← All terms

Forgetting Curve

The forgetting curve describes how memory decays after learning — steeply at first, then leveling off — and why one-off security training fades within months.

The forgetting curve is the pattern of memory decay first measured by Hermann Ebbinghaus in 1885: retention of newly learned material drops steeply in the first hours and days after learning, then flattens into a long, slow decline. A 2015 replication by Murre and Dros reproduced the original result closely — most forgetting happens within the first day, and the bulk of it is complete within a week.

How it works

The curve is roughly exponential. Without reinforcement, the details of a training session — what a spoofed domain looks like, how to verify a payment-change request — fade fastest immediately after the session ends. Each successful retrieval of the memory, however, resets the curve at a shallower slope: reviewing material just before it would be forgotten makes the next forgetting cycle slower. This is the mechanism behind spaced repetition, and it explains why the timing of security training matters as much as its content.

Security-specific research matches the general pattern. Reinheimer et al. (SOUPS 2020) tracked phishing-detection ability after an interactive training session and found it significantly improved four months later — but statistically indistinguishable from baseline by six months. An annual awareness course therefore leaves a workforce spending at least half the year near its untrained level.

How to defend against it

You cannot patch human memory, but you can schedule around it. Refresh phishing-detection skills at least every four months, before the measured decay window closes. Replace one long annual session with short, recurring microlearning touchpoints, and use phishing simulations as retrieval practice — each simulated lure forces employees to exercise the recognition skill, which is exactly what interrupts the curve. For the full evidence and a practical cadence design, see our guide to security training frequency.

Full guide
Read the deep dive on this attack →

Related terms

Spaced RepetitionSpaced repetition schedules reviews at increasing intervals to beat memory decay — the evidence-based way to make security awareness training stick.MicrolearningMicrolearning delivers training in short, single-topic sessions of two to ten minutes — the format that fits real attention spans and slows knowledge decay.Just-in-Time TrainingJust-in-time training delivers a short security lesson at the moment a risky behavior occurs — such as right after a simulated phishing click — instead of in an annual course.
See your Human Risk Score

NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.

Book a demo