Cyberbeveiliging

Cybersecurity Training May Need More Friction, Not Less

mm
Voeg Securities.io toe aan je voorkeursbronnen op Google

Companies have spent years trying to make cybersecurity training easier to complete. Modules have become shorter, interfaces cleaner, and lessons more game-like. The logic is straightforward: if employees are more engaged, they should learn more and make fewer mistakes.

A new study from researchers at Abertay University and the University of Cape Town challenges part of that assumption.1 Rather than asking whether gamification works, the researchers compared two different ways of structuring it. One rewarded users for correct answers. The other made users start with points and lose them when they made mistakes.

The results suggest that the most enjoyable cybersecurity training may not always produce the strongest learning outcome. In the larger experiment, the loss-aversion group recorded a 10.71% overall knowledge gain, compared with 4.65% for the fixed-reward group. Meanwhile, participants exposed to fixed rewards reported somewhat better engagement, although the difference in overall engagement between the groups was not statistically significant.

That distinction matters because cybersecurity training is not entertainment. Its purpose is to change how people behave when an actual phishing email, malicious attachment, fake website, or compromised credential appears in front of them.

The Human Layer Remains Part Of The Attack Surface

Cybersecurity spending has traditionally focused on technical defenses: firewalls, endpoint protection, identity management, encryption, threat detection, and increasingly AI-powered security operations. Those technologies are essential, but many attacks still succeed because someone can be persuaded to click, approve, disclose, or trust something they should not.

The 2026 Verizon Data Breach Investigations Report continues to identify social engineering, phishing, and stolen credentials as major components of the modern breach landscape. At the same time, the economics of failure are becoming more severe. IBM’s 2026 Cost of a Data Breach Report put the global average cost of a breach at $4.99 million and reported a sharp increase in AI-enabled attacks.

This creates an uncomfortable asymmetry. Defensive systems are becoming more automated, but attackers are also gaining better tools for personalization, impersonation, reconnaissance, and scale. As Securities.io has examined in its coverage of AI-driven ransomware defense, cybersecurity is shifting toward broader resilience rather than relying on any single layer of detection.

Employee decision-making belongs inside that resilience model. A worker who notices a suspicious request before interacting with it can stop an attack before expensive technical controls ever need to respond.

Why Losing Points Can Improve Cybersecurity Learning

The study used two web applications containing the same training content but different incentive structures. Participants learned about passwords, social engineering, website security, and malicious software. In the loss-aversion version, wrong answers reduced a user’s score. In the fixed-reward version, correct answers accumulated points and streak bonuses.

In the social engineering scenario, for example, loss-aversion participants began with 60 points and lost points for mistakes, with consecutive errors creating larger deductions. Fixed-reward participants started at zero and earned additional points for consecutive correct answers.

The difference sounds minor, but it changes how the learner experiences a mistake. A missed reward means nothing was gained. A loss means something already possessed has disappeared.

Large-Scale Study Metric Loss Aversion Fixed Rewards
Participants 64 64
Overall Knowledge Gain +10.71% +4.65%
Social Engineering Gain +22.62% +17.77%
Website Security Change -7.12% -19.79%
Overall Engagement Score 3.73 / 5 3.92 / 5

The researchers describe the difference as a potential form of “productive cognitive friction.” When mistakes carry an immediate cost, users may slow down, inspect information more carefully, and move from fast intuitive responses toward more deliberate reasoning.

That does not mean employers should make training deliberately unpleasant. Excessive penalties can create frustration or decision paralysis. The more useful insight is that friction can be designed. Security training does not necessarily need to remove every obstacle between an employee and course completion.

Cybersecurity Training Should Optimize For Decisions, Not Completion

Many corporate training systems are still measured through metrics such as completion rates, time spent in a module, quiz scores, or employee satisfaction. Those numbers are easy to collect, but they can encourage the wrong optimization target.

If the objective is to reduce security incidents, a better model would distinguish between at least three outcomes:

  • whether employees complete the training,
  • whether they retain the underlying security knowledge, and
  • whether they apply that knowledge correctly when confronted with a real threat.

