Opinion: Most Corporate Compliance Training Isn't Training and Doesn't Work
Recently, I read a news report about a study that concluded that cybersecurity training doesn’t work. I can’t say that I’m surprised by that.
I spend a lot of time mentoring on client sites, and many of the clients are large organizations. Often these organizations require me to attend “training” on a regular basis, to satisfy their corporate compliance goals.
I don’t mind doing this at all, even though it’s incredibly repetitive. The course on conflicts of interest, or handling private or sensitive data, or IT security at company A is invariably almost word for word the equivalent course that I do at company B, and company C.
2025-12-04