The Six-Week Amnesia Problem

“Education is what survives when what has been learned has been forgotten.” B. F. Skinner
When it comes to cyber awareness, almost every company holds mandatory annual security training sessions, where employees sit through forty-five minutes of slides about phishing, red flags, and password security. They nod in the right places, before flying out into their hectic daily lives again, perhaps feeling briefly virtuous. However, three months later, someone in Finance receives an email that appears to be from the CFO and clicks on it. This isn’t because they weren’t paying attention in March; by June, most of what they learned has simply disappeared.
And, before you sigh and decide to stop reading this article: this is not a story about careless employees. This story is focused on memory, and more specifically, about a piece of psychology that is well over a century old, and was recently re-confirmed almost exactly as first described, and that most corporate training programmes still design their entire calendar around ignoring.
The oldest experiment in forgetting
From 1880 to 1885, German psychologist Hermann Ebbinghaus ran a series of experiments on himself, testing his memory. He wanted to determine how quickly he lost information he had just learned, and what he found, and has been replicated repeatedly since, is that forgetting is not a slow, steady drip. It’s steep and immediate.
Most of what a person learns in a single sitting is forgotten within hours, and from there, the rate just levels off. So, whatever survives the first day tends to stick around considerably longer. In 2015, researchers Murre and Dros ran as close a replication of Ebbinghaus’s original method with modern science, and in a different language. More than a century after Ebbinghaus’ tests, they found a curve strikingly similar in shape to his. This is a rare occurrence in psychology: the fact that a result from the 1880s can hold up under direct replication in the 2010s.
So, what details matter when designing training? It’s not the percentage lost in the first hour. Especially considering that researchers still debate the precise numbers, and Ebbinghaus’s own data came from memorising meaningless syllables. It’s sufficient to say: about as unforgiving a test of memory as exists. What in fact matters is the shape of the curve left. New information fades fast and early, and the only thing that changes that trajectory is deliberately revisiting the material before it has fully gone. This resets the curve and makes the next decline slower. So, what happens if the window is missed? Then you aren’t reinforcing memory anymore. You are teaching it from scratch.
Why this is a worse problem in cyber than almost anywhere else
Most corporate training (cybersecurity awareness included) is still built on an annual, or at best quarterly, cadence. One long session, then silence until the next scheduled one, or if someone clicks a link, and they need to sit through the training again (in most cases, as “punishment”). Now, looking at this against the forgetting curve, one could hypothesise that is close to the worst possible design. The information is delivered once, allowed to decay fully, and then delivered again from zero, with no compounding benefit from one session to the next.
The data backs this up plainly.
A 2025 peer-reviewed study by Ussher-Eke found that it is important for organisations to move away from a one-size-fits-all annual awareness format. And focus more on a dynamic and ongoing approach if training is meant to change behaviour, rather than tick a compliance box. And on the front line? The effect shows up in real incident data! According to the Verizon 2025 Data Breach Investigations Report, employee reporting of suspicious emails increased fourfold at organisations that had run recent phishing simulation training, compared with those that had not. Read that again: not annual training… recent training.
The fix has a name, and it is not more training
So, would the fix to the forgetting curve be longer sessions or denser slide decks? Most certainly not. It’s more about spacing and retrieval. Kang’s 2016 review of the spacing effect found that distributing practice over time consistently produced stronger long-term retention rather than concentrating it into one sitting, even when the total time spent learning was identical. Roediger and Karpicke‘s influential 2006 research paper on retrieval practice found that actively testing yourself on material, rather than simply re-reading or re-watching it, produced measurably better long-term recall. When we mesh those two findings together, the prescription for security awareness writes itself: short, frequent touchpoints that require someone to recall or apply what they learned, spaced out over months, will outperform one long annual lecture every time, for the same or less total investment of hours.
This is the same logic behind why a five-minute simulated phishing email dropped into someone’s inbox unannounced does more for real world resilience than an hour of slides about phishing ever could. It forces retrieval, at an unpredictable interval, under conditions that resemble the real thing. That is not a training gimmick. It is spacing and retrieval practice, applied.
Then AI changed the shelf life of what you learned
OK, so here is where this tops being a “purely academic memory problem” and becomes an urgent one for anyone working in digital resilience. The forgetting curve assumes that the material you learned stays true even while it fades. In cybersecurity, right now, that’s no longer the case. Generative AI has made social engineering faster to produce, more personalised, and considerably harder to fingerprint by the generic red flags that used to give it away. The clumsy grammar, mismatched tone, and obviously wrong sender name. A phishing email built with AI assistance today can mirror a specific colleague’s writing style, reference a real, ongoing project, and arrive with none of the tells that last year’s awareness training taught people to look for.
So, what does this have to do with anything? Well, it means the forgetting curve and the threat landscape are now decaying in the same direction, at the same time, and compounding each other. Not only is the memory of March’s training fading by June, but the specific tactics March’s training also described may simply no longer be the tactics in circulation by June!
An annual training model that already badly matches how memory decays is now also badly matched to how quickly the threat itself moves. This means that spaced, frequent, and retrieval-based training is not just the better pedagogical choice anymore, but the only realistic way to keep pace with content that must be refreshed as often as the memory of it needs reinforcing.
What this means in practice
Before you start getting nervous and wanting to redo a completely new strategy mid-year and overhaul your entire learning and development budget. Rather, redirect into a different direction: a single long annual session, split into six or eight short ones spread across the year. With each session requiring an active recall, rather than passive viewing, and each one incorporating current attack patterns, rather than a static slide deck built once and reused for three years. This will do much more for actual behaviour change than the original format ever did, often for a comparable total time investment.
The uncomfortable truth underneath all of this is that forgetting is not a failure of attention, motivation, or character. It is just what our brains do by default. Training programmes that are designed as if forgetting is an occasional lapse, rather than the predictable, well-documented, default outcome, are training programmes designed to fail on schedule. The fix is not to blame the person who clicked in June for forgetting March. It is to stop asking memory to do something it was never going to do unassisted.
Building training that outlives the forgetting curve
Everything we’ve covered above points to the same design principle: retention is not a byproduct of good intentions; it is a byproduct of good structure. That is the reason we did not build Cyber Dexterity around a single annual session. Our self-paced, behaviour-focused microlearning exists because spacing must be engineered into delivery, not left to whoever remembers to book a refresher six months later. Our Hack to Protect gamified scenarios exists because retrieval practice needs a low-stakes environment where getting it wrong safely is what makes the lesson stick, not a slide deck that gets watched once and never tested again. Our masterclasses are built as recurring, expert-led touchpoints rather than a single annual event, and our consulting and advisory work exists specifically to help organisations design that cadence deliberately, rather than default to whatever the compliance calendar has always done.
None of that is a workaround for how memory behaves. It is what the psychology of learning requires, which is why we built the model this way from the outset rather than retrofitting it after the fact.
Taryn-Lee Potgieter – Head of Brand Growth