Technical defenses keep improving, yet human-layer breaches keep rising, per the 2026 Verizon DBIR. Here's why standard awareness training isn't working.
Every year, companies spend more on firewalls, endpoint detection, cloud security posture management, and AI-powered threat monitoring. Every year, the technical perimeter gets genuinely harder to breach directly.
And every year, the human element shows up in more breaches, not fewer.
Verizon's 2026 Data Breach Investigations Report — 31,000 incidents analyzed, over 22,000 confirmed breaches — found the human element present in 62% of them, up from 60% the year before. Social engineering alone accounted for 16% of confirmed breaches. Phone-based social engineering attempts — vishing, pretext calls — now succeed roughly 40% more often than email-based ones. Pretexting, the simple act of a convincing lie told with confidence, was promoted this year to a primary initial access vector in its own right.
Technical defenses didn't get worse. Attackers just kept doing what has always worked, and adapted it.
This isn't a mystery, and it isn't really about people being careless. It's about incentives on both sides of the interaction.
A firewall doesn't want to help you. A person does. Most people are cooperative, want to be helpful to a colleague or a customer, and — reasonably — don't treat every unusual request as a potential attack. That's not a flaw to be trained out of someone. It's the same trust that makes a workplace functional in the first place. An attacker doesn't need to break that trust. They just need to borrow it for one conversation.
The specific techniques keep evolving, too. AI has made this worse in a very concrete way: this year's DBIR found the median threat actor now uses AI assistance across roughly 15 distinct documented techniques during an attack, with some using it across 40 or 50. That's not just faster phishing emails — it's more convincing pretexts, researched targets, and, increasingly, real-time conversational deception over phone and voice channels that used to be far harder to fake convincingly.
We see the same pattern from the offensive side. A believable pretext — a claimed authority, a plausible urgent reason, a story that makes questioning it feel like the awkward move — is often all it takes to get past a person who has never been shown what that moment actually looks like from the inside.
Most companies already run some form of security awareness training. The DBIR's trend line is the evidence that, in aggregate, it isn't working well enough — not because awareness training is a bad idea, but because of how it's usually delivered:
Once a year, and then forgotten. An annual slideshow and a quiz doesn't survive contact with a threat landscape that changes month to month. The pretexting techniques, AI-assisted scam patterns, and vishing scripts attackers use today are meaningfully different from eighteen months ago. Training content that doesn't move with them falls behind fast.
Generic, not specific. Template phishing simulations using obviously fake sender domains teach people to recognize obviously fake phishing simulations. They don't reflect what a targeted attempt against your specific organization — using real information about your company, your team, your vendors — would actually look like.
Built around blame, not resilience. Telling people they're "the weakest link" doesn't make anyone stronger at spotting the next attempt — it just makes them less likely to report the one they missed. The goal of awareness training isn't to catch people failing. It's to build the instinct to pause, verify, and ask, before compliance happens automatically.
Effective security awareness training shares a few things in common, regardless of company size or industry:
It's grounded in real reconnaissance, not a template. The most convincing test of whether your team would fall for a targeted pretext is one built the way a real attacker would build it — using genuine open-source reconnaissance about your organization, not a generic "IT department" phishing template everyone has seen a hundred times.
It covers more than email. With voice and phone-based social engineering now outperforming email as an attack vector, training that only covers phishing is training for last decade's threat model.
It updates as the threat landscape does. Awareness training tied to current threat intelligence — what's actually being used against organizations like yours, right now — stays relevant in a way a static annual course never will.
It builds judgment, not just recognition. The goal isn't memorizing a list of red flags. It's building the reflex to slow down and verify when something feels slightly off — the same instinct that stops a pretext whether it arrives by phone, email, or an AI system asking for access it shouldn't have.
Security Awareness & Training is one of five services we offer — alongside penetration testing, AI red teaming, threat intelligence, and physical testing — and it's rarely at its best delivered in isolation. The most effective awareness programs we run are informed directly by findings from the other side of our work: the pretexts that actually got someone to open a door during a physical assessment, the reconnaissance that made a phishing attempt convincing, the current threat intelligence on what's actually being used against organizations in your sector right now.
That's a fundamentally different starting point than a licensed course built for every company in every industry. It's built for yours.
If your last awareness training was a slideshow nobody remembers past the quiz, that's worth revisiting — not because your team is the weak point, but because the techniques being used against them didn't stay still while the training did.
Get in touch to talk about what an awareness program built around your actual risk would look like.
Tell us what you're building and what you're worried about. We'll come back with a scope, a timeline, and a quote.
Request engagement ▸