Managed IT
Almost every business does security awareness training. Far fewer could tell you whether their people are less likely to click a malicious link than they were a year ago. Those are different claims, and only one of them is a security control. The annual module is not useless so much as it is aimed at the wrong thing: it produces a completion record, and completion is not behavior.
The annual training module survives because it is easy to buy, easy to assign and easy to report on. Everyone completed it, the box is ticked, and the record exists if anyone asks. What it does not do is change what somebody does at 4pm on a Thursday when an email arrives that looks like it came from their manager and asks for something urgent.
Why the annual module does not work
Verizon's 2024 Data Breach Investigations Report puts 74% of breaches as involving human error, which makes people the largest attack surface most businesses have. It also makes them the one surface where the defense is a behavior rather than a configuration, and behaviors do not hold for twelve months on a single exposure.
Recall decays, and the calendar ignores it
Someone trained in January is meaningfully less prepared by June and materially less prepared by November. An annual cadence guarantees that most of the year is spent in the weakest part of that curve. Nothing about the training was wrong. The spacing was.
Recognising a described threat is not the same skill
Watching a video that explains phishing teaches you to identify phishing when you are expecting it, sitting in a training context, being asked to spot it. That is a different task from noticing a suspicious message while distracted, mid-task, when it arrives among forty legitimate ones. The knowledge transfers poorly because the conditions do not match.
The content ages faster than the schedule
Attacker technique moves continuously. Annual content is by definition describing last year's approaches, and the gap widens every month until the next refresh. Employees end up well briefed on the phishing style of eighteen months ago.
It measures the wrong thing
Completion rate answers whether people watched the training. It says nothing about susceptibility, which is the number you actually care about and the number an insurer is implicitly asking about. A program with 100% completion and no idea of its click rate has excellent records of an unmeasured control.
What recurring programs do differently
The Components
Three pieces, and the effect comes from running them together rather than from any one of them. KnowBe4's Phishing By Industry benchmarking reports an 86% reduction in phishing susceptibility for organizations on ongoing programs, and IBM's Cost of a Data Breach research associates active recurring training with 70% fewer security incidents. Aureon's own figure for continuous programs against one-time training is a 3.4× reduction in click rate.
Why it comes first
A baseline you measure before training
Unannounced · Whole organization · By department · Recorded
Run a phishing simulation before any training happens. Without that number you cannot tell whether the program worked, and you will be reduced to reporting completion rates because they are the only figure you have. A baseline also tends to end the internal argument about whether this is necessary, because leadership assumptions about susceptibility are usually optimistic and the result is rarely comfortable. Break it down by department: risk is never evenly distributed, and knowing where it concentrates lets you aim the program rather than blanket it.
Why it works
Simulations under real conditions
Unannounced · Varied technique · Immediate teaching moment · No blame
Simulation is the part that changes behavior, because it puts the decision in the same conditions the real one happens in: distracted, mid-task, among legitimate mail. The teachable moment lands hardest immediately after someone clicks, which is why the landing page matters more than the module. One thing to get right from the start is tone. A program that publicly names people who clicked will reduce reporting rather than clicking, and under-reporting is worse for you than a click, because the click you hear about is the one you can contain.
Why the cadence matters
Short modules, frequently
Monthly · Minutes not hours · Current technique · Role-relevant
A few minutes each month outperforms an hour each year, because the spacing is doing the work rather than the volume. Frequent short exposure interrupts the forgetting curve instead of letting it run its full length. It also lets content track what attackers are currently doing, so the material is describing this quarter's technique rather than the one that was common when the annual course was recorded. Keep it role-relevant where you can: finance staff face invoice fraud and executives face impersonation, and generic content lands weakly on both.
The pieces only work as a set
Simulations without training punish people for a gap you never helped them close. Training without simulation gives you no measurement and no realistic practice. And either one run annually decays before it can compound. The reduction figures above come from programs where all three run continuously, which is worth remembering when comparing a managed program against a training platform licence, because the platform is only the third piece.
How to tell whether it is working
Four numbers. Completion rate is not among them.
Click rate, trended
The share of people who click a simulated phishing link, tracked over time rather than as a single figure. One measurement tells you almost nothing, because difficulty varies between simulations. The trend across several is the signal, and it should fall and then stay low rather than bouncing back between campaigns.
Report rate, which matters more
The share who actively report a suspicious message rather than simply not clicking it. This is the metric most programs neglect and the one with the most operational value, because a reported phish gives your team the chance to pull the same message from everyone else's inbox before somebody less careful opens it. Not clicking is passive safety. Reporting is a control.
Time to first report
How long between a campaign landing and the first person flagging it. Falling time to report means people are recognising things faster and trust the process enough to use it, which is precisely the behavior change you were buying.
Repeat clickers
A small group typically accounts for a disproportionate share of clicks. Identifying them allows targeted support rather than blanket retraining for everyone. Handle this carefully: the aim is extra help, not a list circulated to managers, and the moment it becomes punitive your report rate falls.
What the numbers cannot tell you
Simulation results measure performance against simulations. A well-resourced attacker running a targeted campaign against one finance employee, using real context lifted from a compromised mailbox, is a harder test than any program run at scale. Training reduces exposure substantially. It does not eliminate it, which is why it belongs alongside MFA, filtering and endpoint controls rather than in place of any of them.
