Enterprise security training budgets continue to grow, with AI becoming a key investment direction
Cybersecurity certification body ISC2 released a report on Wednesday stating that as enterprises prepare for the AI era, security training budgets continue to increase. 47% of respondents believe AI is the most essential skill for employees to master, and 73% of enterprises have raised security training investment over the past year. The report also analyzed training delivery models, frequency, effectiveness evaluation methods, and major challenges.

Briefing Overview
- Cybersecurity Certification OrganizationA report released by ISC2 on Wednesdayshows that security leaders are seeing their training budgets increase as organizations prepare employees for the AI era.
- Among respondents surveyed by ISC2, nearly half (47%) said their companies consider AI the most important skill employeesneed to learn。
- The report also delves into how organizations are adjusting training programs to fit the modern security landscape and how they are addressing the challenges they face.
Deep Insights
As cybersecurity risks grow increasingly complex, companies are investing more in their employees to combat phishing, ransomware, and other threats. About three-quarters (73%) of respondents said their organizations increased security training budgets over the past year. In terms of training delivery, 20% of organizations rely entirely on internal staff to provide training materials, 43% rely primarily on internal staff but also use third-party vendors, and another 27% split training work evenly between internal staff and third parties.
Larger organizations are more likely to use third-party training companies, which may be related to the costs associated with these services.
In terms of training frequency, monthly training is the most favored approach for keeping security personnel up to date on the latest threats and tactics, with 36% of respondents indicating they use this method. 34% of respondents said they train their security teams quarterly, while 15% train weekly.
Companies use a variety of tools to measure the effectiveness of theircybersecurity training programs. The most commonly used tools are employee performance metrics and trends in reduced security incidents—each cited by 52% of respondents. A similar proportion of security leaders told ISC2 they rely on employee satisfaction surveys, audit results, and employee certification completion rates.
Security leaders believe time constraints are the biggest obstacle to improving training program effectiveness, with more than half (53%) of respondents viewing it as a burden. Keeping training materials up to date and finding qualified trainers round out the top three training challenges.
Nearly all respondents said they closely monitor the latest technology trends and quickly incorporate them into training programs. 40% of respondents said they update training materials before trends become widespread; 54% said they update materials as soon as trends emerge. Only 5% of respondents admitted to being "slightly behind" trends, and just 1% said they are "significantly behind."