Can Friction Make Cybersecurity Training More Effective?

Phishing simulations that offer immediate, friction-filled feedback are becoming essential components for organizations looking to bridge the gap between technical and human defenses. For years, the prevailing wisdom in the cybersecurity sector was that training should be as painless and streamlined as possible. Corporate leaders often feared that intrusive or difficult educational modules would lead to employee burnout or a general disregard for security protocols. This led to an era of “frictionless” learning, characterized by polished interfaces and short, gamified lessons that could be completed in minutes. However, the reliance on ease of use has inadvertently created a “completion culture” where the primary goal is to finish the module rather than to truly understand the underlying risks. As digital threats become increasingly sophisticated in 2026, many experts argue that this path of least resistance has left the human element—the most critical line of defense—woefully unprepared for the psychological manipulation used by modern attackers.

The Psychological Mechanics: How Humans Learn Security

Moving from Engagement: From Satisfaction to Efficacy

A landmark study conducted by researchers at Abertay University and the University of Cape Town recently challenged the established norms of corporate training by comparing two different psychological frameworks within a gamified environment. The first group of participants operated under a “fixed-reward” system, which is the most common model used in modern software. In this setup, users earned points for correct answers and received bonuses for maintaining streaks. This approach was highly popular among participants, who reported high levels of satisfaction and engagement. However, the study revealed a significant flaw in this positive reinforcement model: it did not lead to meaningful knowledge retention. While the participants enjoyed the process, the lack of consequences for incorrect choices meant they could simply guess their way through the training without engaging in the deep cognitive processing required to recognize subtle security threats in the real world.

The second group in the study was subjected to a “loss-aversion” framework, where they began with a maximum score that decreased every time they made a mistake. This introduced a palpable sense of pressure and consequence that is often missing from standard corporate education. The results were striking, as the loss-aversion group demonstrated knowledge gains that were more than double those of the reward-based group. Specifically, the participants facing potential losses saw a knowledge increase of 10.71%, compared to just 4.65% for those who were merely earning points. This finding suggests that the “fun” factor in training may actually be a distraction from the educational goal. When the stakes feel real, the brain is forced to pay closer attention to the details, moving beyond a superficial interaction with the material and toward a genuine understanding of how to detect and mitigate digital risks.

The Power: Productive Friction in Training

The success of the loss-aversion model is grounded in the psychological concept of “productive cognitive friction,” which suggests that a certain level of difficulty is necessary for effective learning. According to the dual-process theory of cognition, humans alternate between “System 1” thinking—which is fast, intuitive, and automatic—and “System 2” thinking, which is slow, deliberate, and analytical. Most frictionless training programs allow users to stay in System 1, clicking through familiar prompts without truly analyzing the information presented. By introducing friction, such as the penalty of losing points or the requirement to explain a wrong answer, training programs force users into System 2. This shift is vital because the sophisticated social engineering attacks of 2026 are specifically designed to exploit System 1 thinking, tricking employees into acting on impulse rather than through careful scrutiny.

Furthermore, introducing designed friction into simulations helps to mirror the high-stakes environment of an actual cyberattack. In a real-world scenario, the consequence of clicking a malicious link is not a missed badge but a potential multi-million dollar data breach that could cripple an entire organization. Productive friction provides a safe space for employees to experience the “sting” of a failure, creating a lasting mental association between a specific mistake and its negative outcome. This psychological reinforcement is far more effective at changing long-term behavior than a positive reward system that lacks gravity. By intentionally making the training process slightly more difficult and consequential, organizations can ensure that their employees are not just completing a task, but are developing the critical thinking skills necessary to identify the increasingly blurred lines between legitimate and fraudulent digital communications.

Risk Assessment: Navigating a Complex Threat Landscape

The Vulnerability: Analyzing the Human Surface

Despite the massive financial investments made in technical defenses like AI-powered firewalls and endpoint detection and response (EDR) systems, the human surface remains the most exploited entry point for global cybercrime. As the industry moves through 2026, data suggests that social engineering, phishing, and the misuse of stolen credentials continue to be the primary drivers behind successful data breaches. Attackers have recognized that it is often far easier to trick a human into providing access than it is to break through a hardened technological perimeter. This vulnerability is exacerbated by the rise of generative AI, which allows criminals to craft perfectly phrased emails, clone voices for vishing attacks, and create convincing deepfakes. This technological leap has removed many of the traditional “tells” of a phishing attempt, such as poor grammar or suspicious formatting, making the employee’s ability to remain vigilant even more essential.

