Just-in-Time Training
Just-in-time training delivers a short security lesson at the moment a risky behavior occurs — such as right after a simulated phishing click — instead of in an annual course.
Just-in-time training (JIT training) is security education delivered at the moment it is relevant: immediately after an employee clicks a simulated phishing link, when they are about to send a file outside the organization, when a new starter receives their first external attachment, or when a finance user opens a payment request from an unfamiliar sender. Instead of front-loading everything into an annual course, the program waits for a teachable moment and delivers a lesson that is short, specific to what just happened, and over in under a minute.
How it works
The mechanism is timing. Research on awareness training consistently shows that knowledge decays: Reinheimer et al. (SOUPS 2020) found that gains in phishing-detection ability had lost statistical significance within six months of training. An eight-month study of about 19,500 employees by Ho et al. (IEEE S&P 2025) found no significant link between completing annual training and resisting a simulated phish, and observed that roughly three-quarters of users spent under a minute on the embedded page they were shown after clicking. The lesson is not that training never works, but that a long course delivered far from the behavior is the least effective format. Just-in-time delivery flips the ratio: a very short intervention, at the exact moment the person has just experienced the risk, tied to the specific lure that fooled them. In a phishing simulation program, that means the landing page after a click explains the two or three cues that gave the message away — the mismatched sender domain, the urgency, the unexpected attachment — rather than restarting a generic module.
How to use it well
Keep it under sixty seconds and about the specific message, not about phishing in general. Make the tone neutral: a JIT page that shames the user teaches silence, and the behavior you actually want is reporting. Pair it with a one-click "report this" action so the lesson ends in the desired habit. Use it beyond simulations — JIT prompts in the email client, the expense tool or the file-sharing dialog turn everyday workflows into training surfaces, which matters most for new employees, as our guide to new hire security onboarding explains. Finally, record every JIT event as a signal: the number of just-in-time moments an individual triggers, and whether they reported afterwards, belongs in their human risk score so reinforcement can be targeted where it is needed. JIT training is one of the practical tools behind the evidence-based approach in our analysis of security awareness training ROI.
Related terms
NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.
Book a demo