Security Awareness Training
July 20, 2026

What Spaced Repetition Research Says About Why Annual Training Doesn't Stick

What Spaced Repetition Research Says About Why Annual Training Doesn't Stick
# Security Awareness Training

Borrowed, Part 2: what memory research can teach security awareness about training cadence

Ant Davis
Ant Davis
What Spaced Repetition Research Says About Why Annual Training Doesn't Stick
Part  one  of this series looked at what product design gets right that phishing reporting gets wrong. This one looks at memory itself, and what a century of research into forgetting says about why annual training was never built to work.
Annual security training runs on an assumption nobody says out loud: that one session, once a year, is enough to change behaviour for the following 365 days. Memory research has spent well over a century disproving that assumption, and the numbers involved should worry anyone still building a programme around a single yearly module.

The forgetting curve, briefly

German psychologist Hermann Ebbinghaus ran the original experiments on memory decay back in 1885, testing himself repeatedly on nonsense syllables and recording how much he retained over time. He found that people forget roughly half of new information within about an hour, and something in the region of 70% within 24 hours. When people have replicated these experiments, the percentages have shifted slightly and it does depend on the material being learned, but the shape of the curve, a steep initial drop that gradually flattens, has held up consistently since, including in a 2015 replication study.
The curve isn't a straight line down. Forgetting slows the more it's reviewed, which is why spaced repetition and active recall exist as deliberate methods to flatten the memory decline and extend knowledge retention. Each properly timed review makes the next bit of forgetting slower.

Spacing beats cramming, reliably

This isn't a single study or a hunch. A meta-analysis by Cepeda and colleagues, published in 2006, pulled together 184 separate articles covering 317 experiments on distributed practice. The consistent finding: spacing learning out over time, distributed practice, produced better retention than massed practice, the term for cramming everything into one session. That advantage stuck regardless of the subject matter or age group of those taking part. This isn't a marginal effect. It's the difference between remembering something and not remembering it at all.
Annual training is massed practice by definition. One module, one sitting, then silence for twelve months. It's the training equivalent of cramming the night before an exam and hoping the knowledge survives long enough to be useful when it actually matters, which in this case means the moment someone opens a suspicious email in month seven or receives a dodgy phone call in month four.

Why one session a year was never going to work

Put the two findings together and the problem is obvious. Most of what's learned in a session is gone within a day without reinforcement, and it's in fact reinforcement spaced over time that actually protects retention. An annual security training module gives people exactly one exposure and then nothing until the next one. By the time the training would actually be tested, in a live phishing attempt or a judgement call about sharing a file, the security learnings have long since faded and all that's left is a vague sense of having done training at some point, not a new set of secure habits.
This also explains why so many awareness programmes feel like they're constantly starting from zero. Because they are. If nothing reinforces the learning between sessions, each annual module isn't building on the last one. It's replacing a memory that's already gone. Filling a void that will soon be a void once again.

Isn't quarterly enough?

A common fix is to move from annual to quarterly. It's an improvement, but it doesn't solve the underlying problem, it just shrinks it.
Four sessions a year is still massed practice, just four separate times. Retention still decays sharply in the weeks after each session, and by the time the next quarterly module arrives, most of the specific detail from the last one is already gone. The gap is smaller than a full year, so the decline is less severe, but the mechanism causing the problem hasn't changed. What made spacing effective in the research wasn't simply "more frequent big sessions." It was short, repeated exposure with retrieval built in between, at increasing intervals, reinforcing one thing at a time. Retrieval means being made to recall or apply something yourself, rather than just being shown it again. Seeing a fact twice and being asked to remember it are different exercises, and the research is clear that the second one is what actually holds.
Quarterly training without anything in between the quarters is a smaller version of the same mistake, not a different model. The fix isn't a shorter gap between big sessions, it's smaller reinforcements filling the gap that's already there.

