The Limits of Awareness Training

Itwerx is a service-disabled veteran-owned managed IT and cybersecurity provider serving Seattle-area businesses, founded in 2005, and part of that work is helping clients decide how much weight employee training should actually carry in their security plan.

Employee cybersecurity training is not, and has never been, a control that can stop every incident on its own. With AI-generated deepfakes, increasingly convincing phishing, and supply-chain and automation-chain attacks all becoming more sophisticated, no amount of training makes every person, every vendor, and every one of their vendors perfect all the time. That was true before AI made phishing more convincing, and it remains true now that AI has.

The design stance this argues for

The useful shift is not abandoning training, it is building your defenses on the assumption that a device, a service, or an account is already compromised, rather than treating good user behavior as the last and only line of defense. Segmented networks, layered monitoring, and access controls that limit what a single compromised credential can reach all keep working even on the day training fails, and training will eventually fail, for the same reason a bulletproof vest is designed to stop most rounds a police officer is likely to encounter rather than promising to stop all of them. That is the honest comparison: training raises the odds substantially, it does not raise them to certainty.

Why training is still required, not optional

None of that makes training dispensable. It is still the control that catches the ordinary, high-volume attempts before they become incidents, and it remains a stated control under several security and compliance frameworks a growing business is likely to face, including the preparation work Itwerx does for clients working toward CMMC readiness. Dropping training would not just weaken a defense in depth strategy, it would leave a documented compliance gap in exactly the frameworks that assume it is in place. The honest position is that training is necessary and, on its own, not sufficient, and a mature security program plans for both halves of that sentence rather than either one alone.

If your business has not yet built in the assumption that a breach can start from any device, any service, at any time, whether internal, external, on a travelling laptop, a home office, or a third-party hosted cloud service, that is the gap worth closing first, alongside the training program rather than instead of it.

Itwerx Corp is a service-disabled veteran-owned small business providing IT services across Seattle, Bellevue, Everett and Snohomish County. This is the kind of thing our cybersecurity work deals with – talk to us about yours.