What is AI-adaptive security awareness training?
AI-adaptive security awareness training is training that is assigned by measured behavior rather than by the calendar. Each employee is continuously tested across the channels attackers actually use; every outcome updates their Human Risk Score; and the score — not a compliance date — decides what training they receive next, how hard their next simulation is, and whether they need any training at all.
How behavior-triggered training works
What the CISO sees
Five tabs. Two of the views answer the question every awareness programme has failed to answer: which module actually reduced clicking.
Champions leaderboard
People view · ranked by risk, not activityRecognition is derived from the risk score and weighted toward reporting: champion score = (100 − risk score) × 0.6 + reporting weight, with reporting capped so it lifts but never dominates.
| Employee | Champion score | Risk score | Reports |
|---|---|---|---|
| 1Employee 1 | 41.6 | 44 | 12 |
| 2Employee 2 | 39.2 | 38 | 3 |
| 3Employee 3 | 37.4 | 40 | 5 |
Custom export
Section-selectable and branded.
Certificates
Each one has a public verification page, so a certificate can be checked by anyone holding it.
Audit log
Exportable to your SIEM.
Completion integrity, measured server-side
So NOUSEC does not record it as evidence. Every completion is classified by time on content against the module's expected duration, and video completion is a measured quantity, not a click.
Four ways to spend an assigned minute
Video completion requires ninety percent of the video's unique seconds to have been watched, computed server-side. Accrual pauses when the tab is hidden or the video is paused.
Drag to the end and walk away and coverage stays near zero: no completion, no certificate. A failed run leaves the enrollment in progress.
The completion record is issued by the server, not asked for by the client. Passive video shows no invented score — the certificate carries the completion date and the actual duration, nothing else.
The compliance scorecard reports both rates
A raw completion rate, and an audit-adjusted rate that discounts completions showing no evidence of real engagement. Auditors see the gap between them, which is the number that actually means something.
What employees actually receive
Fourteen formats across three delivery paths, and five things inside them that are built differently from the rest of the category.
Forensic feedback
Every wrong answer names the observable signal that gives the attack away. Specificity is the entire lesson.
An escape room, not a points system
Async, single-player, in the browser. No scheduled session, no facilitator, no points standing in for a game.
Deepfake voice detection
Real-versus-synthetic audio pairs in a banking context, with a forensic debrief on every clip.
15policy templates
White-labelled to the customer's organisation and paired to a training module. Acknowledgement re-gates on version change while the acknowledgement history is preserved.
Localised, not translated
Character names, company names and cultural context change per language — not just the strings. Arabic runs right-to-left, and every language ships its own SCORM package and subtitles.
A language that only exists on a pricing page is not a language.
The learner is renamed, not subtitled. Company names and scenario context change with them.
Why annual security awareness training fails
We built the platform this way because the published research is unambiguous about the alternative. Three findings decided the design.
Annual training did not reduce phishing failure
A randomized trial across 19,500+ employees over eight months found no significant relationship between recently completing mandated annual training and failing a phishing simulation. Embedded post-failure training moved click likelihood by about 2 percentage points.
Ho et al., IEEE Symposium on Security & Privacy, 2025The gain is gone before the next course is due
Re-tested at intervals, employees were still significantly better at spotting phishing four months after a course (d′ 1.60, p = .034). By month six the improvement was no longer statistically significant (d′ 1.46, p = .123). A twelve-month cycle leaves roughly half the year uncovered.
Reinheimer et al., USENIX SOUPS 2020Continuous measurement is what moves the number
Across 42 million simulations at 64,000 organizations, the average share of employees who fail a phishing test fell from 33.2% at baseline to 20.1% after 90 days and 4.2% at twelve months of continuous testing and training.
KnowBe4 Phishing by Industry Benchmarking Report, 2026All three figures are industry research, not NOUSEC results. We have no customer outcome data to publish yet, and we would rather say so than imply otherwise.
Read the full research →Conventional security awareness training vs. NOUSEC
The difference is not content quality. It is what decides who gets trained, when, and how anyone knows it worked.
Audit evidence for NIS2, DORA, ISO 27001 and PCI DSS
Security awareness training FAQ
What is AI-adaptive security awareness training?
AI-adaptive security awareness training is training assigned by measured behavior rather than by the calendar. Each employee is continuously tested across the channels attackers actually use; every outcome updates their Human Risk Score; and the score — not a compliance date — decides what training they receive next, how hard their next simulation is, and whether they need any training at all.
Does security awareness training actually reduce phishing?
Not in the form most organizations run it. A 2025 randomized trial of more than 19,500 employees found no significant relationship between recently completing annual mandated training and failing a phishing simulation. What does move the number is continuous testing paired with training: across 42 million simulations, average phish-prone rates fell from 33.2% to 20.1% within 90 days and to 4.2% at twelve months. The decisive variable is frequency and measurement, not course quality.
How does NOUSEC measure unique-second watch coverage?
Video completion requires 90% of the video's unique seconds to have been watched, computed server-side rather than claimed by the browser. Accrual pauses when the tab is hidden or the video is paused, so scrubbing to the end and walking away leaves coverage near zero — no completion and no certificate. A forged completion request returns 403.
What is an audit-adjusted completion rate?
The compliance scorecard reports two numbers: a raw completion rate, and an audit-adjusted rate that discounts completions showing no evidence of real engagement. Auditors see the gap between them, which is the figure that actually reflects whether people learned anything. Completions are classified by time on content against each module's expected duration — Skipped under 30%, Fast Clicker 30–70%, Engaged 70–130%, Deep Engaged above 130%.
Which compliance frameworks does security awareness training satisfy?
NIS2 requires management bodies to follow cybersecurity training (Article 20(2)) and lists cyber hygiene and training among mandatory risk-management measures (Article 21(2)(g)). DORA requires ICT security awareness programs as compulsory modules for all staff and senior management (Article 13(6)). ISO/IEC 27001:2022 covers it under Annex A control 6.3. PCI DSS v4.0 requires training on hire and at least every 12 months, explicitly including phishing and social engineering (Requirements 12.6.3 and 12.6.3.1).
Is NOUSEC GDPR compliant, and where is our data held?
NOUSEC is GDPR native with EU data residency in Frankfurt. No endpoint agents and no software installation are required. Training content is delivered in employees' own languages — nine shipped today, with twenty-one more built to the same four-gate localisation process on request.
In 20 minutes we will fail a simulation on purpose and show you exactly what the platform does next.
Book a demo