When it comes to protecting a company, most executives think first about buying a stronger antivirus, firewall, or monitoring system. The logic feels intuitive: technology feels like a controllable investment, while training people feels vague and hard to measure. In practice, it’s the other way around.
The numbers don’t leave much room for debate
According to Verizon’s Data Breach Investigations Report, the human element is involved in 62–68% of all breaches. That means even the most expensive technology only protects part of the perimeter — the most common entry point for an attack stays unprotected unless it’s addressed separately.
You can install a flawless antivirus and still lose company data because an employee opened a file disguised as a photo, or wired money based on a fake email “from the director.”
Why technology alone doesn’t solve this
Antivirus software, firewalls, and monitoring systems work against known threats and suspicious network activity. But most modern attacks don’t technically “break through” security — they convince a person to take the action themselves: click a link, enter a password, send a payment. Purely technical defenses can’t stop that.
Why training pays off faster
- Training costs an order of magnitude less than investigating a serious incident, absorbing reputational damage, and potential regulatory fines
- One trained employee who catches a suspicious email in time can prevent an incident that could otherwise cost a company hundreds of thousands of som
- Training directly reduces exposure to the fastest-growing threats: AI-assisted phishing, deepfake calls, and messenger-based scams
- Unlike technology, which needs regular updates and repurchasing, a trained employee is an asset that keeps working for the company continuously
What makes training actually effective
A single annual training session barely moves the needle — research shows the percentage of employees who fall for phishing barely changes after a one-off course. What works instead:
- Short, regular reviews of real cases — quarterly sessions beat one long annual course
- Test phishing campaigns that reveal a team’s actual readiness, not an assumed one
- Training that extends beyond IT — finance, HR, and sales teams handle money and data too
- A “train and retain” model — the 2026 global trend of building internal training as an ongoing process rather than a one-time event
The regulatory context
In Kyrgyzstan, this isn’t just common sense — it’s a matter of legal accountability. Under Law No. 58 “On Information of a Personal Nature,” companies are required to protect customer and employee data, with real fines in effect since November 2025. If an incident happens because of an untrained employee, the company is still liable — and increasingly, so is its leadership personally.
Employee training isn’t a one-time expense — it’s part of how a company operates, and it either continuously reduces risk or quietly lets it accumulate until the first serious incident.