In one study sample, approximately 40% of participants reported receiving no cybersecurity training. That result deserves attention, but it must remain inside the boundaries of the study.
A finding worth examining
The finding appeared in Cybersecurity Challenge Analysis of Work-from-Anywhere (WFA) and Recommendations Guided by a User Study, by Mohammed Mahyoub, Ashraf Matrawy, Kamal Isleem and Olakunle Ibitoye.
The paper’s abstract reports 45 responses from people working remotely during the COVID-19 pandemic. Participants came from university, government, private-sector and non-profit settings. The author-posted paper says the online survey ran from March through June 2022 and that most participants were working and residing in Canada.
Those boundaries matter. The result should not be extended to all Canadian workers, every organization or the present day. Its value is as a prompt to examine an organization’s own learning programme and evidence.
Dr. Mohammed Mahyoub, ByteDefender’s founder, co-authored the research. The paper was published by IEEE in IEEE Transactions on Human-Machine Systems. ByteDefender did not publish the academic paper.
The more useful organizational question
The study finding should prompt inquiry, not a sweeping conclusion: are people being given the knowledge and support they need to make secure decisions while working remotely or across locations?
“Training provided” is only the first part of that review. A course can exist without covering the situations a particular role faces. A person can complete a module yet remain unsure where to report an unusual event. A policy can state an expectation while the surrounding workflow makes the expected action difficult.
A useful review therefore looks at the complete path from learning to action:
- What security-sensitive decisions does the person encounter?
- What action does the organization expect?
- Has the person had a realistic opportunity to practise that action?
- Is help easy to reach at the moment of uncertainty?
- What evidence will show whether the programme needs to change?
This framing does not treat employees as a control to be “fixed.” It treats learning, workflow design, management support and technical safeguards as connected parts of the same system.
From an event to a learning programme
NIST Special Publication 800-50 Revision 1, finalized in September 2024, describes a lifecycle approach to cybersecurity and privacy learning. It is designed for federal agencies and organizations, and its recommendations are customizable for organizations of different sizes. The guidance connects learning with behaviour change, risk management, security and privacy culture, metrics, evaluation and ongoing improvement.
NIST guidance is not a finding from the remote-work study, and it is not presented here as a Canadian legal requirement. It provides a current, primary-source framework that helps translate the study’s question into programme design.
The practical implication is that awareness should not be reduced to an annual content-delivery event. Organizations can identify needs, design learning for relevant audiences, implement it with usable support, evaluate multiple signals and revise the programme as roles, technology and risks change.
A five-point security-learning review
The following is ByteDefender’s practical synthesis of the study question and NIST’s lifecycle guidance. It is not a checklist reproduced from either source.
-
Identify the decisions that matter
Choose one role and list three recurring situations in which a decision could affect security. For a remote worker, these might involve an unexpected access request, sharing information through an unfamiliar channel, using a new collaboration tool, handling a suspicious message or reporting unusual device behaviour. Keep the list specific to the organization’s systems and approved processes. -
Define the expected action and support route
For each situation, write the action the person should take, what they should avoid, and where they can obtain help. Check whether the reporting route is visible, accessible and staffed. If the safe action depends on a process that employees cannot readily use, training alone will not resolve the gap. -
Make learning relevant and practicable
Use scenarios that reflect the audience’s role, access and work environment. Give people a low-risk way to practise recognition, decision-making and reporting. Explain why an action matters without relying on fear. Reinforce the lesson when a workflow, threat pattern, policy or system changes. -
Evaluate more than completion
Completion data shows who finished an assigned activity; it does not by itself show how someone will respond in context. Select several proportionate signals, such as scenario decisions, the quality and timeliness of reports, recurring requests for help, knowledge checks and feedback about confusing processes. Use the results to find design problems, not to shame individuals. -
Review and improve the programme
Assign an owner, establish a review rhythm and record what changes. Revisit learning after material incidents, technology changes, new work arrangements or evidence that people are struggling with a process. Preserve what is working, improve what is unclear and retire content that no longer reflects the environment.
What the finding does not establish
The study does not:
- Establish a current Canada-wide prevalence rate
- Represent every sector or organization size
- Prove that training alone changes behaviour
- Measure the effectiveness of every programme represented in the sample
- Establish cause and effect
It offers a bounded signal and a reason to examine an organization’s own evidence.
Start with one role
Select one role, one remote or hybrid workflow and one security-sensitive decision. Walk through the five questions with the people who perform and support that work. The result should be a small, concrete improvement list—not a judgement about employees.
Primary sources
- Mahyoub, M., Matrawy, A., Isleem, K., and Ibitoye, O. Cybersecurity Challenge Analysis of Work-from-Anywhere (WFA) and Recommendations Guided by a User Study, IEEE Transactions on Human-Machine Systems. Author-posted paper.
- Merritt, M., Hansche, S., Ellis, B., Sanchez-Cherry, K., Snyder, J. N., and Walden, D. Building a Cybersecurity and Privacy Learning Program, NIST SP 800-50 Rev. 1, final, September 2024.
Sources reviewed August 12, 2026. The study’s sample boundaries and paper-version discrepancy were retained deliberately.
Connect learning with real work
If your organization is reviewing how security learning connects with roles, workflows and practical decisions, explore ByteDefender’s training services.
Review Training Services