Vigilance gained from security education decays with time and fatigue
Aliases: vigilance decay · phishing training forgetting · phishing training decay
What it is
Decay of trained phishing vigilance means that cue memory and checking behavior gained after instruction can weaken with time, repeated messages, task load, and alert fatigue. Improvement on one exercise is not a permanent personal trait. As attacks and work context change, an old checklist may also lose diagnostic value.
Why it happens
Training adds security inspection to ordinary work, but checking has little immediate reward and competes with speed and responsiveness. Repeating similar simulations can teach recognition of a training template rather than transfer to real attacks; frequent low-quality tests can produce disregard or resentment. Spacing, contextual fit, feedback timing, and a punitive climate all affect retention and reporting.
Studying it
In an approved longitudinal design, present simulations with calibrated difficulty and context at several post-training intervals. Compare recognition, independent verification, reporting, false alarms, and response time. Rotate attack forms and use held-out contexts to test transfer rather than template familiarity. Record workload and message exposure; avoid shame boards and punitive harm, and do not optimize click reduction alone.
Where it stops holding
Decay has no fixed rate. Short timely reinforcement, peer norms, and usable reporting can improve retention. Experienced roles and salient incidents may establish durable habits, though fatigue still matters. Training can support comprehension and reporting, but it is neither a permanent patch nor evidence that users should own interception. Technical and process controls remain necessary.
Applying it
- Use spaced, role-relevant, changing micro-exercises with feedback on the decision evidence and safer action, not merely who answered incorrectly.
- Interpret results by message difficulty, recipient context, and time interval rather than ranking raw click rates across unlike exercises.
- Monitor reporting, false alarms, independent verification, and fatigue feedback, adjusting cadence and format when benefits decline.
- Feed training findings into filtering, provenance, and business-process teams to remove recurring system conditions that invite error.
Related
Cards in the same group
- O3.04.1Users have difficulty verifying source authenticity
- O3.04.2Domains and sender fields are weak cues
- O3.04.3The system should provide a trustworthy source indicator
- O3.04.4Spelling and visual lookalikes can fool users during rapid domain scanning
- O3.04.6Relying only on users to detect phishing is a limited defense
- O3.04.7An isolated, context-free warning does not connect users to the risk