The financial and operational implications of a single human error are staggering in the current economic climate. Recent industry reports indicate that the average cost of a data breach has climbed toward $5 million, a figure that includes regulatory fines, legal fees, lost productivity, and long-term brand damage. There is an “uncomfortable asymmetry” at play: while defensive technologies are becoming more automated and efficient, the human targets are being subjected to more personalized and psychologically complex attacks. This means that a passive approach to training is no longer a viable security strategy. Organizations must recognize that their employees are the final line of defense. If an individual cannot distinguish a highly tailored AI-generated phishing message from a legitimate internal communication, even the most expensive and advanced technical stack may fail to protect the organization’s most sensitive data assets.

The Evolution: Shifting Training Metrics

To effectively combat these evolving threats, organizations must fundamentally change how they define and measure the success of their cybersecurity education programs. For too long, the industry has relied on “vanity metrics” like completion rates and average quiz scores to prove the value of training to stakeholders. While these numbers are easy to track and report, they provide very little insight into whether the training has actually reduced the organization’s risk profile. A high completion rate might simply indicate that the training was easy enough for employees to finish quickly, while a high quiz score might only reflect short-term memorization rather than a permanent change in behavior. True efficacy should be measured by how well employees retain knowledge over long periods and, most importantly, how they perform when faced with unannounced, high-fidelity phishing simulations.

Moving forward, the focus must shift toward behavioral control systems that categorize employees based on their actual risk performance. For instance, a user who consistently identifies and reports simulated phishing attempts could be given a higher “trust score” and subjected to less frequent or more advanced training modules. Conversely, individuals who repeatedly fall for simulations should be directed toward high-friction, intensive educational tracks that provide immediate feedback and demand more cognitive engagement. This tiered approach allows security teams to allocate resources more efficiently, focusing their efforts on the individuals who represent the highest risk to the organization. By treating training as a dynamic, data-driven security control rather than a static compliance checkbox, companies can create a more resilient workforce that is capable of adapting to the shifting tactics of modern cyber adversaries.

Behavioral Security: The Future of Defensive Integration

The Role: Leveraging AI for Desirable Difficulty

Artificial intelligence is currently acting as a double-edged sword within the cybersecurity landscape, providing new tools for both the attackers and the defenders. While AI allows cybercriminals to scale their operations with unprecedented speed, it also empowers organizations to develop “agentic” security platforms that can monitor user behavior in real-time. These advanced systems are capable of delivering hyper-personalized training the moment a risky behavior is detected, such as when an employee attempts to visit a flagged website or enters their credentials into an unfamiliar portal. However, the true innovation lies in using AI to implement “desirable difficulty” within these interactions. Instead of simply blocking the action or providing a generic warning, an AI-driven platform can challenge the user to identify why the action was risky, forcing them to engage their analytical skills in a high-stakes moment.

These intelligent systems can adjust the friction level based on the user’s past performance and current cognitive load. If an employee is rushing through their tasks and demonstrating a lack of attention, the AI can introduce more complex scenarios or implement stricter penalties to ensure they remain vigilant. This prevents the training from becoming a predictable routine that employees can navigate on autopilot. The goal is to maintain a state of “optimal challenge,” where the training is difficult enough to require full attention but not so frustrating that the user becomes disengaged. By using AI to create a dynamic and somewhat unpredictable training environment, organizations can keep their employees’ defensive skills sharp. This ensures that the workforce remains prepared for the reality of the 2026 threat landscape, where attackers are constantly finding new ways to exploit the briefest moments of human inattention or fatigue.

The Outcome: Building the Human Firewall

The shift toward behavioral-focused security is already reflected in the product offerings of major cybersecurity firms. Modern platforms are moving beyond traditional antivirus and firewall solutions to include comprehensive human-risk management tools that treat employee behavior as a measurable data point. By integrating these tools into the broader security ecosystem, organizations are finally treating their workforce as a “human firewall” that can be tested, patched, and reinforced just like any software system. This integration allows for a more holistic view of security, where technical controls and human actions work in tandem to protect the enterprise. Companies that have successfully adopted this model found that creating a culture of security—one where individuals understand the stakes and are held accountable for their actions—is the most effective way to build long-term resilience against sophisticated digital threats.

In the final analysis, the transition toward friction-filled, behavioral-based training represented a necessary evolution in the fight against global cybercrime. Organizations that moved away from the frictionless compliance models of the past and embraced the concept of productive difficulty saw significant improvements in their defensive posture. By the middle of the decade, it became clear that the most effective training was not the one that employees liked the most, but the one that challenged them to think critically and react correctly under pressure. Security leaders prioritized the development of a resilient culture where safety was valued over convenience, ensuring that every member of the organization understood their role in the collective defense. This strategic shift successfully bridged the gap between technical infrastructure and human behavior, providing a robust framework for navigating the increasingly dangerous and unpredictable digital world.

Subscribe to our weekly news digest.

Join now and become a part of our fast-growing community.

Invalid Email Address
Thanks for Subscribing!
We'll be sending you our best soon!
Something went wrong, please try again later