Security awareness training has to prepare employees for decisions made during ordinary work, often when a request appears routine. A wider mix of channels and impersonation tactics can leave generic training out of step with what employees actually encounter.
The Anti-Phishing Working Group counted 10.1% more phishing attacks in the second quarter of 2026 than in the first. Smishing was up 40%. Wire-transfer business email compromise attacks rose 88%. It also tracked attacks through social platforms and paid advertising.
The same basic tactic may reach an employee by email one day and by text or social media the next. Other types of lures and delivery channels are also on the rise, such as deepfakes in video chats or QR codes in collaboration platforms. Machine learning can help prevent many of these attacks, but ultimately, it all comes down to the “human firewall.” Employees need to know what to expect, and they need to know how to react.
A useful training program should reflect this evolving mix of attack channels and business scenarios. Training simulations should resemble the requests employees are likely to receive, the channels those requests arrive through, and the decisions attackers are trying to influence.
A security awareness training program can start with the organization’s own exposure. Review what employees are reporting and what incident teams are investigating.
Recurring impersonation or payment fraud patterns can then be turned into scenarios that reflect what attackers are actually asking people to do.
Patterns often differ by role. Finance staff may see invoice fraud or payment change requests, while executives and their assistants attract more impersonation attempts. Developers may run into fake repository notices or credential requests. Customer-facing teams can be approached through shared documents and collaboration tools.
Visible clues are still relevant in phishing exercises. Misspelled domains, unexpected links, and unusual sender addresses can all justify a closer look. The more sophisticated and convincing attacks, however, do not provide an obvious visual mistake.
Context often provides a stronger clue. A payment request may come from someone who normally has no role in approvals, or a message may ask for credentials through a channel the company does not use for that purpose. A sudden change to a supplier’s banking details should also prompt verification.
A 2026 FBI warning describes fraudsters impersonating IC3 personnel. Some used AI-generated video and spoofed websites to make the contact look credible. A training exercise could put employees in a similar situation: would they act on the request, or would they insist on verifying it through a channel they already know?
Not every employee needs the same exercise. New hires may benefit from obvious examples at first. Someone who already spots credential phishing consistently can move on to harder impersonation scenarios.
Training difficulty should change as people improve. Someone who keeps missing one attack type may need a short refresher on that problem. Employees who are doing well can be given scenarios with fewer obvious clues and more realistic business context.
Progression does not need to be complicated. Start with clearer signals, then remove some of the obvious clues as an employee becomes more consistent. Later exercises can lean more heavily on business context.
Email is still a common route for social engineering, but employees now make security-sensitive decisions in many other places.
Someone who is cautious with email may drop their guard when a request comes by text or through a collaboration tool. A shared document, QR code, or phone call can create the same kind of pressure. The channel changes, but the employee may still be asked to trust, approve, pay, or sign in.
Training should give employees a familiar response even when the channel changes. An unusual request can be verified through a known contact method. Staff also need a clear reporting route and a sense of which actions deserve extra scrutiny.
Annual sessions still have a place for baseline expectations and compliance. They leave long gaps, however, if the organization is also trying to reinforce how employees respond to changing attacks.
Shorter exercises can fill some of those gaps when they are tied to risks employees are likely to encounter. More frequent does not automatically mean better. If simulations arrive too often or feel detached from real work, employees can start treating them as a trap to outsmart.
Some employees will need more practice than others. New hires and people struggling with a recurring attack type may benefit from closer reinforcement. Experienced staff may see more value from fewer, more challenging exercises.
With the right platform, click rate is easy to track, but it does not say much on its own about why someone failed a simulation or whether behavior is improving. Reporting rate and reporting speed are usually more informative than clicks alone. They show whether employees notice something suspicious and know what to do next. Repeated mistakes point to areas that still need reinforcement.
Simulation difficulty changes how click rates should be read. A lower click rate after an easy simulation may say less than modest improvement on a scenario that closely resembles a recent incident or targets a familiar workflow.
Reporting real phishing attempts is especially valuable because a fast report gives the security team information it can act on. If the same lure continues to dupe other employees, early reporting may help the team investigate and warn others sooner.
Security teams already see material that can keep training grounded in current conditions. Employee reports, help-desk cases, and incident reviews show which attack themes are reaching the workforce and where people are getting caught.
Recurring attack patterns can shape future exercises. If attackers begin impersonating a supplier used by the organization, procurement and finance teams may need additional reinforcement. If fake collaboration invitations are becoming common, an upcoming exercise can use that workflow.
The feedback does not need to be immediate or automated. A regular review of incident patterns can be enough to keep scenarios from drifting too far from current exposure.
The mix of attacks reaching a workforce changes over time. New tools, role changes, and recent incidents can all make older scenarios less useful. During a review, compare the exercises with the requests employees are seeing now. If the two have drifted apart, the training needs updating.
Training is easier to use when it resembles real work. Security teams also get a clearer picture of which employees or attack types still need attention.