Skip to main content

Security Awareness Training ROI: Measuring Real Behavioural Change Beyond Click Rates

7 min read
CISO Daily
Security Awareness Training ROI: Measuring Real Behavioural Change Beyond Click Rates

Every year, most large organisations run phishing simulations. Every year, the results land in board decks alongside a click rate — 12% clicked in Q1, 8% clicked in Q2, trending down. The CISO reports improvement. The board nods. Security awareness training gets its budget renewed.

The problem is that click rate decline rarely correlates with reduced breach risk. The 2024 Verizon Data Breach Investigations Report found that social engineering remained the top initial access vector despite years of increasing phishing simulation investment. Click rates measure how many people click a simulated link sent by their own security team. They don’t measure whether the same people would recognise a well-crafted spear-phish targeting their specific role, whether they’d report a suspicious email from an unfamiliar sender, or whether security-aware behaviour has actually become habitual.

CISOs who cannot demonstrate that their security awareness budget reduces risk — not just generates activity metrics — are exposed when the next board budget conversation begins.

What Click Rates Actually Measure

Phishing simulations are not invalid tools. They measure one specific thing: an employee’s susceptibility to a specific phishing template, at a specific point in time, when they know they’re being tested (even if subconsciously).

The construct validity problems are significant. Your simulation sends emails that match your organisation’s current template library. Threat actors don’t use your template library. High-quality spear-phishing leverages OSINT about the specific recipient — their role, their manager’s name, a current project, a vendor they work with. A 5% click rate on a generic “your account will be suspended” simulation tells you very little about susceptibility to an email from someone impersonating a named colleague asking the recipient to review a shared document.

Click rates also decline for reasons unrelated to behaviour change: employees become template-familiar over time (recognising internal test emails by their cadence and link domains), simulation fatigue sets in, and high-risk users learn to avoid clicking anything that arrives via security awareness training systems.

A Framework for Measuring Real Behavioural Change

Effective measurement tracks behaviour across four dimensions:

1. Reporting Behaviour

The single most operationally useful metric from a security awareness programme is the rate at which employees report suspicious emails — both real threats and simulation emails. A high report rate indicates employees are applying security-aware behaviour rather than simply avoiding the click.

Metrics to track:

  • Phishing report rate: percentage of recipients who actively report suspicious emails vs. click vs. ignore
  • Mean time to report: how long between email arrival and employee report (shorter is better for real incidents)
  • False positive report rate: employees calling out legitimate emails as suspicious (too high indicates over-zealousness, too low may indicate under-engagement)
  • Report-to-triage ratio: what fraction of employee reports generate actionable security team triage

A programme that shifts click-and-ignore behaviour to click-then-report behaviour is producing security value even if the click rate itself hasn’t moved.

2. High-Risk Role Coverage and Targeting

Not all employees represent equal risk. Finance team members who authorise wire transfers, HR staff with access to payroll systems, executive assistants with calendar and communications access, and IT administrators with privileged access are disproportionately targeted and disproportionately impactful when compromised.

Measure:

  • Targeted simulation rate for high-risk roles vs. general population
  • Click rate delta between high-risk cohorts and baseline
  • Training completion rates specifically for high-risk roles
  • Whether simulation templates for high-risk roles reflect actual targeting patterns (BEC-style, not generic credential phishing)

A flat click rate improvement across the organisation that masks unchanged or worsening performance in finance and executive assistant cohorts is a programme that’s improving the wrong metric.

3. Time-to-Behaviour-Drift

Security awareness training has a documented half-life. Studies from SANS and Proofpoint indicate that click rates begin rising approximately 4-6 months after training completion, returning to near-baseline within 12 months without reinforcement. This means annual training programmes may be investing heavily in improvements that evaporate before the programme’s claimed value is realised.

Measure:

  • Simulation click rate at 30, 60, 90, and 180 days post-training for the same cohort
  • Whether reinforcement interventions (micro-learning, targeted follow-up training for clickers) slow the decay curve
  • Correlation between training frequency and sustained behaviour change

Most awareness platforms provide this data. Most programmes don’t analyse it.

4. Incident Correlation

The highest-value measurement — and the hardest to construct — is correlating awareness training participation with actual security incident involvement. This requires cooperation between the awareness team and the SOC:

  • Are employees who clicked simulations in the last 6 months overrepresented in social engineering incidents?
  • Are employees who completed advanced training underrepresented?
  • What fraction of actual phishing incidents that reached inboxes were reported by recipients vs. caught by filters?

This analysis is feasible in any organisation with a decent SIEM and an awareness platform that logs training completion and simulation results at the individual level. The data is there; it’s rarely connected.

Building a Business Case for the Board

The board conversation on security awareness training is usually one-sided: the CISO reports training completion rates and click rates as evidence of programme health. Boards that have been burned by breaches involving socially engineered employees — and there are more of them each year — are increasingly asking harder questions.

A more credible board presentation structure:

Baseline incident data: What fraction of your incidents in the last 12 months involved a human action as a contributing factor? (Social engineering, credential phishing, accidental data exposure.) This is your risk exposure statement, not your programme results.

Programme reach and targeting: What percentage of the employee population completed training? What percentage of high-risk roles received targeted simulation content? Is your training content current — does it address voice phishing, QR code attacks, deepfake video calls, and AI-generated email, not just 2019-era credential harvesting templates?

Behavioural metrics: Report rates, time-to-report, high-risk cohort performance. These are harder to fabricate and harder to game than click rates.

Incident correlation where available: If you can show that employees who completed targeted training were underrepresented in actual phishing incidents in the following 6 months, you have a causal linkage claim worth making. If you can’t, be honest about that gap.

Cost comparison: The average cost of a socially engineered breach, per IBM/Ponemon data, exceeds £3.5 million in EMEA. Your awareness programme likely costs a fraction of that. The board needs to understand the asymmetry of the bet, not just be shown a declining click rate chart.

What Good Programmes Actually Do

The highest-performing security awareness programmes share a few characteristics that are entirely absent from generic, platform-driven training rollouts:

Role-specific content: Finance teams learn about BEC and wire fraud, not generic phishing. HR learns about fake job applicant CV attacks. Developers learn about supply chain compromise and IDE plugin risks. Generic content produces generic behaviour, which is the wrong kind.

Just-in-time training: The most effective training intervention is a targeted module delivered immediately after someone clicks a simulation — when the experience is fresh and the learning is contextually anchored. Platforms that do this well outperform annual training completions.

Culture measurement: The ultimate programme outcome isn’t a click rate — it’s whether employees feel comfortable reporting suspicious activity without fear of embarrassment, punishment, or bureaucratic friction. Psychological safety around reporting is a cultural attribute that should be measured, ideally via annual employee survey questions targeting the security culture construct specifically.

Measurable programme iteration: The best teams test different training content, simulation templates, and delivery mechanisms against each other using A/B methodology and measure outcomes against the behavioural metrics framework above, not just completion rates.

Security awareness training that produces defensible ROI exists. It requires more sophisticated measurement, tighter connection to actual incident data, and content that matches the threat landscape employees actually face. The click rate is a starting point, not a destination.