For CISOs, IT teams, and compliance leaders in LATAM, security awareness training stops being an attendance checkbox and becomes a human risk program. Evidence across NIST, academic research, and industry reports shows that a stand-alone annual course measures compliance, but does not reliably change clicks, reporting, or retention. The right approach is to run with behavior metrics and continuous reinforcement.
Before looking at each source separately, the comparison brings together something none of them provides in full: the regulatory framework, empirical evidence, and operational consequence. That is where it becomes clear that the value is not in completing a course, but in sustaining learning, simulation, and measurement by cohort and role.
| Source | Time dimension | Main metric | Observed effect | Implication for the CISO |
|---|---|---|---|---|
| NIST SP 800-50 | Program with four steps, design, development, implementation, and post-implementation | Awareness and training as separate functions | Awareness means making security matter, training means teaching specific tasks | Separate culture and performance metrics, and run a formal measurable program |
| NIST SP 800-50 Revision 1 | Continuous approach for the whole workforce | Role-based learning program | Updates awareness and training into a continuous program | Move from annual course to sustained, segmented learning |
| UC San Diego | 10 types of phishing emails over eight months | Probability of clicking in phishing | Embedded phishing training reduced link clicks by 2% | Question the practical value of annual training as an isolated control |
| Frontiers in Computer Science | Mediation analysis on training and awareness | Security awareness and reporting | Security Awareness is the strongest predictor of mitigation and reporting | Measure awareness and reporting as intermediate indicators |
| Verizon DBIR 2026 | Breaches in the latest report | Human element and social engineering | Human element present in 62% of breaches, social engineering in 16% | Prioritize human behavior metrics and controls against social engineering |
| 90 days and 12 months of continuous training | Phish-prone Percentage | PPP fell from 32.4% to 17.6% at 90 days and to 5% after a year | Use continuous campaigns and compare PPP by segment |
What does NIST say about the program, and what changes with the revision?
NIST SP 800-50, Building an Information Technology Security Awareness and Training Program, organizes the program into four steps: design, development, implementation, and post-implementation. It also separates awareness from training, where awareness means making security matter and training means teaching specific tasks. That distinction matters because it prevents everything from being measured with one variable, course completion.
The 2024 revision, NIST SP 800-50 Revision 1, shifts the focus toward a continuous learning program for the whole workforce, based on roles. Whalemate reads that directly: the standard no longer pushes an annual-event logic, but a sustained and segmented model. For a CISO, that enables program design, not just a training plan.
Why does the annual course fall short in practice?
The UC San Diego study evaluated 10 types of phishing emails over eight months and found that embedded phishing training reduced the probability of clicking links by only 2%. The study’s own conclusion is that these programs are unlikely to offer significant practical value in reducing phishing risk. That creates an uncomfortable tension for compliance, because the course can exist and still not change behavior.
Whalemate reads this as a problem of timing and design. If the intervention happens once a year, but the risk appears every day, the control expires before it matures. That is why the useful metric is not attendance, but behavior change across simulations and reinforcement.
What does the evidence show about awareness, not just training?
The Frontiers in Computer Science study found that Information Security Training has a positive effect on Security Awareness, but awareness is the strongest predictor of both phishing mitigation and reporting. In other words, training does not directly drive the most valuable change; it does so through the level of awareness it helps build.
The tension here is operational, not theoretical. If the indicator that best explains behavior is awareness, then a dashboard that only counts completed courses is tracking the wrong variable. For CISOs and compliance teams, the value is in measuring awareness and reporting rates as intermediate signals, because that is where it becomes clear whether the intervention is working.
What happens when the program is continuous and practice-based?
The report summarized by HIPAA Journal shows that the average Phish-prone Percentage fell from 32.4% to 17.6% after 90 days and to 5% after a year of continuous training. In healthcare and pharmaceuticals, PPP also reached 4.1%, 5.1%, and 5.9% depending on organization size. The signal is clear: when there is continuity, practice, and reinforcement, the metric that matters does move.
That does not contradict UC San Diego. It complements it. The difference does not appear to be whether training exists, but how it is structured. Continuity, repetition, and cohort tracking change the result where an isolated course does not.



