All resources
Practical guide

How to measure a security awareness programme

Use clear denominators, comparable exercises and follow-up records to explain what your training results do and do not show.

Go to checklist

Keep the measurement question narrow

Ask whether people are practising the intended action, whether reports reach the right team and whether follow-up happens. A completed course is evidence of participation, not proof that incidents cannot occur.

Avoid combining several percentages into a risk score unless you can explain the model, inputs and limitations. Keep operational measurements visible alongside any summary score.

Use a consistent definition for each measure

The definitions below are a suggested reporting template. Confirm how your own tools count delivery, interaction and reporting before comparing their exports.

  • Completion rate: people who completed the assigned activity divided by people assigned, for the same reporting window.
  • Simulation interaction rate: unique recipients who performed the measured action divided by successfully delivered simulation messages, with one message per recipient in that exercise.
  • Simulation report rate: unique recipients who reported the simulation divided by successfully delivered messages in the same exercise.
  • Time to report: elapsed time from delivery to the first report for each reporting recipient. State the median and the number of reporters; non-reporters are excluded.
  • Follow-up completion: agreed follow-up actions completed divided by actions due in the period.

Show what changed between exercises

Record the audience, language, scenario, difficulty and time window. NIST’s Phish Scale provides a method for assessing human phishing detection difficulty. These factors help explain why click rates vary.

Exclude automated mail-security interactions where your tools can identify them, and document any uncertainty. Do not present a change in simulation results as a measured reduction in real-world incidents.

Use a short review record

For each reporting period, record the metric definition, numerator, denominator, exclusions, comparison period and owner. Add one sentence explaining the next action.

For example, a hypothetical exercise with 100 delivered messages and 12 unique reporters has a 12% report rate. This example is arithmetic, not a Moxso benchmark or customer result.

0 / 5 completed

Your review checklist

Use this checklist during your review. Selections are not saved when you leave the page.

Your review checklist

Sources and further reading

Continue your programme

Get started

See how your team can reduce human risk

Explore how Moxso helps your team identify employee risk, target training and assess progress. Tell us where you want to reduce exposure.

  • Explore how training, simulations and follow-ups address gaps.
  • See how human risk varies across your organization, departments and employees.
  • Review how your goals automatically steer risk reduction.

By submitting this form, you agree to our Privacy Policy.

ISO 27001-certified ISMSReview the certificate and its scope.
EU sovereign by architectureData sovereignty compliance built in.