A security manager receives confirmation that 96 per cent of staff have completed mandatory training.

The report is tidy, the audit trail is complete and the organisation appears prepared. Then an incident, suspicious behaviour or difficult evacuation decision exposes the void.

People have seen the material, but they cannot recognise what matters, decide what to do or communicate clearly under pressure.

That is why ‘why does security training fail’ is the wrong question if it is treated as a question about course quality alone. Training fails when it is designed to prove attendance rather than improve performance.

A certificate records completion. It does not demonstrate judgement, confidence or operational capability.

Why security training fails

Security work is context dependent.

The right response in a busy retail site, a corporate reception, a transport setting or a major event venue will not look identical. Roles, layouts, customer expectations, reporting routes and available resources all shape the decision. Generic learning can establish a baseline, but it cannot substitute for applying that knowledge in the environment where people work.

Many organisations stop at awareness. Staff are told to remain vigilant, report concerns and follow procedures. These are sensible messages, but they are not enough on their own. Someone who has been instructed to report suspicious activity may still hesitate because they do not know what a useful report sounds like, who is responsible at that moment or whether they are overreacting.

Hesitation is often mistaken for apathy. More commonly, it is uncertainty. People do not want to disrupt operations, accuse an innocent person or make themselves look foolish. If training has not dealt with those practical tensions, it has not prepared them for the decision that matters.

The same applies to supervisors and managers. They may understand a policy but lack confidence in how to assess incomplete information, coordinate a response or make proportionate decisions while protecting business continuity. Reading a procedure is not rehearsal.

It rarely reveals where the procedure is unclear, impractical or dependent on a person who is not available outside normal hours.

Completion data creates false confidence

Completion rates are easy to measure, which is why they dominate training conversations.

They answer an administrative question, who has accessed and finished the assigned material? They do not answer the operational questions.

Can a front of house colleague identify a concern that warrants escalation? Can a duty manager make a sound initial decision without waiting for perfect information? Can the control room, site team and senior leader share a common picture quickly? Can staff explain what they saw without adding assumptions?

An organisation can achieve full compliance and still be poorly prepared. This is uncomfortable because it challenges a familiar assurance model. Boards, regulators and clients understandably want evidence, and records have a place. Yet a record should be the starting point for assurance, not the end of it.

This matters particularly as organisations consider their protective security responsibilities under Martyn’s Law. The practical test is not whether a learning module was assigned.

It is whether the people responsible can carry out their role when the situation is confusing, time is limited and normal routines have broken down.

Training is often detached from the job

Off the shelf eLearning has value. It can give large, dispersed workforces consistent access to core knowledge and can be refreshed efficiently. It is especially useful where staff need a clear introduction to threat awareness, reporting principles or their responsibilities.

Its limitation is equally clear. Passive content asks learners to recognise the right answer on a screen. Operational reality asks them to notice weak signals, assess relevance and act in a live setting with competing demands. Those are different tasks.

A short course about suspicious behaviour may explain indicators well. It becomes more useful when staff consider what those indicators might look like at their own entrance, loading area, service desk or public space. They need to discuss what they would report, how they would preserve accuracy and what happens after the report is made. Without this local connection, learning remains abstract.

Training also fails when it ignores the authority of the learner. Junior staff may be closest to the concern but feel they have no permission to intervene, challenge or escalate. A manager may be expected to lead a response without being clear about their decision rights.

No amount of polished content will solve an unclear operating model.

Knowledge decays when it is not used

Security training is frequently delivered as an annual event. It competes with other mandatory subjects, is completed quickly and then disappears for another year. That rhythm makes sense for administration. It does not reflect how people retain and use skills.

Capability needs reinforcement. The most effective organisations create short, relevant opportunities to revisit key decisions. A team briefing can test how staff would report a concern. A supervisor can work through a recent operational issue and ask what information would have improved the response. A simple scenario can reveal whether contact details, escalation routes and responsibilities are understood.

