Awareness Training Isn't Broken — Your Metrics Are
Multiple studies have found that click-through-rate training barely moves real-world resilience. The programs that do work stopped measuring clicks and started measuring outcomes.
Few security investments attract as much confident spending — or as much quiet skepticism — as awareness training. Over the past year that skepticism acquired hard evidence. A 2025 study from researchers at UC San Diego concluded that anti-phishing training programs, in their current and commonly deployed forms, are unlikely to provide meaningful protection on their own. Research presented at Black Hat reached a similarly sobering conclusion about phishing simulation specifically. Meanwhile, training vendors publish benchmark reports showing dramatic risk reductions after a year of continuous programs. Both camps are reporting real measurements. The conflict is mostly about what is being measured.
The Circular Metric
Click-through rate is the industry's default scoreboard, and it has a structural flaw: it measures performance on the vendor's own test. Programs that reduce clicks often do so by making simulations more recognizable — teaching employees what the assessment looks like rather than what an attack looks like. A falling click rate on known simulations can coexist with unchanged behavior on the one real message that matters. Worse, punitive programs that rely on public shaming, remedial courses, or manager escalation train the behavior nobody wants: people who do click stop reporting it.
Measure the Things That Predict Survival
Organizations that get measurable results have largely stopped optimizing for clicks and started tracking outcomes that map to resilience:
- Report rate and time-to-report: The most valuable behavior is a fast report. A workforce that reports 60 percent of suspicious messages within five minutes is worth more than one that clicks rarely and stays silent.
- Time-to-containment: How long from first report to disabled session and rotated credential? That number, not a quiz score, is what a real incident will test.
- Exemption rate: Every MFA exemption and shared mailbox is a place where training is being asked to compensate for missing design.
Make the Safe Action the Easiest One
Training fails most often not because employees do not know better but because the secure path is harder than the insecure one. A one-click report button that auto-triages to the SOC, passwordless authentication that removes credential entry entirely, and browser-level URL protection all shift burden away from human vigilance — which, unlike a phishing quiz, does not degrade at four in the afternoon on a Friday.
What Good Looks Like
Effective 2026 programs share a shape: short, frequent, role-specific modules instead of an annual video; bespoke scenario work for executives and finance staff, whose specific weaknesses are worth modeling; simulations used as telemetry rather than discipline; and a standing rule that reporting a suspected compromise is always rewarded and never punished. Awareness is a sociotechnical control, not a compliance ritual. Treated as a control, it can be measured. Treated as a ritual, it can only be audited.