What annual training is actually for

There's an honest case worth making here. Annual training was probably never going to be the vehicle for behaviour change, and treating it as though it should be sets it up to fail. Its more realistic job is compliance, ticking the regulatory or audit box that says training happened, and brand. It's one of the only moments in the year the whole organisation hears from the security team directly, a chance to put a face and a tone to a function most people otherwise only encounter when something's gone wrong.
The real behaviour change, the bit spacing research is actually about, happens in the gaps. Between the annual session and the next one, or between quarterly sessions if that's the cadence. That's where the short, retrieval-based reinforcement earns its keep, not in the big session itself.
Given that, I'd rather treat the annual module as a minimum viable product. As short as it can possibly be while still doing its compliance and brand job, something people can get through, take one thing from, and actually thank you for, rather than a dense hour they resent sitting through and forget by lunchtime. If it isn't carrying the behaviour change anyway, there's no reason to make it long.
It's worth asking honestly, how frequently do your colleagues hear from you outside of the demand for annual or quarterly training? If the answer is only then, the big session is carrying weight it was never built for, and the silence in between it is the real problem.

What reinforcement actually looks like

None of this means scrapping structured training and running on drip-fed content alone. It means treating the annual security awareness session as one input into a longer cycle, not the whole cycle.
A workable cadence doesn't need to be complicated:
  • A short, specific reinforcement at increasing intervals after the annual (or quarterly) security awareness session, for example a few days later, then a couple of weeks later, then a month out
  • Reinforcement through retrieval rather than repetition of the same material. Asking colleagues to recall or apply something from the last security awareness training works better than just showing it to them again
  • Reinforcement tied to real events. A live phishing attempt, a near miss, a relevant news story, used as a natural trigger to revisit one specific behaviour from the annual or quarterly training cycle
The content doesn't need to be long. A single behaviour, reinforced briefly and repeatedly, beats an hour-long module delivered once and never touched again.
Picture what that actually looks like in practice -
January - Someone sits through the annual session, where password hygiene gets covered for ninety seconds among a dozen other topics.
March - A real phishing attempt lands across the business, so a two-line message goes out the same afternoon: a screenshot of the actual email, the one giveaway that should have flagged it, and a one-click "would you have spotted this" prompt. Takes fifteen seconds to engage with.
May - A colleague in finance gets caught by a similar attempt and reports it, so a short note goes round crediting the catch and reminding everyone what to look for.
None of these touchpoints are training in the formal sense. Each one asks for a small act of retrieval, tied to something real, months apart. That's the cadence doing the work the annual session alone never could.
Cadence itself has been tested directly, not just inferred from memory research. I've discovered that Hoxhunt's own data on phishing simulation frequency found that quarterly simulations made little measurable difference to behaviour, close enough to running nothing at all. Monthly cadence produced a significant shift. Going faster than monthly produced an even more pronounced change, but only when each touchpoint stayed relevant, rewarding and actionable. Push the frequency up without holding that bar and it stops being reinforcement and starts being noise, which trains people to ignore it rather than act on it.

The metric that matters

Completion rate measures whether people sat through the annual module. It says nothing about whether they remember any of it three months later. If retention is the actual goal, the metric to track is whether a specific behaviour shows up when it counts, not whether a training record shows a tick in a box from February.
The forgetting curve isn't a reason to give up on training. It's the reason a single annual dose was never going to be enough on its own.
ďťż
Coming up in Borrowed, Part 3: what marketing figured out about audience segmentation decades ago, and why finance and engineering are still getting sent the same phishing simulation.
Comments (0)
Popular
avatar
ďťż
Dive in

Related

Content
Phish of the Week 20th of July
By Mette Luntama • Jul 20th, 2026 • Views 9
Content
Phish of the Week 13th of July
By Mette Luntama • Jul 13th, 2026 • Views 15
Content
Recruitment Phishing
By Mette Luntama • Jul 15th, 2026 • Views 39
Content
Why Your Reporting Button Has Bad Conversion
By Ant Davis • Jul 13th, 2026 • Views 63
Content
Phish of the Week 20th of July
By Mette Luntama • Jul 20th, 2026 • Views 9
Content
Recruitment Phishing
By Mette Luntama • Jul 15th, 2026 • Views 39
Content
Why Your Reporting Button Has Bad Conversion
By Ant Davis • Jul 13th, 2026 • Views 63
Content
Phish of the Week 13th of July
By Mette Luntama • Jul 13th, 2026 • Views 15
Privacy Policy
Your Privacy Choices