BLOG

How to measure the effectiveness of security awareness training (metrics and KPIs)

Jul 31, 2026

Measure security awareness training by tracking behaviour, not completion. The core metrics are the phishing click rate, which should fall, and the reporting rate, which should rise, both measured against a baseline. Add time to report, repeat clickers and module completion, then show the trend over time to prove falling risk and return on investment.

If you cannot measure your security awareness training, you cannot prove it works, improve it or justify its budget. Yet many organisations track only completion, which says nothing about whether behaviour has changed. This guide sets out the metrics and KPIs that actually matter, how to capture them and how to turn them into a clear story of reduced risk for your leadership team.

Why does measuring security awareness training matter?

Measurement turns training from an act of faith into a managed control. It tells you whether your people are getting safer, where the remaining risk sits and whether your investment is paying off. It also gives you the evidence leadership, auditors and cyber insurers increasingly demand. The starting point is a baseline. Boxphish analysis of more than 400,000 platform users found that untrained users are 8.8 times more likely to click a phishing email than trained users, so your first measurement, taken before training begins, sets the line against which every later improvement is judged. Without that baseline, you have numbers but no story.

What are the key security awareness training metrics?

A handful of metrics carry most of the value. The phishing click rate is how many people clicked a simulated malicious email, and it is your headline measure of exposure. The reporting rate is how many people actively reported the suspicious email, and it measures vigilance. Time to report captures how quickly the first report arrives, because speed is what lets the security team contain a real attack. Repeat clickers identify the minority who fall for multiple simulations and need targeted help. Module completion still matters as a hygiene check, but it should never be mistaken for effectiveness. Tracked together, these metrics describe both the risk and the culture.

How do you measure the phishing click rate?

The phishing click rate comes from running realistic phishing simulations and recording how many recipients clicked the link or opened the attachment. To be meaningful it needs to be measured consistently and repeatedly, with varied scenarios so people cannot simply learn one template. Track it by team and by role as well as across the whole organisation, because an average can hide a high risk pocket such as a finance team being heavily targeted. Watched over months, a falling click rate is the single clearest sign that training is working.

What is a good phishing click rate?

There is no universal pass mark, because rates vary by sector, by the difficulty of the simulation and by how the campaign is run. What matters far more than any benchmark is the direction of travel. A click rate that falls steadily over successive campaigns shows behaviour changing, while a flat or rising rate signals that the programme needs attention. Treat your own baseline as the benchmark and aim to beat it, rather than chasing a headline figure from a different organisation facing different threats.

How do you measure the reporting rate?

The reporting rate is the percentage of recipients who report a suspicious email, and it is the metric many programmes overlook. It deserves equal billing with the click rate, because an organisation where people click less and report more has genuinely shifted its culture. Make reporting effortless, for example through one click in-inbox reporting, then track how the rate climbs over time. A high reporting rate is also an operational asset, since every report is an early warning that helps contain a real attack before it spreads.

How do you demonstrate ROI to leadership?

Leaders think in risk and money, so translate your metrics into both. Show the click rate falling from its baseline and express it as reduced likelihood of a successful phishing attack, then connect that to the avoided cost of ransomware, fraud, downtime and regulatory penalties. Pair the falling click rate with the rising reporting rate to show a workforce that is both less likely to fall for an attack and more likely to catch one. Presented as a simple trend over time, this is a far more persuasive case than completion percentages, and it positions the programme as part of human risk management rather than a training cost.

How does measurement support compliance and cyber insurance?

Good measurement produces exactly the evidence regulators and insurers ask for. A documented baseline, a record of regular training and simulations and a clear trend of improving metrics demonstrate that the organisation is actively managing human risk, not just claiming to. Cyber insurers increasingly expect this evidence before offering cover or settling a claim, and frameworks such as Cyber Essentials and the expectations set out in NCSC guidance assume ongoing staff education. A measured programme makes renewal conversations and audits markedly easier.

What are the common measurement mistakes?

The most common mistake is measuring completion and calling it effectiveness, which tells you people clicked through a module but nothing about behaviour. The second is running a single simulation and treating it as a verdict, when only a trend over time is meaningful. The third is reporting one organisation wide average that hides high risk teams. The fourth is ignoring the reporting rate and watching only clicks, which misses half the picture. And the fifth is punishing clickers, which suppresses reporting and corrupts the very data you are trying to collect. Avoid these and your numbers will reflect reality.

How do you build a measurement dashboard?

A useful dashboard brings the key metrics together in one view and shows movement over time. Include the click rate and reporting rate trended against the baseline, a breakdown by team or department, repeat clicker counts and completion as a secondary hygiene measure. The aim is a single, glanceable picture that answers the question leadership actually asks: is our human risk going up or down? Boxphish provides this reporting out of the box and integrates with Microsoft 365, so the data is captured automatically rather than assembled by hand.

How do you turn measurement into action?

Metrics are only useful if they change what you do next. The point of measuring is to create a feedback loop, not a report that gets filed. When the click rate in a particular team stays stubbornly high, that is a signal to increase the cadence of training and tailor the simulations to the threats that team actually faces. When a small group of repeat clickers emerges, they need targeted, supportive coaching rather than another generic module. When the reporting rate plateaus, it may be time to make reporting easier or to remind people what to do with a suspicious email. Each metric points to a specific intervention.

This is the Measure stage of the Assess, Educate, Reinforce and Measure cycle, and it feeds directly back into the next round of education. The organisations that get the most from measurement review their numbers on a regular monthly or quarterly rhythm, decide one or two concrete actions each time and check at the next review whether those actions moved the needle. Over a year, that disciplined loop compounds into a substantial reduction in human risk, and it produces a clear narrative of continuous improvement that leadership and insurers find genuinely reassuring. Measurement without action is just reporting, while measurement that drives the next decision is what makes a programme steadily better.

Frequently asked questions

How do you measure the effectiveness of security awareness training?

Measure effectiveness by tracking behaviour against a baseline. The headline metrics are the phishing click rate, which should fall, and the reporting rate, which should rise. Add time to report, repeat clickers and completion, then judge effectiveness by the trend over time rather than any single result.

What are the most important security awareness training KPIs?

The phishing click rate and the reporting rate are the two most important, because together they show whether people are less likely to fall for an attack and more likely to catch one. Time to report and repeat clicker counts add useful depth.

What is a good phishing simulation click rate?

There is no universal figure, because it varies by sector and simulation difficulty. What matters is the direction: a click rate falling from your own baseline over successive campaigns is the clearest sign of progress, far more telling than any external benchmark.

How do you prove training ROI to leadership?

Translate metrics into risk and cost by showing the click rate falling and the reporting rate rising over time, then connecting that to the reduced likelihood and avoided cost of a successful attack. A clear trend is far more persuasive than completion rates.

Measure what matters with Boxphish

Boxphish captures every metric this guide describes automatically: click rates, reporting rates, repeat clickers and completion, all trended against your baseline and broken down by team. Integrated with Microsoft 365 and aligned to NCSC guidance, it gives busy IT and security teams the evidence to improve the programme and prove its value.

To establish your baseline and see the reporting in action, book a Boxphish demo and start with a phishing simulation. The first set of numbers will show you exactly where you stand.

Ready to transform your cyber culture? Book a demo today!

Latest insights

Employees using cyber awareness training

Aug 11, 2026

How to get employees to engage with security training

Aug 14, 2026

Your checklist for the 2026 Cyber Security Breaches Survey

Aug 14, 2026

Your guide to the 2026 Cyber Security Breaches Survey