Teams should use performance data, not guesswork. Users who complete foundational training, avoid repeated risky behavior in simulations, and show strong knowledge in assessments may need less frequent training. Users who fail assessments or are repeatedly targeted should receive more focused learning. This approach preserves time while keeping training aligned to actual need.
How to decide who needs more training
The practical test is whether the data shows a gap that training can close. If people keep missing the same concepts, fail assessments, or repeat unsafe choices in simulations, they have earned more focused learning. If they already demonstrate stable performance, the better move is usually lighter refreshers instead of repeating the same material.
That means the decision should be tied to observed behavior, not role seniority, manager preference, or a fixed annual schedule. The teams that get this right use assessment results, simulation outcomes, and trend data together so training intensity reflects actual need.
It also helps to separate broad awareness from targeted remediation. Someone may not need the full course again, but they may still need a short module on the specific control or habit they keep missing, especially if the issue shows up in repeated phishing tests, policy violations, or low assessment scores.
When can someone safely test out?
Testing out should be allowed only when there is enough evidence that the person already understands the material and can apply it under realistic conditions. A single good quiz score is usually not enough on its own. Strong candidates for testing out have completed foundational training, passed knowledge checks, and shown consistent good judgment in simulations or day-to-day behavior.
The safest approach is to define clear thresholds in advance. For example, a team might require a passing score on the assessment, no recent repeat failures in simulations, and no open concerns from supervisors or security reviewers. When those conditions are met, testing out becomes a controlled shortcut, not an exception based on convenience.
Teams should also review whether the content being skipped is still relevant to the person’s current exposure. If the user’s tools, permissions, or workflows have changed, the earlier result may no longer be a reliable sign that they can skip training. Competence is role-specific and time-sensitive, so recertification matters when the environment changes.
What data should drive the decision?
The best input set is simple: assessment results, simulation performance, completion records, and repeat-offense history. Together, these show whether the person learned the material, retained it, and can apply it when it matters. If you only look at training completion, you may reward attendance instead of understanding.
Performance data should also be grouped by risk pattern. Some users may need more training because they miss one specific topic repeatedly, while others may need a broader refresher because they struggle across several topics. That distinction matters because the second group usually needs a deeper intervention, not another reminder on the same narrow issue.
When available, add a review step for outliers, such as people who test out but later show poor simulation results, or people who fail assessments despite repeated training. Those cases often reveal either a content problem, a role mismatch, or a process issue in the training program itself. SANS Security Resources offers practitioner material that can help teams benchmark how they structure awareness, detection, and response learning.
Practitioner Guidance
What to verify: Use a consistent rule set before granting a test-out. Verify that the learner has both recent assessment success and no repeated risky behavior in simulations; otherwise, the result may reflect familiarity with the test rather than real readiness.
Decision rule: If the user has strong scores and stable simulation performance, reduce training frequency and move to lighter refreshers. If the user misses the same control twice or shows repeated risky behavior, assign focused remediation on that specific weakness instead of repeating the full program.
What good looks like: The program should produce fewer unnecessary refreshers, faster remediation for weak performers, and clearer evidence that training intensity is matched to actual behavior. That is the signal that the process is measuring competence rather than simply counting completions.
Practitioner takeaway: The goal is not to treat everyone the same, but to use evidence to place each person at the right training level and recheck that decision whenever their performance or exposure changes.