Fortinet 2025 Report: The high cost of the security training completion gap

According to the Fortinet 2025 Security Awareness and Training Global Research Report, based on insights from 1,850 leaders across 29 countries (including India), the "human element" is now the ultimate pivot point for cyber resilience.
The AI paradox: awareness high, readiness low
In 2026, AI is a double-edged sword. Nearly 90% of organisations admit that AI-powered attacks have actually helped employees understand why training matters. People are seeing the deepfakes and the hyper-personalised phishing emails and getting nervous.
However, awareness doesn't equal ability. Only 40% of leaders feel their teams are actually ready to identify and report these AI-based threats. While most companies are rushing to implement "GenAI policies," there is a massive gap in execution. The takeaway? You can have a policy, but if your employees don't know how to use it in the heat of a "vishing" (voice phishing) attack, the policy is just paper.
The shift: Insider risk is rising fast
For years, we’ve been told the "bad guys" are outside the building. While external threats still drive 40% of training adoption, insider risk is the new sleeper hit. Over a quarter of organisations now cite internal threats as a primary reason for upgrading their training.
This isn't just about "bad actors" inside the company; it's about accidental errors, employees sharing sensitive data with LLMs or ignoring security protocols to get work done faster.
Proof in the numbers: It actually works
For those sceptical about the ROI of training, the data is undeniable: 67% of organisations reported a significant drop in breaches and incidents after implementing formal training.
But there’s a catch. The report highlights that completion rates and consistency are the Achilles' heel of the modern program. If only half the team finishes the training, the entire network remains vulnerable. The industry is now moving toward "micro-training", short, frequent bursts of learning that keep up with the breakneck speed of AI.
India’s role: Building a cyber-aware culture
Vishak Raman, Vice President of Sales (India, SAARC, SEA & ANZ) at Fortinet, emphasises that as India scales its digital infrastructure through the cloud and AI, the "human element" remains the first line of defence.
"Security awareness is becoming cultural, not just procedural," the report notes. It’s no longer about passing a test; it’s about shaping the daily decisions of every employee, from the intern to the CEO.
Conclusion
In 2026, a "one-and-done" yearly security video is a recipe for disaster. To safeguard the future, training must be continuous, AI-focused, and treated as a core risk management control. As Vishak Raman puts it, equipping employees to recognise and respond to threats is the only way to safeguard India’s digital future.
Read More:
Why rising DDR RAM prices and chip shortages may push PC costs up
Middle East conflict raises supply chain alarm for India’s IT hardware exports
Apple experiential store in India: iNvent’s strategy explained






