Join our Newsletter — 33% off our NHI Course
Home FAQ Cyber Security What do teams get wrong about using training…
Cyber Security

What do teams get wrong about using training exercises to improve cybersecurity awareness?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 20, 2026 Domain: Cyber Security

Teams often treat awareness training as passive education instead of an active test of decision making under pressure. The stronger approach is to use scenarios, simulations, and technical exercises that reveal how people actually respond to phishing, stolen credentials, and exposed vulnerabilities. That makes gaps visible in a way classroom content cannot, and it helps security leaders target the behaviors that most affect real-world risk.

What Training Exercises Expose That Slides Never Will

Awareness work fails when it only checks whether people recognise a topic, rather than whether they can make a sound decision in context. Exercises force the real judgement call: whether to click, verify, escalate, isolate, or ignore. That matters because teams usually do not fail from ignorance alone, they fail when pressure, ambiguity, and time constraints change how they respond.

The best exercises therefore measure behaviour, not recall. A phishing simulation, for example, is only useful if it tests whether users report quickly, whether suspicious links are handled consistently, and whether security staff see the signal in time to act. The same logic applies to stolen credential scenarios and exposure of known vulnerabilities, where the important question is how people respond once the issue is operationally real.

Good programmes also connect the exercise to the real control path. A scenario that ends with a training score but no review of reporting, triage, containment, or access revocation gives a false sense of progress. The point is to identify where the process breaks, not just who answered incorrectly.

How Teams Misread the Value of Simulations

One common mistake is using exercises as punishment or as proof that users are the weakest link. That framing narrows the learning value and usually encourages shallow compliance rather than better judgement. A better interpretation is that the exercise reveals how the organisation actually behaves when an alert, lure, or compromise path appears.

Another mistake is treating a single success metric, such as click rate, as the whole story. A low click rate can still coexist with poor reporting discipline, weak escalation, or delayed containment. Conversely, a higher click rate may be less important than whether users self-reported quickly enough to limit damage. That is why scenario design should include the full lifecycle of response, from first contact to escalation and remediation.

Training also loses value when it is too generic. Teams need scenarios that reflect their actual exposure, such as phishable business workflows, exposed services, admin credentials, or vulnerable systems that are already part of daily operations. The closer the exercise is to the environment, the more useful the findings are for security prioritisation.

Risk and Threat Considerations

Weak awareness exercises create a measurement problem: leaders may think behaviour has improved when only classroom familiarity has improved. The practical risk is that phishing, credential abuse, and vulnerability exploitation still succeed because the organisation has not tested recognition, escalation, or containment under realistic conditions.

Failure mechanism: Exercises that stop at education do not reveal whether staff can detect a lure, report it promptly, or take the right next step when the issue is urgent. That leaves gaps in the human-to-process handoff, which is where many real incidents expand.

Impact: If the team has not rehearsed actual decision making, attackers can gain more time to use stolen credentials, exploit exposed weaknesses, or move before defenders respond. The result is often slower containment, broader blast radius, and weaker confidence in the control environment.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK address the attack and risk surface, while CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
CIS Controls v814.4 — Security Awareness and Skills TrainingExercises turn awareness into practiced decision-making under realistic attack conditions.
17.1 — Security Operations Center (SOC) and Incident Response ProcessExercises should test the handoff from user recognition to operational response.
Recommendation — Run scenario-based training that verifies reporting, escalation, and response behaviors, not just content completion. Rehearse the reporting and triage path so human detections reach incident response quickly.
NIST CSF 2.0GV.OC-02 — Cybersecurity Strategy and Risk Management StrategyTraining exercises should be tied to the real risks the organization is trying to reduce.
DE.CM-01 — Networks and Systems MonitoredExercises should validate whether suspicious activity is detected and surfaced in time.
RS.CO-02 — CommunicationsAwareness exercises often fail at the reporting and escalation step rather than first recognition.
Recommendation — Align simulations to the highest-risk user behaviors and attack paths in your environment. Use simulations to test whether monitoring and human reporting create timely detection signals. Practice the communication chain from user report to security triage and containment.
MITRE ATT&CKT1566 — PhishingPhishing simulations directly exercise a common initial access technique.
T1078 — Valid AccountsExercises about stolen credentials map to attacker use of compromised logins.
T1190 — Exploit Public-Facing ApplicationScenarios involving exposed vulnerabilities should test how teams react to exploitable services.
Recommendation — Use phishing scenarios to measure reporting speed and follow-on response, not just click rates. Test how quickly teams detect and contain suspicious use of valid accounts. Simulate exposure of a reachable vulnerability and verify containment and remediation speed.

Practitioner Guidance

What to prioritise: Design exercises around the decision you most need people to make correctly, not around the message you want them to remember. If your biggest loss comes from phishing, credential theft, or delayed patching, test reporting speed, escalation quality, and the quality of the handoff to response teams.

What to verify: Look for evidence that the exercise produced an operational improvement, such as faster reporting, clearer triage, or fewer ambiguous handoffs on repeat scenarios. If the only outcome is a training completion count, the programme is probably measuring attendance rather than resilience.

Practitioner takeaway: The most useful awareness exercises expose whether the organisation can make and execute the right decision under pressure, because that is where real-world exposure is either reduced or allowed to grow.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 20, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org