Targeted Training Programs May Effectively Prevent the Next Data Breach
Recent research shows that approximately 66% of cyber intrusions stem from employee negligence or misconduct. Faced with increasingly sophisticated attack methods, companies urgently need to make employee training a core part of their security strategy. Drawing on industry expert insights, this article proposes a three-step strategy from awareness enhancement, continuous training, to simulated exercises, and emphasizes that training must align with corporate culture and adopt a top-down approach to build a truly effective 'human firewall'.

When high-profile hacker attacks dominate headlines, you may worry about whether your company's defenses are strong enough. However, the biggest threat to information security may come from internal employees.
According toa recent report by Willis Towers Watson, about 66% of network intrusions are caused by employee negligence or misconduct; external threats account for only 18%, and ransomware accounts for 2%. If employees are allowed to use personal devices for work, the risk will further increase.
This is where the Learning and Development (L&D) department comes into play. Employee training should be the first line of defense—employees need to know what to watch out for, what to avoid, and how to report to the IT department.
Internal risks: old tricks are making a comeback
Training may need to "go retro." As hacker tactics evolve, many classic attack methods are resurging. In 2017,a Cisco reportpointed out that the activity of traditional attack vectors such as email, spam, and adware has rebounded to its highest level since 2010. Spam accounts for 65% of all email, with about 8% to 10% being malicious. Any employee can become an entry point for attacks.
Another risk path is employees saving data to third-party cloud applications. Employees may only be doing so for remote work or file sharing, but Cisco says more than a quarter of such websites are "high-risk" and should raise security concerns.
Even the use of USB drives is not recommended. Flash drives can not only spread viruses but are also prone to being lost. Last year, on the streets of London,a USB drive was foundcontaining sensitive security data from Heathrow Airport, including the route of Queen Elizabeth II to the airport.
Bring Your Own Device (BYOD) risks
Most employers should not assume that employees will consciously follow basic security norms. Withnearly 60% of employersimplementing "Bring Your Own Device" (BYOD) policies and 28% of Americans not setting phone passwords, training is especially critical.
Although many employershave set requirements for passwords and Wi-Fiand can enforce them on company devices, in a BYOD environment, training may be the best line of defense.
Awareness, training, and testing
Training begins with raising awareness. A recent MediaPRO survey shows that70% of employees lack cybersecurity awareness. "Understanding where your company's risks lie is the first step in developing a training program," said Tom Pendergast, chief strategy officer at the company. He told HR Dive via email that L&D professionals should first assess employee knowledge levels and use that as a baseline to develop a training roadmap tailored to both company and individual needs.
Pendergast recommends a three-pronged strategy of "awareness, training, and accountability." "Effective training only happens when employees are both aware of the consequences their actions can have on the company and are willing to take responsibility for reducing risk in their daily work." He believes that a culture of risk awareness is not built overnight but is gradually formed through continuous training, reinforcement, and accountability, making employees the first line of defense against cybercriminals.
Training cannot be a one-time event, emphasized Erich Kron, security awareness advocate at KnowBe4: "Training must be ongoing, not just once a year. This helps employees keep security top of mind in their daily work." He told HR Dive via email.
Giving employees the opportunity to test what they have learned is equally important. KnowBe4 conducts a monthly simulatedphishing attackdrill to keep employees alert. While testing can reinforce learning, Kron cautions against shaming employees for failing. "The goal is to change behavior by challenging existing habits. Expect people to make mistakes," he said, "but supporting them even when they err helps build confidence and improve skills."
Building a "human firewall"
Like other training, cybersecurity training needs to fit the corporate culture. Brian A. Engle, founder and CEO of Riskceptional Strategies, told HR Dive via email that creating and delivering internal training content in the company's own terms and cultural tone ensures the desired results.
A good security awareness program should be like excellent advertising.
Engle recommends a top-down approach, including involving key personnel in tabletop cybersecurity exercises. He says not everyone needs to participate, but having senior leaders involved in communication, escalation, and response scenarios demonstrates organizational readiness and clarifies leadership roles in response.
Training also needs to be proactive and forward-looking. Kevin Gumienny, senior learning architect at Microassist, said: "Defining what employees need to do (rather than what they need to know) helps keep training focused, concise, and on point." He noted via email.
Similarly, as threats evolve, training should be updated accordingly. "Cybersecurity skills need regular practice to stay sharp," Gumienny said. To help employees remember what they have learned, short, frequent, regular training sessions aid memory retention. "Combining testing with spaced learning is a great way to ensure training effectiveness."
"A good security awareness program should be like excellent advertising," Pendergast said. "Think of it as influencing employee behavior." For L&D professionals, initial awareness and training are just the beginning. Delivering consistent messages repeatedly through multiple channels can keep cybersecurity top of mind and reinforce knowledge. This level of awareness may be the dividing line between data security and an unrecoverable breach.