The email arrived on a Tuesday morning. It looked exactly like a Microsoft Teams notification—logo, formatting, the familiar blue accent. The accounts payable clerk clicked through, entered her credentials on what appeared to be the standard Microsoft login page, and went back to her coffee.
Forty-eight hours later, the company discovered that €340,000 had been redirected to an account in Eastern Europe.
She had completed her annual security awareness training three months earlier. She passed the quiz with 85%.
The Compliance Checkbox
Most organisations approach security awareness training the same way: once a year, a video, a quiz, a signature. The compliance box is ticked. The auditor is satisfied. Everyone goes back to work.
Meanwhile, 68% of breaches still involve a human element, according to Verizon’s 2024 Data Breach Investigations Report. IBM puts the average cost of a data breach at $4.88 million. The gap between what organisations are doing and what’s actually needed isn’t a crack—it’s a chasm.
The uncomfortable truth is that your annual training programme isn’t designed to change behaviour. It’s designed to prove you tried. And attackers—who evolve their techniques weekly, not annually—are counting on exactly that.
Why Traditional Training Fails
A 45-minute video followed by a 20-question quiz tests one thing: short-term memory. It doesn’t test whether your finance team can spot a Business Email Compromise at 4:30 PM on a Friday. It doesn’t prepare your vessel crew for a USB-based attack in a foreign port. It doesn’t teach your IT administrators that their privileged access makes them high-value targets.
Traditional training fails because it treats security awareness as an event rather than a process. Consider how it typically works:
- Generic content: The same video for the CEO and the junior developer. Different roles face different threats, but the training doesn’t reflect this.
- No reinforcement: One exposure per year. Forgetting curves are brutal—within a month, most people retain less than 20% of what they watched.
- No measurement: A quiz score isn’t a risk metric. It tells you nothing about whether behaviour actually changed.
- No accountability: If someone fails, they retake the same quiz. There’s no escalation path, no targeted remediation, no manager visibility.
The result? A workforce that can pass a compliance quiz but can’t recognise a spear-phishing email that uses their own company’s language and branding.
The Regulatory Landscape Has Changed
Regulators have noticed the gap. The era of “any training will do” is ending.
ISO 27001:2022 now explicitly requires security awareness programmes that are role-appropriate, regularly updated, and measurably effective. It’s not enough to show you have a training programme—you must demonstrate it works.
NIS2, which applies to essential and important entities across the EU, mandates that management bodies approve and oversee cybersecurity training measures. Article 20 requires “regular training”—not annual, regular. Member states are interpreting this as quarterly at minimum.
For maritime organisations, IMO MSC-FAL.1/Circ.3 guidelines on maritime cyber risk management require that personnel at all levels are trained on their cyber security responsibilities. Port State inspections increasingly ask for evidence of crew-specific training, not just a generic certificate.
GDPR Article 39(1)(b) requires that staff involved in processing operations receive appropriate data protection training. Supervisory authorities have cited inadequate staff training as a contributing factor in enforcement actions worth hundreds of millions.
The common thread: regulators want evidence of continuous, role-based, measurable training. A PDF certificate from an annual video doesn’t cut it anymore.
What Effective Security Awareness Actually Looks Like
If traditional training is a lecture, effective training is a curriculum. The difference isn’t just frequency—it’s architecture.
Role-based paths. A vessel crew member faces different threats than a shore-based finance officer. Training content should reflect actual risk profiles, not organisational hierarchy. Shore staff need to understand BEC and social engineering. Vessel crew need to understand removable media risks and physical access threats. IT staff need to understand privilege escalation and lateral movement.
Continuous delivery. Short, focused modules delivered regularly outperform annual marathons. The goal is sustained awareness, not a compliance sprint. Monthly modules of 10–15 minutes each produce better retention than a single two-hour session.
Assessment with teeth. Randomised question pools prevent answer-sharing. Configurable pass thresholds ensure actual comprehension. Retake cooldown periods prevent brute-force completion. Difficulty levels allow progression from foundational to advanced topics.
Policy integration. Training alone isn’t enough if employees haven’t read and acknowledged the policies they’re expected to follow. Linking training modules to specific policies—acceptable use, incident reporting, data handling—creates a closed loop between knowledge and obligation.
Audit-ready reporting. When the auditor asks “how do you know your training is effective?”, you need more than attendance records. Completion rates by department, quiz score distributions, overdue training alerts, and compliance coverage by framework—these are the metrics that demonstrate a mature programme.
The Maritime Dimension
Maritime organisations face a unique challenge. Shore staff operate in connected office environments where updates can be pushed instantly. Vessel crew operate in bandwidth-constrained, sometimes air-gapped environments where a browser-based training platform may not be practical.
Add to this the multilingual nature of maritime crews, the high turnover rates, and the increasingly stringent requirements from flag states and classification societies, and you have a training problem that generic corporate platforms weren’t designed to solve.
Effective maritime security awareness training must account for these realities: offline capability, multilingual content, vessel-specific threat scenarios, and compliance mapping to maritime-specific frameworks alongside ISO 27001 and NIS2.
From Checkbox to Culture
The real goal isn’t compliance. It’s culture change. You want employees who pause before clicking, who report suspicious emails instead of deleting them, who understand that security is everyone’s responsibility—not just IT’s problem.
This doesn’t happen with a single training event. It happens when security awareness becomes part of the operational fabric: regular training, policy acknowledgements, visible metrics, management engagement, and consequences for non-completion.
It’s also why we developed CSAWTP—our Cyber Security Awareness Training Platform—in partnership with Margetis Maritime. We kept encountering the same gap in the organisations we advise: compliance frameworks that demand continuous, role-based, measurable training, and a market full of platforms that deliver a video and a quiz. CSAWTP maps 27 training modules to 56 compliance clauses across ISO 27001, NIS2, GDPR, and IMO frameworks, with nine role-based training paths and automated certification. It was designed for organisations—particularly in maritime and regulated industries—where a generic solution creates more risk than it mitigates.
The question isn’t whether you can afford a proper security awareness programme. It’s whether you can afford the breach that happens without one.
Need help assessing your organisation’s security awareness maturity? Let’s talk.