How Often Should You Train? What Memory Research Says
Annual training fades within months. What memory research says about security training frequency, and how to build a cadence that keeps skills alive.

Ask ten organizations how often they run security awareness training and most will give the same answer: once a year. Ask why, and the honest answer is rarely about risk — it is the audit calendar. Annual training is what the checklist asks for, so annual training is what the workforce gets.
The problem is that human memory does not operate on fiscal years. With the Verizon DBIR attributing 62% of breaches to the human element, the interval between training sessions is not an administrative detail — it determines how much of the year your workforce spends effectively untrained. And unlike most questions in security awareness, this one has real research behind it: a century of memory science, plus a growing set of security-specific studies that measured exactly how fast phishing-detection skill decays. This article walks through that evidence and turns it into a cadence you can actually run.
A century of forgetting, replicated
In 1885, Hermann Ebbinghaus measured how quickly he forgot what he had memorized, and drew the curve that still carries his name: retention drops steeply in the first hours and days after learning, then levels off. The finding is not folklore — a 2015 replication by Murre and Dros, published in PLOS ONE, reproduced the original forgetting curve with remarkable fidelity: the steepest losses came within the first day, with most of the forgetting complete inside a week.
Two implications follow directly. First, a single training event — however good — is a wasting asset from the moment it ends. Second, the shape of the curve matters as much as its speed: because decay is steepest early and flattens later, well-timed reviews do disproportionate work. Each refresh slows the next round of forgetting, which is the entire premise of spaced repetition.
What the security-specific evidence shows
Generic memory research would be enough to doubt the annual model. But phishing detection has been studied directly, and the results line up.
| Study | What it measured | What it found |
|---|---|---|
| Reinheimer et al., SOUPS 2020 | Phishing-detection ability (d′) over 12 months after interactive training | Detection jumped from 1.11 to 2.13 immediately after training; still significantly elevated at 4 months; no longer statistically significant at 6 months |
| Ho et al., IEEE S&P 2025 (UCSD Health, ~19,500 employees, 8 months) | Annual compliance training vs. real simulation failures | No significant relationship between training recency and failure rate; embedded post-click training moved failure by only ~2 percentage points; 75% of employees closed the training page within a minute |
| KnowBe4 2026 Phishing by Industry benchmark | Phish-prone percentage under continuous simulation + training | Baseline 33.2% → 20.1% after 90 days → 4.2% after 12 months of sustained monthly-cadence programs |
Read together, the three studies triangulate the same conclusion from different directions. The lab study says skill exists but decays on a four-to-six-month half-life. The field study says the annual, low-engagement format delivers approximately nothing. The vendor benchmark — vendor data, so treat the exact figures as a band — says the one format that reliably bends the curve is the one that never stops: simulation and short training repeated across the whole year.
Notice what none of the evidence says: it does not say training fails. It says training on an annual interval fails, for the same reason a gym membership used every January fails. The intervention works; the schedule wastes it.
The calendar is the wrong trigger for training. Memory decays on its own schedule, and risk arrives on the attacker's — a defensible cadence follows those two clocks, not the audit cycle.
Why shorter and more often beats longer and rarer
If decay is the disease, distribution is the treatment. The spacing effect — the finding that material reviewed across spaced intervals is retained far better than the same material massed into one session — is among the most replicated results in cognitive psychology; Cepeda, Pashler, Vul, Wixted and Rohrer's quantitative synthesis of more than a century of verbal-recall experiments found spaced practice consistently outperforming massed practice across hundreds of comparisons.
For a security program, that means the sixty minutes you currently spend once a year is worth more cut into pieces. Six ten-minute microlearning sessions spread across the year cost the same seat time as the annual course, but each one lands inside the retention window the previous one opened. And the Ho et al. attention data — three-quarters of employees dismissing training inside a minute — argues the pieces should be small even if the budget allows more: a module employees finish beats a module employees close.
There is a second, less obvious benefit. Frequent short touchpoints turn training from an event into an ambient property of the culture — the thing that happens here monthly, not the thing that happens to you in Q4. That is the same mechanism that makes phishing simulations effective as retrieval practice: each simulated lure forces the recognition skill out of storage, which is precisely what interrupts the forgetting curve.
