Ask most businesses how their awareness programme is doing and they will quote a click rate. It is the wrong headline. A real phishing campaign against your finance team will get someone eventually. What determines the damage is how fast you find out.
The four numbers that matter
Report rate
What share of recipients flagged the message. This is the single best predictor of incident outcome, because a reported attack is a contained attack. A business with a twelve percent click rate and a sixty percent report rate is in far better shape than one with two percent and four percent.
Time to first report
Minutes from delivery to the first person raising it. This is the number that maps directly onto how much damage a real attack does, because it determines when you can start revoking sessions and blocking senders.
Repeat-click concentration
Whether risk is spread across the business or concentrated in a handful of people or roles. Concentrated risk is good news, because it is addressable with targeted support rather than a company-wide programme.
Trend, not snapshot
A single campaign tells you almost nothing. Difficulty varies, timing varies, and a bad month may just mean a harder lure. Quarter-on-quarter movement is the only reading worth putting in front of a board.
What to report to management
| Metric | What it answers | Good direction |
|---|---|---|
| Report rate | Would we find out? | Rising |
| Time to first report | How fast could we react? | Falling |
| Repeat clickers | Where is the risk concentrated? | Small and shrinking |
| Departmental split | Who needs targeted training? | Evening out |
| Training completion | Are we meeting our obligations? | At or near full |
| Click rate | How hard was the last lure? | Context only |
Why click rate misleads
Click rate belongs in the report as context, not as the headline. Presented alone it drives exactly the wrong behaviour, because the easiest way to improve it is to send easier simulations.
The metric nobody tracks and everybody should
Count genuine emails reported as suspicious. Most businesses treat these as noise. They are the clearest evidence your programme is working, because they show staff are willing to look cautious rather than risk being wrong. Discouraging over-reporting is how you quietly kill the behaviour you spent a year building.
Compliance evidence
If a standard or an insurer expects documented awareness training, the evidence usually needs to show recurring delivery and participation over a period rather than a single completed course. Build the record as you go, because assembling it retrospectively is far harder than capturing it at the time.
Reporting on awareness to your board?
We run awareness programmes and report on the numbers that actually predict incident outcomes, in a format non-technical directors can act on.
Frequently asked questions
Why is click rate a poor headline metric?
Because it measures lure difficulty as much as staff behaviour, and because the easiest way to improve it is to send easier simulations. It also implies the goal is zero clicks, which is unachievable. Report rate and time to report predict real outcomes far better.
What is a good report rate?
Less important than the direction it is moving. A business improving quarter on quarter is doing better than one with a higher static number, because the trend shows the programme is changing behaviour rather than reflecting a workforce that was already cautious.
Should we track individuals?
Track patterns, support individuals privately. Repeat-click concentration is genuinely useful because it tells you whether to run targeted training or a company-wide programme. Publishing named results destroys the reporting culture you are trying to build.
What about people reporting real emails as phishing?
Count it and welcome it. Over-reporting is the safe failure mode and clear evidence the programme is working. Businesses that treat these as a nuisance and discourage them usually see report rates fall within a couple of quarters.
What evidence do auditors want?
Typically proof that training was delivered recurringly and that staff participated, covering a period rather than a single date. Capture the records as you go. Reconstructing participation evidence after the fact is considerably harder than logging it at the time.
Usman K.
· IT Support LeadIT support lead at Azizi Technologies. Manages 24/7 helpdesk, Microsoft 365 migrations, server administration, and managed IT contracts for Dubai SMBs. Microsoft Certified. Mentioned by name in client reviews for fast resolution.
Need a quote for Security Awareness Training Dubai?
WhatsApp this article plus your device or site. We reply with next steps and a written quote.