an employee’s own trained judgment for the ones that get through.
What’s the single most cost-effective way to start improving security awareness? A baseline simulated phishing exercise, run before any new training program begins, gives a genuine measure of current vulnerability and a concrete before/after comparison once training is underway — far more useful than assuming a program is working based on completion rates alone.
Should security awareness training be mandatory for all employees, or just technical staff? All employees, without exception. The DBIR data shows social engineering succeeding across every seniority level and every department — executives are frequently targeted specifically because of the authority a compromised executive account or impersonation carries.
Conclusion
The consistent, decade-long finding across Verizon’s Data Breach Investigations Reports is not a controversial or surprising one at this point: technology alone cannot close the human-factor gap in cybersecurity, because social engineering is specifically engineered to exploit human psychology rather than software vulnerabilities. What closes that gap is sustained, well-designed, consistently delivered training — exactly the kind of program a Learning Management System is built to support, and exactly the kind of program that a once-a-year, IT-owned checkbox exercise consistently fails to deliver.