Why security awareness training is essential
Phishing simulations: design, frequency, and follow-up
Measuring training effectiveness
Building a training program from scratch
Key Takeaways
TL;DR
Over 70% of breaches involve human error — security awareness training is not optional.
Run monthly phishing simulations and track click rates, report rates, and repeat clickers.
Target a phishing click rate under 5% and a report rate above 70% within 12 months.
Never punish employees for failing simulations — use failures as immediate teaching moments.
Document all training completion and simulation results for compliance and insurance evidence.
FAQ
Frequently asked questions
How often should we run phishing simulations?
Monthly is the industry standard and what most cyber insurance carriers expect. Some organizations run bi-weekly simulations, but monthly provides sufficient data while avoiding simulation fatigue. Vary the difficulty, timing, and attack type each month to keep employees engaged.
Should employees be punished for clicking simulated phishing emails?
No. Punitive approaches create a culture of fear and discourage employees from reporting real phishing attempts. Instead, provide immediate, constructive feedback when an employee clicks a simulation. Use failures as coaching opportunities with targeted micro-training. Reserve disciplinary action only for employees who repeatedly refuse to complete required training.
What is a good phishing click rate?
The average baseline click rate for organizations without training is 30-40%. After 12 months of consistent training and simulations, the target is under 5%. World-class programs achieve 1-2%. More important than click rate is the report rate — you want employees actively reporting suspicious emails, not just ignoring them.
Does security awareness training satisfy compliance requirements?
Yes. The FTC Safeguards Rule, HIPAA Security Rule, PCI DSS v4.0, NIST CSF, SOC 2, and virtually all cyber insurance carriers require documented security awareness training. Keep records of training completion, simulation results, and follow-up actions for a minimum of three years.
Get your Cyber Defense Score™ in 60 seconds.
100 tools. No installation. No credit card. Real evidence.