Jul 29 2026
Security

Security Awareness Training Reduces Phishing Success

Districts are combating cyberattacks by training their staff, and they’re seeing measurable improvements.

Human error is the soft underbelly of cybersecurity. According to IBM, it plays a role in roughly 95% of breaches, a statistic that looms especially large in K–12 education. Schools are uniquely vulnerable, with thousands of users, limited IT resources, and an environment built on openness and trust.

“People talk about humans as the weakest link,” says Randy Rose, vice president of security operations and intelligence at the Center for Internet Security. “And the reason they get that rap is because the No. 1 factor in a majority of cyber incidents is social engineering, mostly phishing emails.”

All it takes is one hurried teacher clicking a convincing phishing link, or a staff member reusing a weak password, to set off a chain reaction — locked systems, exposed data, and days or weeks of disruption. “There’s a lot of information coming at educators, and they’re expected to make decisions quickly,” Rose says. “When you put those things together, it’s very easy for people to make mistakes.”

Click the banner below to find a roadmap for keeping your district cyber resilient.

 

In response, school districts are increasingly turning to security awareness training as a frontline defense, pairing education with technical controls to create a more resilient digital environment. The goal, in an ever-changing threat environment, is to turn a weak link into the first line of defense.

“Phishing attacks evolve like anything else, especially with generative artificial intelligence. The things we used to teach people to look for aren’t always happening anymore,” Rose explains. “Districts have to train staff on the latest attacks, and a great way to do that is through security awareness training.”

Districts Place an Increased Focus on Cybersecurity Training

Implemented as a managed service or a feature of endpoint protection software, security awareness training is meant to mitigate human error, giving teachers and staff the information they need to avoid costly mistakes. Although it can be hard for districts to require such training of staff, a growing number of insurance companies are making it mandatory when issuing cyber policies.

“There’s definitely an increased focus on cybersecurity training in the K–12 sector,” Rose says.

The Appleton Area School District (AASD) in Wisconsin is looking hard at how to mandate its cyber training and phishing simulations. It’s been using the Infosec IQ security awareness training alongside a Fortinet endpoint detection and response (EDR) solution for three years and has seen good results.

Today, when the platform sends out a phishing simulation, the number of staff who mistakenly click a link is down about 60%, according to Scott Werfal, the district’s director of technology services. “The product is well integrated and automated, so we don’t have to touch it much,” he says.

Simulated emails include a button to report them as phishing, and should staff erroneously click a link, the system explains how they could have identified it correctly as a phishing attempt.

Werfal says the ongoing training is important because phishing is relentless. “It’s 99% of our issues,” he explains. “So, all staff, including IT, get four simulations a month and then monthly video training with assessments on various topics. The content is high-quality, and it’s been well received by staff.”

Still, although the number of compromised accounts has dropped through training and other endpoint security measures voluntary participation in the video trainings hovers around 40%. “No one necessarily likes training,” Werfal says.

Having recently presented to AASD leadership, Werfal says that momentum is building to better formalize security awareness as required training. “It’s coming,” he says, “because we’re getting attacked constantly. We have to make sure people understand what they should and shouldn’t be doing.”

WATCH: K–12 districts are building a culture of shared responsibility for cybersecurity.

67%

The percentage of organizations that have seen a reduction in intrusions, incidents and breaches since implementing security training

Source: Fortinet, “2025 Security Awareness Training Global Research Report,” February 2026

Some Cyber Insurance Providers Require Security Awareness Training

When South East Cornerstone Public School Division (SECPSD) No. 209 in Saskatchewan began exploring security awareness training solutions, it was one of the only divisions in the Canadian province at the time that qualified for cyber insurance coverage.

“Then comes the next re-up, and we’re asked, ‘Are you doing cybersecurity training for your staff?’” recalls Brian Belinsky, information systems manager.

The expansive division of 35 schools had already adopted Arctic Wolf managed detection and response to monitor its endpoints, network and cloud applications. It implemented email security and zero trust, and yet, Belinsky says of cyber insurance, “What you qualify for today won't be the same three months down the line.”

SECPSD spent two years cutting its teeth on a separate platform before it adopted Arctic Wolf’s Managed Security Awareness offering, which integrates with its other Arctic Wolf services. “It's not just about compliance,” Belinsky says. “It really drives behavior change.”

Arctic Wolf’s program focuses on continuous improvement rather than periodic training. Staff members receive regular phishing simulations and short, engaging training modules tailored to their roles. Quizzes are not based on the most recent security videos; they test staff’s recall of all accumulated knowledge, a feature Belinsky finds particularly impactful.

Through a dashboard, the IT team can see trends — who’s improving, where vulnerabilities persist and which types of attacks seem most effective. This data-driven approach allows them to refine their efforts and allocate resources more effectively.

The Arctic Wolf platform calculates a “security culture score” to describe awareness across the division’s staff of 1,500. When it rolled out in 2023, SECPSD rated in the “high 40s,” Belinsky says. Now, it’s in the 80th percentile. And although SECPSD doesn’t require staff to participate in the training, completion rates went from 34% in the beginning to 66% today.

“We don’t force it on people, and we haven’t had any pushback from our staff, the teachers federation or other union groups,” Belinsky says. “They see it as a valued add-on.”

Scott Werfal
We have to make sure people understand what they should and shouldn't be doing."

Scott Werfal Technology Director, Appleton (Wis.) Area School District

Just-in-Time Security Training

Homer Community Consolidated School District 33C, 30 miles southwest of Chicago, had a similar experience. In 2023, it rolled out a managed detection and response solution, and its cyber insurance provider wanted the district to consider security awareness training. “They weren’t saying we had to mandate it. They just wanted us to offer it,” explains Eric Nush, the district’s technology director.

Homer CCSD adopted Huntress Managed Security Awareness Training (SAT), along with the company’s Managed EDR and security information and event management solutions. Just in time.

“In the past year or so, phishing attacks have increased,” Nush says. “They’ve gotten more sophisticated too. We’re seeing attacks from one school district to another, where a user in one gets compromised. Those are hard to simply block.”

Since adopting Huntress in 2023, Nush says, no accounts in Homer CCSD have been compromised, which he credits in large part to the Managed SAT. “Our phishing training has really helped. Every user gets an automatic message sometime every month,” he says.

The timing and content vary from user to user. That way, staff can’t alert others to the specific simulations. In addition, the platform pushes out training modules — seven- to nine-minute videos on various cybersecurity subjects — up to twice a month. The steady cadence has had fortuitous benefits.

“One time, the platform sent out its version of a DocuSign phishing attempt, just weeks before an actual DocuSign phishing attempt started hitting districts,” Nush says. “Fortunately, our staff had already seen something similar.”

Overall, training completion rates in the district have been modest, though clerical and office staff rates have been significantly higher. Nush says he’d love to require staff to take security awareness training, but the negotiations are out of his hands.

“Every school district does it differently because there’s no mandated cybersecurity training in our state,” he says. “But the biggest takeaway from these programs is the simple awareness. Previously, nobody but IT talked about cybersecurity because it wasn’t on their radar. With this kind of training, it is.”

Photography by Graham Washatka
Close

New Research from CDW on Workplace Friction

Learn how IT leaders are working to build a frictionless enterprise.