← All terms

Just-in-Time Training

Just-in-time training delivers a short security lesson at the moment a risky behavior occurs — such as right after a simulated phishing click — instead of in an annual course.

Just-in-time training (JIT training) is security education delivered at the moment it is relevant: immediately after an employee clicks a simulated phishing link, when they are about to send a file outside the organization, when a new starter receives their first external attachment, or when a finance user opens a payment request from an unfamiliar sender. Instead of front-loading everything into an annual course, the program waits for a teachable moment and delivers a lesson that is short, specific to what just happened, and over in under a minute.

How it works

The mechanism is timing. Research on awareness training consistently shows that knowledge decays: Reinheimer et al. (SOUPS 2020) found that gains in phishing-detection ability had lost statistical significance within six months of training. An eight-month study of about 19,500 employees by Ho et al. (IEEE S&P 2025) found no significant link between completing annual training and resisting a simulated phish, and observed that roughly three-quarters of users spent under a minute on the embedded page they were shown after clicking. The lesson is not that training never works, but that a long course delivered far from the behavior is the least effective format. Just-in-time delivery flips the ratio: a very short intervention, at the exact moment the person has just experienced the risk, tied to the specific lure that fooled them. In a phishing simulation program, that means the landing page after a click explains the two or three cues that gave the message away — the mismatched sender domain, the urgency, the unexpected attachment — rather than restarting a generic module.

How to use it well

Keep it under sixty seconds and about the specific message, not about phishing in general. Make the tone neutral: a JIT page that shames the user teaches silence, and the behavior you actually want is reporting. Pair it with a one-click "report this" action so the lesson ends in the desired habit. Use it beyond simulations — JIT prompts in the email client, the expense tool or the file-sharing dialog turn everyday workflows into training surfaces, which matters most for new employees, as our guide to new hire security onboarding explains. Finally, record every JIT event as a signal: the number of just-in-time moments an individual triggers, and whether they reported afterwards, belongs in their human risk score so reinforcement can be targeted where it is needed. JIT training is one of the practical tools behind the evidence-based approach in our analysis of security awareness training ROI.

Related terms

Security NudgeA security nudge is a small, well-timed prompt — a banner, a warning, a reminder — that steers employees toward the safe choice without blocking them or requiring training.Security CultureSecurity culture is the shared attitudes, norms and habits that shape how people in an organization actually behave around security when nobody is checking.Human FirewallA human firewall is a workforce trained and measured to recognize, resist and report social engineering — the defensive layer technology cannot replace.PhishingPhishing is a social engineering attack that uses fraudulent emails, websites, or messages to trick people into revealing sensitive information or installing malware.
See your Human Risk Score

NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.

Book a demo