Compliance sets the floor, not the cadence
None of this conflicts with your obligations — the frameworks define minimums, not designs. PCI DSS v4.0.1 requires awareness training upon hire and at least once every 12 months. HIPAA requires it within a reasonable period after someone joins the workforce. NIS2 makes training mandatory for management bodies and says employees should be trained on a regular basis, and DORA makes ICT security awareness a compulsory module in staff training schemes. NIST SP 800-50r1 goes furthest, reframing awareness as a continuously managed learning program with measured outcomes rather than a scheduled event.
Treat the annual course as the floor it is: it satisfies the auditor and catches the long tail of policy content that genuinely only needs yearly coverage. Just do not confuse it with the part of the program that changes behavior — the ROI evidence is blunt about which formats pay for themselves.
How to design a cadence that survives contact with memory
1. Baseline before you schedule anything. Run an unannounced simulation and score where risk actually sits — by department, role and behavior, not just org-wide click rate. A human risk score gives you the per-group baseline that the rest of the cadence adjusts against.
2. Redistribute the hour. Replace the single annual block with a short monthly session — five to ten minutes, one topic, one behavior. Same annual seat time, radically different retention profile.
3. Refresh detection skills before month four. The SOUPS 2020 curve is your service interval: detection ability was still elevated at four months and statistically gone by six. Any group that has gone a quarter without touching phishing recognition — through a module or a simulation — is overdue.
4. Let failures trigger training, not just the calendar. Just-in-time training delivered at the moment someone clicks a simulated lure ties the lesson to a live memory of the mistake. Keep it under a minute of genuinely specific content — the Ho et al. data shows anything longer gets closed, not read.
5. Tier frequency by role and risk. Finance, executive assistants, help desk and IT admins face more targeted attacks and warrant a denser schedule; low-exposure roles can run leaner. New hires need the most compressed cadence of all — susceptibility is front-loaded in the first months, which is why onboarding deserves its own design.
6. Measure decay, not completion. Completion rates measure administration. Track simulation failure and report rates between training touches: if a cohort's performance sags before its next scheduled session, shorten its interval; if it holds, lengthen it. The right frequency is not a constant — it is the output of measurement.
The short answer
If you need a number: a short session monthly, a detection refresh at least every four months, event-driven training within minutes of a failure, and the annual course kept for the auditor. That cadence is not more expensive than the annual model — it is mostly the same hours, placed where memory research says they compound instead of evaporating.
Frequently asked questions
How often should security awareness training happen?
The longitudinal evidence points to a refresh interval of no more than four months for detection skills: in the SOUPS 2020 study, phishing-detection ability was still significantly improved four months after training but statistically indistinguishable from baseline at six. In practice, mature programs run a short monthly micro-session as the default rhythm, add event-driven training when someone fails a simulation, and treat the annual course as a compliance floor rather than the program.
Why does annual training alone fail?
Two reasons: memory and format. Memory research going back to Ebbinghaus shows that most forgetting happens quickly after learning, so a single yearly event leaves the workforce near baseline for most of the year. Format compounds it: an eight-month study of about 19,500 employees published at IEEE S&P 2025 found no significant relationship between recently completing annual compliance training and resisting a simulated phish — and roughly 75% of employees closed the embedded training page within a minute.
What do regulations actually require for training frequency?
Most frameworks set a floor of once a year plus at onboarding. PCI DSS v4.0.1 requires awareness training upon hire and at least once every 12 months; HIPAA requires training within a reasonable period after joining; NIS2 requires mandatory training for management bodies and encourages regular training for employees; DORA makes ICT security awareness a compulsory module in staff training schemes. None of these caps frequency — they are minimums, and the evidence says minimums do not change behavior.
Is more frequent training always better?
No. Attention is the binding constraint: the same IEEE S&P 2025 study found most employees spent under a minute on training pages, so adding more long modules mostly adds skipping. The evidence favors redistributing time rather than adding it — short, spaced, varied sessions beat both a single annual block and a heavy monthly course. If sessions start getting closed instantly or simulation report rates stall, the cadence is too dense or the content too repetitive.
NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.
Book a demo