Employees Want Better Cybersecurity Skills. The Training Has to Keep Up.
Most employees don’t need to become security analysts. They do need to know what a suspicious situation looks like in the work they actually perform.

Cybersecurity training has an awkward reputation.
For many employees, it arrives as an annual module, a collection of familiar warnings and a quiz that strongly encourages remembering whatever appeared on the previous screen.
Meanwhile, the workplace has become considerably less predictable.
ENISA’s latest Cybersecurity Month data shows that 74% of surveyed employees had received suspicious emails, messages, voice communications or links at work during the previous six months. Phishing remained the most common example, but employees also encountered attempts to steal personal information, passwords, AI-generated scams, malware and ransomware. ENISA
Yet only 45% said their organization regularly sends cybersecurity awareness information or updates.
The interesting part is that employees don’t appear uninterested. Eighty-five percent said they wanted to improve their cybersecurity skills. ENISA
The gap is partly about how training is delivered.
The Biggest Training Problem May Be the Calendar
Among employees who identified obstacles to developing cyber skills, 26% cited finding time during work, ahead of cost at 16%, followed by limited information about training and insufficient employer support. ENISA
That matters because cybersecurity training often competes with everything else people are expected to finish that day.
A better program has to respect that reality.
Useful workforce training can focus on specific decisions employees regularly face:
- Whether an unusual request should be independently verified
- What information is safe to enter into an AI tool
- How to report suspicious activity quickly
- What to do when a familiar login process suddenly behaves differently
- How to handle customer or confidential information outside normal workflows
- When an unusual request from a manager should still trigger a second check
These aren’t abstract cybersecurity concepts. They’re moments that can happen between two ordinary meetings.
Different Jobs Create Different Risks
A finance employee, software developer and communications manager don’t necessarily need identical cybersecurity training.
Finance teams may face payment fraud and impersonation. Developers need secure handling of code, credentials and dependencies. Communications teams can encounter compromised social accounts, fraudulent media requests or suspicious files arriving from external contacts.
The basics overlap, but the scenarios should feel familiar to the learner.
NIST’s FISSEA program takes a similar direction. Its 2026 training forums emphasize employee behaviour and practical learning, including short micro-training modules and methods that move users from passive awareness toward verification habits they can use in real situations. NIST
That’s a more useful objective than asking whether everyone remembers the definition of phishing.
Train the Decision, Not Just the Definition
Cybersecurity readiness improves when employees practise what to do.
Give a finance team a realistic payment-change request. Let employees inspect it, verify it through another channel and decide when to escalate. Give another group an AI tool and several documents with different sensitivity levels, then ask what can safely be uploaded.
The learning becomes a decision rather than a lecture.
For dedicated cyber professionals, the same principle can continue into deeper practical environments. ITSEC Cyber & AI Academy connects cybersecurity and AI learning with hands-on exercises where participants can investigate, test and respond rather than simply consume material.
Most employees already know cybersecurity matters.
The more useful training question is whether they’ll know what to do when something slightly strange appears at 3:47 on a busy afternoon.
Explore practical cybersecurity and AI learning at ITSEC Cyber & AI Academy.
References: ENISA: Cybersecurity Month @ Work, 30 September 2026 · NIST FISSEA Spring Forum 2026 · NIST FISSEA Fall Forum 2026
.png)


