Fortinet 2025 Report: The high cost of the security training completion gap

DQChannels Bureau
DQChannels Bureau
Fortinet 2025 Report: The high cost of the security training completion gap

According to the Fortinet 2025 Security Awareness and Training Global Research Report, based on insights from 1,850 leaders across 29 countries (including India), the "human element" is now the ultimate pivot point for cyber resilience.

The AI paradox: awareness high, readiness low

In 2026, AI is a double-edged sword. Nearly 90% of organisations admit that AI-powered attacks have actually helped employees understand why training matters. People are seeing the deepfakes and the hyper-personalised phishing emails and getting nervous.

However, awareness doesn't equal ability. Only 40% of leaders feel their teams are actually ready to identify and report these AI-based threats. While most companies are rushing to implement "GenAI policies," there is a massive gap in execution. The takeaway? You can have a policy, but if your employees don't know how to use it in the heat of a "vishing" (voice phishing) attack, the policy is just paper.

The shift: Insider risk is rising fast

For years, we’ve been told the "bad guys" are outside the building. While external threats still drive 40% of training adoption, insider risk is the new sleeper hit. Over a quarter of organisations now cite internal threats as a primary reason for upgrading their training.

This isn't just about "bad actors" inside the company; it's about accidental errors, employees sharing sensitive data with LLMs or ignoring security protocols to get work done faster.

Proof in the numbers: It actually works

For those sceptical about the ROI of training, the data is undeniable: 67% of organisations reported a significant drop in breaches and incidents after implementing formal training.

But there’s a catch. The report highlights that completion rates and consistency are the Achilles' heel of the modern program. If only half the team finishes the training, the entire network remains vulnerable. The industry is now moving toward "micro-training", short, frequent bursts of learning that keep up with the breakneck speed of AI.

India’s role: Building a cyber-aware culture

Vishak Raman, Vice President of Sales (India, SAARC, SEA & ANZ) at Fortinet, emphasises that as India scales its digital infrastructure through the cloud and AI, the "human element" remains the first line of defence.

"Security awareness is becoming cultural, not just procedural," the report notes. It’s no longer about passing a test; it’s about shaping the daily decisions of every employee, from the intern to the CEO.

Conclusion

In 2026, a "one-and-done" yearly security video is a recipe for disaster. To safeguard the future, training must be continuous, AI-focused, and treated as a core risk management control. As Vishak Raman puts it, equipping employees to recognise and respond to threats is the only way to safeguard India’s digital future.

Read More:

Why rising DDR RAM prices and chip shortages may push PC costs up

Middle East conflict raises supply chain alarm for India’s IT hardware exports

Apple experiential store in India: iNvent’s strategy explained

AI PCs and the channel shift: Hype to reality

Latest Stories