Back to blog

Blog

Security awareness training: measure clicks, not courses

NIST, UC San Diego, Frontiers, Verizon and SANS agree that annual training alone is not enough. The useful metric is sustained behavior.

Security awareness training: measure clicks, not courses

For CISOs, IT teams, and compliance leaders in LATAM, security awareness training stops being an attendance checkbox and becomes a human risk program. Evidence across NIST, academic research, and industry reports shows that a stand-alone annual course measures compliance, but does not reliably change clicks, reporting, or retention. The right approach is to run with behavior metrics and continuous reinforcement.

Before looking at each source separately, the comparison brings together something none of them provides in full: the regulatory framework, empirical evidence, and operational consequence. That is where it becomes clear that the value is not in completing a course, but in sustaining learning, simulation, and measurement by cohort and role.

Source Time dimension Main metric Observed effect Implication for the CISO
NIST SP 800-50 Program with four steps, design, development, implementation, and post-implementation Awareness and training as separate functions Awareness means making security matter, training means teaching specific tasks Separate culture and performance metrics, and run a formal measurable program
NIST SP 800-50 Revision 1 Continuous approach for the whole workforce Role-based learning program Updates awareness and training into a continuous program Move from annual course to sustained, segmented learning
UC San Diego 10 types of phishing emails over eight months Probability of clicking in phishing Embedded phishing training reduced link clicks by 2% Question the practical value of annual training as an isolated control
Frontiers in Computer Science Mediation analysis on training and awareness Security awareness and reporting Security Awareness is the strongest predictor of mitigation and reporting Measure awareness and reporting as intermediate indicators
Verizon DBIR 2026 Breaches in the latest report Human element and social engineering Human element present in 62% of breaches, social engineering in 16% Prioritize human behavior metrics and controls against social engineering
90 days and 12 months of continuous training Phish-prone Percentage PPP fell from 32.4% to 17.6% at 90 days and to 5% after a year Use continuous campaigns and compare PPP by segment

What does NIST say about the program, and what changes with the revision?

NIST SP 800-50, Building an Information Technology Security Awareness and Training Program, organizes the program into four steps: design, development, implementation, and post-implementation. It also separates awareness from training, where awareness means making security matter and training means teaching specific tasks. That distinction matters because it prevents everything from being measured with one variable, course completion.

The 2024 revision, NIST SP 800-50 Revision 1, shifts the focus toward a continuous learning program for the whole workforce, based on roles. Whalemate reads that directly: the standard no longer pushes an annual-event logic, but a sustained and segmented model. For a CISO, that enables program design, not just a training plan.

Why does the annual course fall short in practice?

The UC San Diego study evaluated 10 types of phishing emails over eight months and found that embedded phishing training reduced the probability of clicking links by only 2%. The study’s own conclusion is that these programs are unlikely to offer significant practical value in reducing phishing risk. That creates an uncomfortable tension for compliance, because the course can exist and still not change behavior.

Importance of Cybersecurity Awareness in an Employee Life Cycle by Mr. Monil Adhikari, Growth Sellers HR Solution and more. Ver el original

Whalemate reads this as a problem of timing and design. If the intervention happens once a year, but the risk appears every day, the control expires before it matures. That is why the useful metric is not attendance, but behavior change across simulations and reinforcement.

What does the evidence show about awareness, not just training?

The Frontiers in Computer Science study found that Information Security Training has a positive effect on Security Awareness, but awareness is the strongest predictor of both phishing mitigation and reporting. In other words, training does not directly drive the most valuable change; it does so through the level of awareness it helps build.

The Best Free One Hour Security Awareness Training Ever, LSNTAP Videos. Ver el original

The tension here is operational, not theoretical. If the indicator that best explains behavior is awareness, then a dashboard that only counts completed courses is tracking the wrong variable. For CISOs and compliance teams, the value is in measuring awareness and reporting rates as intermediate signals, because that is where it becomes clear whether the intervention is working.

What happens when the program is continuous and practice-based?

The report summarized by HIPAA Journal shows that the average Phish-prone Percentage fell from 32.4% to 17.6% after 90 days and to 5% after a year of continuous training. In healthcare and pharmaceuticals, PPP also reached 4.1%, 5.1%, and 5.9% depending on organization size. The signal is clear: when there is continuity, practice, and reinforcement, the metric that matters does move.

That does not contradict UC San Diego. It complements it. The difference does not appear to be whether training exists, but how it is structured. Continuity, repetition, and cohort tracking change the result where an isolated course does not.

What do Verizon and SANS say about the real priority of human risk?

The Verizon DBIR 2026 says the human element appears in 62% of breaches and social engineering accounts for 16% of patterns. social engineering, including phishing, smishing, and vishing, remains the main human risk. Both sources point to the same reading: this is neither marginal nor episodic.

The Best Free One Hour Security Awareness Training Ever, LSNTAP Videos. Ver el original

For a CISO in LATAM, the implication is that training stops being a compliance box and becomes a first-line control against social engineering. If the attacker gets in through people, the organization needs to see behavior, not just completion certificates.

What fails when you only look at course completion?

The main failure is that completion does not predict clicks, reporting, or retention. The SETA programs can reduce phishing susceptibility by 50% in an initial experiment, but the knowledge gain fades in about a month. study reports that SETA programs can reduce phishing susceptibility by 50% in an initial experiment, but the knowledge gain fades in about a month. The USENIX / ACM paper adds that improvements in email identification disappear after six months and that semestral reminders and formats with videos and interactive examples are needed.

Whalemate interprets that combination as evidence of fragile retention. If knowledge disappears quickly, the organization has to measure decay, not a static snapshot. That is where periodic reinforcement, simulations, and role segmentation become program decisions, not optional extras.

What decision does this enable for a CISO, IT team, or compliance function in LATAM?

The enabled decision is to replace the annual course model with a human risk program built on operational KPIs. That means measuring click rates in simulations, incident reporting, awareness, knowledge retention, and PPP by cohort or role. It also means using the score to prioritize interventions, not to punish people, because the value is in identifying where to strengthen technical controls, communications, and training.

For IT and compliance, this changes the conversation with auditors and leadership. Instead of proving that training happened, teams can show whether susceptibility fell, whether reporting rose, and whether human risk moved over time. That supports more concrete decisions about investment, prioritization, and coverage.

What to read next?

What is a LATAM security awareness platform?

A LATAM security awareness platform is a continuous program for the whole workforce, based on roles and focused on measuring behavior, not just completion. In this article, the right logic is to move from the isolated annual course to simulation, reinforcement, and cohort tracking.

NIST SP 800-50 separates awareness from training, and the 2024 revision pushes a sustained learning program. The cited studies also show that clicks, reporting, and phishing susceptibility change more effectively when measurement follows behavior over time.

See the full topic guide

Would you like to go deeper on this topic?

Open this article directly in Claude or ChatGPT — ask questions, get a summary, or explore related ideas.

Open with ClaudeOpen with ChatGPT