Source URL: rmalberta.com/news/from-compliance-to-culture-why-cybersecurity-awareness-training-matters/

From Compliance to Culture: Why Cybersecurity Awareness Training Matters

Published: October 28, 2025 | Version: 2.0 | Last updated: October 6, 2026

Author: Canadian Internet Registration Authority (CIRA)

Applies to: Organizations responsible for employee cybersecurity awareness training

Purpose: This bulletin explains why regular cybersecurity awareness training matters and how training frequency affects an organization’s ability to defend against cyber threats

Each year, CIRA surveys Canadian cybersecurity decision makers about their views and experiences across all stages of a cyber incident, from risk assessments to resources, preparedness, and recovery. This article draws on findings from the 2025 CIRA Cybersecurity Survey.

Training is everyone’s responsibility

Cybersecurity training is one of the strongest tools organizations have to defend against modern cyber threats, but it is too often treated as one-and-done exercise.

It starts with a single click. A distracted employee, rushing to clear their inbox before the end of the day, opens what looks like a routine invoice. Within minutes, attackers are inside the network. This scenario plays out in organizations across Canada every day.

Herbert A. Simon, a Nobel Prize-winning social scientist, argued that organizational effectiveness depends less on the brilliance of individuals and more on the structured coordination of many rules, routines, and communication systems. This insight explains why cybersecurity training must go beyond IT departments and become a regular, organization-wide practice.

According to the 2025 CIRA Cybersecurity Survey, 98 per cent of Canadian organizations provide some form of cybersecurity awareness training. That is a strong foundation, but training frequency has not kept pace with current threats.

Most organizations are training employees at the same rate they did three years ago, despite rising threats. Among organizations that offer training, 29 per cent do so annually or less, 57 per cent quarterly, and only 14 per cent monthly. These figures are virtually unchanged since 2022.

Human error remains one of the biggest security risks. Rising threats demand more training.

Don’t forget the forgetting curve

Why is training better? For one thing, a large body of research shows that people quickly forget what they have learned when they do not make a conscious effort to retain it. The forgetting curve shows that people forget 50 per cent of new information within an hour, 70 per cent within 24 hours, and up to 90 per cent after a week. This is how critical training lapses happen. Employees do care, but information fades over time.

Not surprisingly, more frequent training improves retention. A 2023 study found that employees who received weekly phishing simulations were 2.74 times more effective at reducing phishing risk than those trained quarterly.

No matter how informative, engaging, and useful a training session is, employees’ ability to remember what they have learned and apply it every day depends on repetition and reinforcement.

Stay ahead of the rapid pace of change

The fallibility of memory is only part of the challenge. The speed at which cybersecurity threats are changing, especially as generative AI adoption accelerates, is another key factor. This year’s survey found that 42 per cent of organizations experienced a breach of customer or employee data in the past 12 months, up from 29 per cent in 2022. Even experienced cybersecurity professionals are struggling to keep up, let alone non-experts. Generative AI-enabled attacks are more scalable, personalized, adaptive, and convincing, which raises the bar for defenders.

Organizations that increase the frequency and quality of their cybersecurity training are better positioned to keep pace with these threats. While too much training can overburden employees, even a slight increase in frequency, especially among high-risk groups, can be a cost-effective way to reduce risk in any organization.

Summary

When a single click can compromise an entire organization, frequent, high-quality cybersecurity training is one of the most effective defences available.

Learn how CIRA cybersecurity awareness training can help your organization improve its security posture.

References

Questions?

RMA Insurance members can access CIRA’s cybersecurity awareness training through our value-added risk services. To get started, contact your Risk Advisor or the Risk Team at risk@rmainsurance.com.

This bulletin is provided by RMA Insurance for general information only and includes content originally published by CIRA. It is based on our understanding of current law and practice as of the date of publication and does not constitute legal, technical, cybersecurity, or other professional advice, or an interpretation of any insurance policy. Coverage is governed solely by the terms of your policy. Organizations remain responsible for complying with their own legal obligations, and any use of this information is at the reader’s discretion. For advice on your specific situation, contact your RMA Risk Advisor or legal counsel.