Unveiling Security Education Efficacy in Corporations
In a recent study conducted by LRM Corporation, which specializes in the security education cloud service 'Securio,' approximately 1,000 business professionals across Japan were surveyed to gain insight into corporate security education. The results showcased a concerning reality: about 50% of employees claimed that security training failed to change their behaviors. Furthermore, the incident experience rate among executives was found to be 1.7 times higher than that of general employees.
Key Findings from the Study
1.
Executive Risk Awareness vs. General Employee Behavior
- The study found that the rate of security incidents or close calls experienced by executives peaked at 42.9%, compared to significantly lower rates among general employees, which stood at 25.6%. This striking difference raises questions about the effectiveness of security measures despite higher levels of knowledge among leadership.
2.
Discrepancy in Reporting Security Threats
- When faced with suspicious emails, a primary reason cited by 31.8% of employees for not reporting was that it felt too tedious. Executives, while reporting more often (66.1%), also indicated their busy schedules led to 'time constraints' or a 'lack of judgment criteria' when it came to recognizing threats.
3.
Limited Impact of Security Education
- A significant 57.0% of training participants reported no change in their actions post-education. Particularly, general employees exhibited a notable gap, as only 37.3% reported a change in behavior compared to 62.3% of executives. In fact, 19.1% of general employees said they hadn't changed at all.
Improving Security Training Methods
As the study reveals a critical need for change, employees expressed a desire for security training that is more relevant to their specific organizations. The top concerns included real-world scenarios and hands-on learning experiences that apply directly to their roles. Educational formats that resonate on a personal level could enhance engagement and improve overall effectiveness.
The Need for Practical and Actionable Education by 2026
Going forward, as cyber threats evolve with advancements in AI, simply providing knowledge is insufficient. The key for organizations will be to implement training that is tailored to employees' specific roles and to instill a culture of security awareness. This could include developing systems that lower the burden of reporting suspicious activities, thus encouraging intuitive behavioral changes among staff.
Survey Overview
- - Target Group: Men and women aged 20-69 working in various capacities, including executives and public sector employees.
- - Sample Size: 1,000 responses (with executive and employee breakdowns included).
- - Duration: Conducted from December 22-23, 2025.
- - Methodology: Internet survey.
About Securio
'‘Securio’ offers an easy-to-use cloud service for security education. By integrating simulated targeted email training with e-learning components and daily security awareness practices, it aims to foster behavioral change among employees efficiently.
About LRM Corporation
Established with a mission to advance information security awareness, LRM is dedicated to helping organizations build sustainable security measures and enhancing overall corporate value. With over 2,200 implementations of the Securio service and extensive consulting experience, LRM aims to be Japan's go-to information security company.
Explore more about Securio
here.