logo

CISA Recommends Continuous Cybersecurity Training

ID: 3c5ad2ca-d62d-5b49-a26c-a6cc1b8f77e6

STIX ID: report--3c5ad2ca-d62d-5b49-a26c-a6cc1b8f77e6

Feed Name: KnowBe4 Blog

Date Published: 2024-03-21

Date Updated: 2026-04-28

Author: Roger Grimes

...
...

The article advocates for continuous cybersecurity training to reduce human-factor risk from social engineering—citing data that 70–90% of breaches involve social engineering—and recommends an initial onboarding session, annual refreshers, and short monthly training reinforced by frequent simulated phishing. It notes CISA’s endorsement of “continuous cybersecurity training” in recent guidance related to Volt Typhoon and argues that regular, tailored instruction (including AI-driven personalization via AIDA) is more effective than infrequent training. The piece emphasizes making cybersecurity education an ongoing practice akin to real-world safety habits.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.