← All terms

Microlearning

Microlearning delivers training in short, single-topic sessions of two to ten minutes — the format that fits real attention spans and slows knowledge decay.

Microlearning is a training format that delivers content in short, focused sessions — typically two to ten minutes, covering one topic and one behavior at a time — instead of long, comprehensive courses. In security awareness programs, a microlearning module might cover exactly one thing: how to verify a bank-detail change, what a QR-code lure looks like, or when to report a suspicious login prompt.

How it works

Microlearning is built around two constraints that long-form training ignores. The first is attention: in an eight-month study of roughly 19,500 employees, Ho et al. (IEEE S&P 2025) observed that about 75% of employees closed the training page they were shown within a minute. A 45-minute course does not get 45 minutes of attention; it gets skimmed, deferred, or clicked through. A five-minute module, by contrast, fits inside the attention an employee will actually give it between meetings.

The second constraint is memory. The forgetting curve means a single long session decays just as fast as a short one — so the same total seat time buys far more retention when distributed across the year on a spaced repetition schedule. Six ten-minute modules cost what one annual hour costs, but each lands inside the retention window the previous one opened.

How to use it well

Keep each module to one behavior, and end it with an action rather than a quiz-for-completion — report this email, check this sender, verify via a second channel. Pair the scheduled modules with event-driven just-in-time training that fires the moment someone fails a phishing simulation, when motivation to learn is highest. And resist the temptation to stack modules into a de facto long course: the format works because it is small. For how microlearning fits into an evidence-based cadence, see our guide to security training frequency.

Related terms

Just-in-Time TrainingJust-in-time training delivers a short security lesson at the moment a risky behavior occurs — such as right after a simulated phishing click — instead of in an annual course.Forgetting CurveThe forgetting curve describes how memory decays after learning — steeply at first, then leveling off — and why one-off security training fades within months.Spaced RepetitionSpaced repetition schedules reviews at increasing intervals to beat memory decay — the evidence-based way to make security awareness training stick.
See your Human Risk Score

NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.

Book a demo