Your Team Is Either Your Best Cyber Defense or Your Biggest Liability. Training Decides
Annual training checks a box. It doesn't change behavior. Here's what effective security awareness training actually looks like for West Coast...
8 min read
Nick Stevens : September 2, 2026
Annual training checks a box. It doesn't change behavior. Here's what effective security awareness training actually looks like for West Coast businesses.
TL;DR: Sixty-two percent of breaches involve a human element, according to Verizon's 2026 Data Breach Investigations Report. That number has barely moved in years, not because organizations aren't trying, but because most security training programs aren't actually changing behavior. A one-time annual video doesn't prepare anyone for a well-crafted phishing email at 4:45 on a Friday. The organizations that close the human risk gap treat training as an ongoing program, not a compliance checkbox, and the difference in outcomes is measurable.
Think about the safety demonstration at the beginning of a flight. The flight attendant goes through the whole routine: seatbelts, exits, oxygen masks, seat cushion doubles as a flotation device. Everyone on the plane has seen it before. Most people have earbuds in and/or are looking at their phones. If something actually went wrong at 30,000 feet, a meaningful percentage of those passengers couldn't tell you what they should do in case of an emergency. The demonstration happened. Nothing was retained. The box got checked.
Security awareness training works exactly the same way. A one-time annual module covers the basics, gets clicked through by 11 a.m., and is mostly forgotten by the time a convincing phishing email arrives three months later. The employee who clicks it isn't careless. They're just human, and they were never given the kind of repeated, realistic practice that builds an actual conditioned response.
According to Verizon's 2026 Data Breach Investigations Report, sixty-two percent of breaches involve a human element. That number hasn't moved meaningfully in years. Not because people are getting worse at their jobs, but because the training most organizations provide isn't designed to change behavior under pressure. It's designed to satisfy a requirement.
The good news is that effective training does exist, it just looks nothing like what most businesses are currently doing. The gap between a workforce that amplifies your security posture and one that undermines it is almost entirely a training problem, and training problems are fixable.
The structural problem with once-a-year training isn't the content. It's the calendar.
But honestly, the calendar is only part of it. People aren't naturally wired to invest time and attention in something that feels abstract and unlikely. We take risks seriously after we've experienced consequences, a fender bender that made us a more careful driver, a kitchen burn that changed how we handle a hot pan. Cybersecurity threats don't come with that kind of visceral feedback loop. A phishing email that gets clicked doesn't immediately feel like anything. The consequences show up later, sometimes much later, and usually for someone else to deal with. That psychological distance is exactly why "just be careful online" has never worked as security advice, and why a one-time annual module that people click through to satisfy a requirement changes almost nothing about how they actually behave under pressure.
An employee who completes a 60-minute security module in January and isn't tested again until the following January has eleven months to forget everything they learned. Phishing emails don't arrive on a compliance schedule. They arrive on a Tuesday afternoon when someone is trying to clear their inbox before a 3 o'clock meeting. The gap between what an employee was told once and what they can recall under pressure six months later is exactly what attackers count on.
The data on this is pretty clear. Verizon's 2025 DBIR found that phishing report rates increased four times when employees had received training or a simulated phishing test within the past 30 days, compared to those who hadn't. Not marginally better. Four times. That's not a training content problem. That's a frequency problem. And KnowBe4's 2025 benchmarking data found that organizations running continuous training over 12 months cut their phish-prone rate by 86 percent, dropping from a baseline of 33 percent down to just 4 percent. The training works when it's actually given a chance to work.
The other thing annual training misses is that threats change. An employee trained on last year's phishing patterns is being prepared for last year's attacks. AI-assisted phishing is now producing lures that are personalized, grammatically perfect, and contextually aware in ways that would have looked like sophisticated nation-state targeting two years ago. A training program that updates annually is always fighting the last war.
The programs that actually change behavior have a few things in common, and none of them are complicated.
They're continuous. Short modules delivered monthly, not a single annual session. Two to five minutes of relevant, current content on a regular cadence beats an hour of generic material once a year on every retention metric available.
They include simulated phishing. Not once, as a baseline test, but on a regular schedule using current techniques. The goal isn't to catch people out or embarrass anyone. It's to give employees realistic practice recognizing threats before they encounter the real version. An employee who clicks a simulated phish and gets immediate feedback learns something. An employee who clicks a real one and finds out three weeks later when IT calls doesn't.
They build a reporting culture. The metric that matters most isn't how many people avoid clicking. It's how many people report something suspicious. An employee who reports a phishing attempt they're not sure about is doing exactly the right thing. Making that feel safe and easy is what determines whether it actually happens.
And they document everything. Completion rates, simulation results, click trends over time. Not for the training program's sake. Because that documentation is what gets produced when a cyber insurer, a regulator, or a client asks how seriously you take this. Employee training is one piece of a broader security strategy; for the full framework on how it fits together, The Cybersecurity Tools Are Fine. The Strategy Is What's Missing covers the complete picture.
Generic training tells everyone the same thing. The problem is that a finance manager, an executive, and an IT administrator face genuinely different threats, and preparing them identically leaves the highest-risk people the least prepared for what's actually coming at them.
Verizon's 2025 DBIR found that 8 percent of employees account for 80 percent of security incidents. Those employees aren't evenly distributed across the organization. They cluster in roles with elevated access, financial authority, or high external visibility. Finance teams are the primary target of business email compromise, which cost US businesses $3.04 billion in 2025 according to the FBI. Executives face personalized spear phishing built from publicly available information on LinkedIn and company websites. IT administrators are targeted specifically because compromising their credentials opens everything else.
