Stop reporting completion: measuring human risk instead of attendance
Training completion measures whether people showed up. Here is a factor model that measures whether they are getting harder to attack.
By SafeLoop
Completion is the metric most awareness programmes report because it is the metric most awareness platforms produce. It answers a question nobody senior asked: did people open the thing we sent them.
Three groups, ten factors
A usable model separates what people fall for, what they do about it, and how much attack surface their role carries. Collapsing those three into one average is how a department full of fast reporters ends up looking identical to one that ignores everything.
- Susceptibility rate10
- Credential-submit rate8
- Repeat-clicker rate8
- Time-to-click6
- Report rate9
- Real-threat response7
- Training completion6
- Multi-channel exposure7
- Department risk5
- Tenure / onboarding risk5
Susceptibility
Susceptibility rate, credential-submit rate, time-to-click and repeat-clicker rate. This is the group most programmes already measure, usually as a single click percentage.
Resilience
Report rate, real-threat response and training completion. This is the group that predicts future outcomes, and the group most often missing from a board slide.
Exposure
Multi-channel reachability, tenure risk and department risk. Without it, a team that hires heavily or handles payments is permanently penalised for its job description.
Why a letter grade rather than a percentage
A percentage invites an argument about a two-point move that means nothing. A band moves when behaviour moves. Grading resilience rather than risk also fixes the polarity problem: higher should always be better when a letter is attached.
What to put in front of a board
- The graded score and its direction of travel.
- Phish-prone rate, so the number has a familiar anchor.
- Report rate, as the leading indicator.
- Your percentile against comparable organisations.
Completion goes in the appendix, where operational metrics belong.
Keep reading
Related articles
Why quarterly phishing tests fail, and what monthly-per-person fixes
Sending one campaign to everybody every three months optimises for administrative convenience. Here is what changes when you pace per person instead.
Read article →Running simulations without wrecking trust
The fastest way to kill a report rate is to make people afraid of being wrong. Framing, manager comms, and the lures never to send.
Read article →The 2026 human risk benchmark: what 4.6 million simulations show
Phish-prone rates fall from 33.2% to 4.2% over twelve months — but two-thirds of that lands in the first ninety days.
Read article →