← All terms

Spaced Repetition

Spaced repetition schedules reviews at increasing intervals to beat memory decay — the evidence-based way to make security awareness training stick.

Spaced repetition is a learning technique that schedules reviews of the same material at increasing intervals — shortly after first exposure, then days, then weeks, then months later — instead of massing everything into a single session. Each review lands just before the material would be forgotten, resetting the forgetting curve at a shallower slope so the knowledge survives longer between touches.

How it works

The underlying finding, known as the spacing effect, is one of the most consistently replicated results in cognitive psychology. Cepeda, Pashler, Vul, Wixted and Rohrer's quantitative synthesis of more than a century of verbal-recall experiments found that spaced practice reliably outperforms massed practice — the same minutes of study produce substantially better retention when distributed over time. The effect is strongest when each review forces retrieval: actively recognizing a spoofed sender address trains the skill far better than passively re-reading a slide about it.

Applied to security awareness, spaced repetition means the sixty minutes most organizations spend on one annual course are worth more cut into short, recurring sessions across the year. It also reframes what a phishing simulation is: not a test to pass, but a scheduled retrieval event that exercises detection skills inside the retention window the last training opened. Longitudinal research shows why the schedule matters — phishing-detection ability measurably decays within four to six months of a one-off session.

How to use it

Build the program as a rhythm rather than an event: a short microlearning module monthly, a simulation between modules, and a detection refresh at least every four months. Rotate lure types and topics so each touch is a fresh retrieval rather than rote repetition, and tighten the interval for groups whose simulation performance sags between sessions. Our guide to security training frequency turns the research into a full cadence design.

Related terms

Forgetting CurveThe forgetting curve describes how memory decays after learning — steeply at first, then leveling off — and why one-off security training fades within months.MicrolearningMicrolearning delivers training in short, single-topic sessions of two to ten minutes — the format that fits real attention spans and slows knowledge decay.Just-in-Time TrainingJust-in-time training delivers a short security lesson at the moment a risky behavior occurs — such as right after a simulated phishing click — instead of in an annual course.
See your Human Risk Score

NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.

Book a demo