The purpose is not to catch people out. It is to make security decisions familiar before they become urgent. Repetition, feedback and discussion are what convert information into usable judgement.

This is also where assessments have greater value than many organisations realise. A well designed capability assessment does more than produce a score. It identifies where understanding is weak, where confidence exceeds competence and where development should be targeted. Immediate, meaningful feedback gives the learner a reason to improve, rather than simply a result to file away.

Poor design asks too much of the learner

Some security training is burdened with too much information.

It covers legislation, terminology, procedures, threat categories and case studies, often in a single sitting. Learners finish with broad exposure but limited recall. The issue is not that the content is inaccurate. It is that it does not distinguish between knowledge people must remember, knowledge they need to know exists and information they can retrieve when required.

Good training is selective. It focuses on the decisions each role is likely to face and the consequences of getting them wrong. A receptionist, a project manager, a security officer and a senior responsible person do not need identical depth. They need a shared foundation, then role relevant development.

This means accepting a trade off. Bespoke training takes more effort than simply purchasing a standard package. It requires honest discussion about local risks, operating realities and weak points.

But the result is more likely to alter behaviour. For many organisations, the sensible approach is a strong common baseline supported by targeted exercises, manager briefings and role specific evaluation.

Build capability, not a training library

The first step is to define the performance required.

Avoid vague aims such as raising awareness. Be precise. Who needs to notice what, decide what and communicate with whom? What would good performance look like on a normal shift, during a busy period and when a key decision maker is unavailable?

Then test the existing position. Speak to the people who carry responsibility, not only those who own the learning platform. Ask staff to explain an escalation route in their own words. Present a realistic but non-sensitive scenario and listen to how they reason. Review whether managers can distinguish a routine issue from one requiring wider coordination.

These conversations often reveal more than completion reports.

Use the findings to create a development cycle. Give people concise learning that explains the principle. Let them apply it to their work. Assess their understanding and decision making. Provide feedback, then revisit the issue later. Where a weakness has serious consequences, include facilitated practice with the relevant teams.

Leaders have a particular responsibility here. If they treat security learning as a box to tick, their teams will do the same. If they ask practical questions, make time for discussion and respond constructively to reporting, they make good security behaviour part of normal operations.

Mildot Group’s experience is that the strongest programmes do not attempt to turn every employee into a security specialist. They make each person more capable in their own role, while ensuring specialists, managers and decision makers can perform at the level their responsibilities demand.

The useful question is not whether your people have been trained. It is whether they could make a sound decision tomorrow, in their actual workplace, when the situation does not match the slide deck.

.

Useful Links:

.

Why Mildot Group?

Built on Experience. Focused on Capability.

Mildot Group helps individuals and organisations build practical capability through professional learning, capability evaluations, premium publications and specialist consultancy. Every solution is designed to bridge the gap between theory and practical application, helping people and organisations perform with greater confidence in real-world environments.

Our Mission

Our mission is to help individuals and organisations build practical capability through professional learning, capability evaluations, expert guidance and real-world application. Everything we create is designed to bridge the gap between theory and practice, helping people make better decisions, strengthen resilience and perform with confidence.

Our Philosophy

We believe capability is developed through structured learning, practical application and continuous improvement, not simply by completing a course or meeting a compliance requirement. Every learning programme, capability evaluation, publication and consultancy engagement is designed to help individuals and organisations apply knowledge with confidence in real-world environments.

What Makes Mildot Group Different?

Real Operational Experience
Built on experience gained across military, corporate and international environments.

Practical Learning
Professional learning designed to develop skills that can be applied immediately.

Capability Focused
Building practical capability rather than simply delivering awareness or compliance.

Evidence-Based
Combining operational experience with research, proven frameworks and practical methods.

Individuals & Organisations
Supporting personal development, professional capability and organisational performance.

Continuous Development
A growing platform with new learning programmes, evaluations and professional publications added regularly.

Privacy Preference Center