Cyber Insurance & Compliance Readiness Checklist: Training & Documentation
The Checklist
Fifteen questions covering the training and documentation topics underwriters and auditors ask about most. Requirements vary by carrier, policy and framework, so use this to prepare for the conversation rather than as a substitute for your own application or your auditor. Tick what you can answer without going and asking someone.
Tick what you can answer without checking. The blanks are the gaps.
Program Design
How often does training actually run?
Applications increasingly ask for frequency rather than a yes or no. Annual and monthly are not the same answer.
Does every employee receive it, including contractors and executives?
The two groups most often exempted are the ones most often targeted.
Do new starters get trained before they have full access?
Onboarding is the gap. A new employee with live credentials and no training is the easiest target you have.
Is content updated as attacker technique changes?
Material recorded two years ago is teaching people to spot a style attackers have moved on from.
Simulation Practice
Do you run phishing simulations at all?
Without them there is no susceptibility number, and completion records are all you can offer.
Do you have a baseline from before training started?
Improvement is only demonstrable against a starting point. Without one you cannot evidence that anything changed.
Are simulations unannounced and varied in technique?
Announced tests measure whether people were expecting a test. Repeating one template teaches that template.
Is there a defined follow-up for someone who clicks?
Auditors ask what happens next. Immediate, non-punitive teaching is the answer that also protects your report rate.
Documentation & Evidence
Could you produce completion records this week?
Per employee, per module, with dates. The most requested artifact and often the slowest to assemble.
Are simulation results retained with dates and outcomes?
Campaign history is what demonstrates a program rather than an event.
Is there a written training policy, not just a platform?
A configured tool is not a documented policy, and audits ask for the document.
How long is training documentation retained?
Frameworks specify retention periods. Most organizations have never checked what theirs is.
Renewal Readiness
Can you show susceptibility improving over time?
A trend line is far stronger evidence than a completion percentage, and it is what a program is for.
Have you read the training questions on your own application?
Wording differs by carrier and changes year to year. The form in front of you is the only authority.
Is someone accountable for keeping this current between renewals?
Programs lapse quietly. An answer that was accurate at last renewal may not be accurate now.
Frequently asked questions
Recurring programs do. KnowBe4's Phishing By Industry benchmarking reports an 86 percent reduction in phishing susceptibility for organizations running ongoing training, and IBM's Cost of a Data Breach research associates active recurring programs with 70 percent fewer security incidents. The distinction that matters is cadence rather than content. A single annual module produces a completion record, while recurring training combined with phishing simulation produces a susceptibility rate you can measure and move.
Four reasons. Recall decays across twelve months, so most of the year is spent at the weakest point of the curve. Recognizing phishing in a training context is a different task from noticing it while distracted and mid-task. Annual content describes attacker technique from the year it was recorded. And it measures completion, which tells you people watched the training but nothing about whether they are less likely to click, which is the number that actually matters.
Short monthly modules outperform a single annual session, because the spacing does the work rather than the volume. Frequent brief exposure interrupts the forgetting curve instead of letting it run its full length, and it lets content track what attackers are currently doing rather than what was common when an annual course was recorded. Aureon reports a 3.4 times reduction in click rate for continuous programs compared with one-time training.
A phishing simulation is a harmless test email sent to employees that mimics a real attack, used to measure who clicks, who reports it and who does neither. It works because it puts the decision in the conditions the real one happens in: unannounced, mid-task, among legitimate mail. The most valuable moment is immediately after someone clicks, when a short explanation lands harder than any scheduled module. Simulations should vary in technique, since repeating one template teaches people that template rather than the skill.
A single click rate means little, because difficulty varies between campaigns and a benchmark from another organization tells you nothing about yours. What matters is your own trend across several simulations, measured against a baseline taken before training began. Watch report rate alongside it. If click rate falls while reporting stays flat, people may simply be ignoring unfamiliar mail rather than recognizing threats, which is a weaker outcome than it looks.
No, and programs that do tend to get worse results. Publicly naming people who clicked reduces reporting rather than clicking, and under-reporting is the more damaging outcome, because a reported phishing message lets your team pull the same email from everyone else's inbox before somebody less careful opens it. Handle repeat clickers with targeted support rather than a list circulated to managers. The moment the program feels punitive, your most useful metric starts falling.
It appears on most cyber insurance applications, though the specific questions vary by carrier, policy and year. Applications commonly ask about frequency, whether all employees are covered, and whether phishing simulations are run, and auditors typically want completion records, simulation history and a written policy rather than a statement that training happens. Read the questions on your own renewal application rather than relying on a general answer, since the wording changes.
HIPAA, PCI DSS, SOC 2 and CMMC all include human-factor controls, though each words its expectations differently and applies to different scopes. Rather than assuming a general requirement covers you, identify which frameworks apply to your organization and confirm the wording with your auditor. What they consistently ask for beyond the training itself is evidence: per-employee completion records with dates, simulation results, a written policy, and a defined retention period for all of it.
Want to know your actual susceptibility rate?
Get a free training assessment. We'll run a baseline simulation so you start with a real number instead of an assumption.



