Conclusion: The threat of a data breach (unauthorised access to data) is not just from hackers, and not just as a result of malicious intent. Carelessness and oversight by trusted inside sources has been shown, repeatedly, to be the root cause of numerous data breaches. Recognising this, many organisations (particularly in government and finance) include security awareness training as part of an employee's induction.
But this one-time security awareness training is easily lost in the information overload experienced by new starters. Security awareness training is vital but in order to realise the benefits, and prevent the acts of carelessness, it is even more important to repeatedly expose employees to the training to keep their level of security awareness elevated. Elevated security awareness helps create the human firewall: probably the most cost effective security resource you can get.