The short answer: Ideally, training should be continuous. At a minimum, organizations should conduct formal training annually, but supplement it with monthly updates to be effective.
The Forgetting Curve
Why Annual Training Fails
Recommended Cadence
1Onboarding
Day 1-30. Comprehensive training on policies and tools.
2Monthly
Micro-learning (2-5 mins) on specific topics like 'Holiday Scams'.
3Simulations
Monthly phishing tests. The sweet spot for vigilance without fatigue.
4Annually
Formal refresher course dealing with compliance updates.
5Ad-Hoc
Just-in-Time training triggered immediately after a user fails a test.