Gamification can support all three, but the same mechanics may not maximize each one. The study illustrates this clearly. Fixed rewards produced the stronger descriptive engagement profile. Loss aversion produced the larger overall knowledge gain.

This has implications for how companies deploy security awareness software. Instead of giving every employee the same annual module, organizations could increasingly adapt training to observed behavior. A user who repeatedly identifies simulated phishing emails may need little intervention. Someone who routinely clicks suspicious links may need more frequent exercises, stronger feedback, or additional friction before risky actions.

That approach turns security training from a compliance exercise into a behavioral control system. It also fits the wider movement toward continuous cybersecurity. Recent Securities.io coverage of agentic cybersecurity platforms shows how quickly automated security operations are evolving. Human-risk systems can develop along the same trajectory by continuously measuring behavior and adjusting training rather than waiting for an annual refresher.

AI Makes Human Cyber Risk More Important, Not Less

AI creates another reason to rethink security awareness. Attackers can use generative systems to produce more convincing messages, mimic writing styles, accelerate reconnaissance, and create persuasive impersonation attempts. Defenders can use the same class of technology to filter threats, automate analysis, and identify anomalous behavior.

The result is not the removal of humans from cybersecurity. It is a change in the kinds of decisions humans must make. Employees increasingly need to judge requests that may appear polished, personalized, and contextually believable.

This is why the human layer should not be treated as an embarrassing weakness that technology will eventually eliminate. It is another security surface that can be monitored, trained, and improved. Securities.io’s broader look at cybersecurity companies reflects how the sector is already moving toward integrated platforms that combine multiple forms of protection rather than treating each threat in isolation.

The study also offers a useful warning for AI-enabled training systems. Personalization should not automatically mean making everything easier. An intelligent training platform may be more valuable if it knows when to introduce difficulty, when to require a second look, and when a user should experience a consequence for a poor decision.

Investing In Human Risk Management

For investors interested in the cybersecurity sector, the emerging human-risk layer creates another dimension to an already expanding market. One company directly addressing this area is Fortinet.

Fortinet And Security Awareness Training

Fortinet’s FortiSAT platform combines security awareness training with phishing simulations, risk scoring, behavioral measurement, and targeted remediation. The important connection to the research is not that Fortinet uses the exact loss-aversion design tested in the paper. Rather, FortiSAT reflects the broader move toward treating employee behavior as measurable security data rather than a one-time compliance obligation.

The platform can identify higher-risk users, assign remedial training after failed phishing simulations, and connect behavioral outcomes with wider security controls. That is a more mature model than simply requiring every employee to watch the same video once per year.

For investors, Fortinet therefore represents exposure not only to traditional network security, but also to the convergence of technical controls, user behavior, analytics, and continuous security education.

FTNT Prijsgrafiek

Cybersecurity May Need Desirable Difficulty

The strongest takeaway from the research is not that punishment is better than reward. The study is exploratory, the samples are relatively small, and the researchers acknowledge limitations including unpaired assessments, possible differences in question difficulty, and cognitive fatigue in later modules.

The more durable idea is that effective cybersecurity training may require a certain amount of desirable difficulty. An employee who breezes through a course may feel confident without having learned enough to make better decisions under pressure.

As attackers become faster and more persuasive, enterprises will need to measure cybersecurity training by what employees actually learn and how they behave, not simply whether they enjoyed the experience. The next generation of human-risk platforms may therefore compete on something more meaningful than engagement: their ability to create the right amount of friction at the exact moment it improves judgment.

References:

1 Carle, N., Ophoff, J., & Shepherd, L. (2026). Incentive design in gamified cyber security training: The roles of loss aversion and fixed rewards. Computers & Security. https://doi.org/10.1016/j.cose.2026.105187

Daniel is een sterke voorstander van de potentie van blockchain om traditionele financiën te verstoren. Hij heeft een diepe passie voor technologie en verkent altijd de laatste innovaties en gadgets.