The US Army has reduced the frequency of mandatory cybersecurity training from once a year to once every five years

https://defensescoop.com/2026/03/31/army-cybersecurity-training-policy-change/

Commanders now responsible for cybersecurity training after Army cuts online course requirement to once every 5 years

Commanders are now responsible for preparing their soldiers and civilians on cybersecurity, according to a senior service official who said the change was intended to give unit leaders more flexibility.

DefenseScoop
@campuscodi In fairness...

@cR0w @campuscodi No kidding. We’ve known for over a decade that more frequent training doesn’t improve outcomes. It’s reasonable to look at how much less frequent we can make it before outcomes suffer.

Feels like how password expiration was just made up as a starting point for further discussion, then it got carted around verbatim for decades.