94% of EMEA Organizations Say Employee Awareness Reduces Cyberattacks - But Two-Thirds Still Have a Training Gap
New research across 500 EMEA security leaders finds 94% believe stronger employee awareness directly reduces cyber incidents. Yet 67% say their workforce still lacks sufficient cybersecurity knowledge. For Gulf enterprises, the human layer remains the most underdeveloped defense.

Enterprise cybersecurity awareness training in the Gulf. Fortinet 2025 EMEA research highlights employee security culture gaps in Saudi Arabia and the wider region
Enterprise cybersecurity investment across the Gulf has grown substantially over recent years in infrastructure, tooling, and regulatory compliance. But a consistent gap persists in the layer that sits between every technology control and every actual breach: the people who use those systems every day.
New research from Fortinet's Security Awareness and Training 2025 Global Research Survey drawing on responses from 500 senior IT and cybersecurity decision-makers across the EMEA region puts hard numbers on a challenge that security leaders in Saudi Arabia and across the GCC have been grappling with for years. The headline finding is both encouraging and sobering in equal measure: 94% of organizations believe stronger employee cybersecurity awareness would directly reduce cyber incidents yet 67% say their employees still lack sufficient knowledge to act on that awareness consistently.
That gap between recognition and reality is where breaches happen.
AI Is Changing the Urgency Calculation
The research was conducted across 2025, and its findings land in a 2026 threat environment that has shifted meaningfully since the data was gathered. 81% of surveyed organizations say AI-driven attacks have increased the perceived importance of cybersecurity awareness training and the attacks that were AI-assisted in 2025 are more sophisticated and more automated in 2026.
AI-generated phishing emails, deepfake voice scams, and automated social engineering campaigns are no longer emerging threats they are operational tools being used against Gulf enterprises right now. As highlighted in recent KPMG analysis, Saudi Arabia alone accounted for approximately 63% of cyber incidents across the Middle East in 2025, with phishing rising 22.5% in a single quarter. The human layer employees who click links, share credentials, and interact with AI-generated deception remains the most exploited entry point.
Progress Is Real, But Incomplete
The research does capture genuine progress. 65% of organizations report moderate to significant reductions in cyber incidents following the implementation of structured awareness programs. 94% report at least some improvement in their overall security posture after investing in training. These are not marginal returns they represent measurable risk reduction from a category of investment that is still significantly underfunded relative to its impact.
Phishing simulations remain the most widely deployed awareness tool, with 69% of organizations actively running simulation campaigns to test and strengthen employee readiness against real-world attacks. Structured training campaigns have been adopted by 76% of organizations, while 84% now deliver tailored training for specific employee groups a meaningful shift from the one-size-fits-all compliance training that characterized earlier approaches.
The Priorities Shaping Gulf Training Agendas
For organizations in Saudi Arabia and across the GCC, the research findings on training priorities are directly relevant to the Kingdom's regulatory and strategic agenda. Data security (49%) and data privacy (42%) rank as the top training priorities areas that align closely with Saudi Arabia's data sovereignty focus and the NCA's expanding compliance framework.
AI-related threats (38%) are emerging as a distinct training category reflecting the reality that employees now need to understand not just phishing and password hygiene, but the specific characteristics of AI-generated attacks: the absence of the spelling errors that once signaled fraud, the voice cloning that can impersonate a CFO convincingly enough to authorize a transfer, the automated reconnaissance that makes spear-phishing feel personal.
Half of organizations are now training employees on the responsible use of generative AI tools, while 51% have implemented controls to prevent sensitive information from being exposed through AI platforms a sign that the internal AI adoption risk is being taken as seriously as the external threat.
The Talent and Resource Constraint
The research also surfaces a challenge that is particularly acute across the Gulf's expanding digital economy: 28% of organizations that delayed implementing awareness programs cited personnel limitations as the primary barrier. Security awareness programs require dedicated internal ownership someone who builds the curriculum, runs the simulations, measures the outcomes, and updates the content as the threat landscape evolves.
For organizations scaling their digital operations under Vision 2030 mandates while simultaneously competing for scarce cybersecurity talent, this constraint is real. It points toward a growing role for managed security awareness services where the program design, delivery, and measurement is handled externally, allowing internal teams to focus on response rather than training administration.
What Security Leaders Should Take From This
Sami AlShwairakh, Regional VP for Saudi Arabia at Fortinet, framed the broader picture clearly: the Kingdom's strong regulatory foundations, local skills development focus, and infrastructure investment create the conditions for genuine cybersecurity leadership but technology investment alone is insufficient. Empowering employees through continuous cybersecurity education is the necessary complement to the infrastructure being built.
The data supports that position. Organizations that treat security awareness as a core risk management control continuous, relevant, and measurable are seeing real reductions in incidents. Those that treat it as an annual compliance checkbox are not.
For Gulf enterprises building their security programs in 2026, the research offers a straightforward directive: the human layer is not a soft problem. It is a quantifiable risk with a quantifiable return on investment and the organizations that close the 67% knowledge gap will be materially more resilient than those that do not.
Layla Haddad
Cyber Policy & Digital Risk CorrespondentLayla Haddad covers cybersecurity regulations, data protection laws, and digital transformation initiatives across GCC and North Africa. She has worked closely with compliance teams, fintech startups, and government advisory groups. Her articles explore how cyber policy, AI governance, and privacy frameworks shape the region’s digital future.