A finance employee at engineering firm Arup approved a $25 million wire transfer in 2024 after joining a video call where every participant turned out to be a deepfake. That's not a generic phishing scenario. It's a role-specific threat that generic training would never have prepared anyone to recognize.
The programs that actually work build content around what each role actually faces. Not what all employees theoretically might encounter someday.
Oregon's Consumer Privacy Act took effect July 1, 2024, and it requires businesses handling personal data of Oregon residents to maintain reasonable safeguards, including administrative, technical, and physical measures to protect that data. The Oregon DOJ's guidance on reasonable safeguards explicitly lists employee training as a required component. Not implied. Listed.
The enforcement picture changed on January 1, 2026. The 30-day cure period that previously gave businesses notice before the AG could take action expired. The Oregon Attorney General can now serve a Civil Investigative Demand or file a lawsuit without giving anyone a heads up first. Penalties run up to $7,500 per violation, and each affected consumer counts as a separate violation. A data exposure affecting a few thousand Oregon residents stops being an abstract compliance question pretty quickly.
For businesses that process data of 100,000 or more Oregon consumers annually, or 25,000 or more and derive more than 25 percent of revenue from data sales, coverage is clear. For businesses closer to those thresholds, the safe move is to confirm rather than assume.
The practical implication is straightforward: a documented, ongoing employee training program isn't just good security practice for Oregon businesses. It's evidence of the reasonable safeguards the law requires.
Washington's My Health MY Data Act has been in effect since early 2024, and it covers a broader range of businesses than most people expect. The definition of "consumer health data" is wide enough to sweep in fitness apps, wellness platforms, retailers that infer health status from purchases, and plenty of other businesses that wouldn't naturally think of themselves as handling health data. Employee training on MHMDA obligations is explicitly listed as essential for compliance, not suggested.
The part worth paying attention to is the enforcement mechanism. Unlike Oregon's OCPA, the MHMDA includes a private right of action. That means individual consumers can sue directly, not just wait for the state AG to act. For a business that gets it wrong, the exposure isn't just regulatory. It's litigation.
Washington state also requires annual cybersecurity awareness training for all state agencies and contractors through WaTech policy. That standard increasingly shapes what private sector organizations operating in Washington's ecosystem are expected to demonstrate, particularly those doing business with government entities or in regulated industries.
The practical point is the same as Oregon: documented, ongoing training isn't just good practice. It's what the law expects, and in Washington, it's what plaintiffs' attorneys look for too.
Here's the uncomfortable truth: most breaches don't start with a sophisticated attacker finding a zero-day vulnerability in your firewall. They start with a Tuesday afternoon email that looked just convincing enough. Someone was busy, the urgency felt real, and the click happened before anyone thought twice. That's not a technology failure. That's a human one, and human failures are the only category of security risk that training actually fixes.
The good news is that it works. Twelve months of continuous training cuts phish-prone rates by 86 percent. Employees who've been trained and tested within the past 30 days report phishing attempts at four times the rate of those who haven't. The gap between a workforce that catches threats and one that enables them is almost entirely a function of how seriously the organization takes training, and how consistently it keeps pace with what attackers are actually doing.
Heroic Technologies works with professional services firms, law firms, and mid-sized businesses across Oregon, Washington, and California. They've spent 14-plus years helping organizations close the gaps that compliance checkboxes leave open, and security awareness training is one of the most consistent conversations they have with new clients. Because it's almost always underdone, and the consequences of that are almost always avoidable.
When it comes to employee training specifically, that means building programs that actually change behavior: continuous, role-specific, tested with realistic simulations, and documented well enough to satisfy a regulator, an insurer, or a client who asks.
If your current program is an annual video and a completion certificate, there's meaningful ground between where you are and where the threat environment requires you to be. Reach out to Heroic Technologies and let's close that gap.
1. How often should we run security awareness training?
Monthly micro-modules are the baseline for continuous programs, with simulated phishing campaigns on a similar cadence. Verizon's 2025 DBIR found that employees trained or tested within the past 30 days report phishing at four times the rate of those who haven't. Annual training satisfies a compliance checkbox. Monthly training actually changes behavior.
2. Do Oregon and Washington businesses have specific legal requirements around employee security training?
Yes. Oregon's Consumer Privacy Act explicitly lists employee training as a required component of reasonable safeguards, with penalties up to $7,500 per violation and no notice period before enforcement as of January 2026. Washington's My Health MY Data Act requires employee training on data handling obligations and includes a private right of action, meaning consumers can sue directly without waiting for the state AG.
3. What's the difference between a training program that changes behavior and one that doesn't?
The programs that actually work are continuous, role-specific, and tested with realistic simulations. The ones that don't are annual, generic, and measured by completion rates rather than behavior change. An employee who finishes a module isn't necessarily prepared for a well-crafted phishing email. An employee who's been regularly tested with realistic simulations and knows exactly how to report something suspicious is.
Annual training checks a box. It doesn't change behavior. Here's what effective security awareness training actually looks like for West Coast...
Artificial intelligence is already changing how law firms research, draft, review, and manage information. In many cases, the operational benefits...
Most law firm AI use is happening without oversight, without compliance monitoring, and without anyone clearly accountable. Here's how to fix that.