Click rate can distort programme value because it treats one action as the whole story. Teams may miss whether people report suspicious messages, whether high-risk users need extra coaching, and whether security controls are reinforcing each other. A programme can look weak on clicks while still improving detection, response, and behaviour in ways that matter operationally.
Why click rate breaks as a standalone measure
Click rate is a narrow proxy for behaviour change. It can tell you that people interacted with a test message, but not whether they recognised it, reported it, escalated it, or changed how they handle similar messages later. When organisations optimise only for a lower click rate, they can create a false sense of progress while missing the real security outcomes.
The main failure is measurement distortion. A single metric encourages a single target, and people adapt to the target rather than the underlying risk. That can push programmes toward easy-to-game outcomes, while the more valuable signs of maturity, such as reporting speed, safer handling, and better judgement under pressure, are left outside the scorecard.
Click rate also collapses different user behaviours into one bucket. Someone who clicks and reports immediately is treated the same as someone who clicks and ignores the warning signs, even though those behaviours have very different operational meaning. A useful awareness programme has to distinguish exposure from response, not just success from failure.
What the metric hides about actual resilience
A programme can look weak on click metrics and still be improving the controls that matter most. If employees are reporting suspicious messages faster, if higher-risk teams are getting more targeted coaching, or if email controls are catching more of the same patterns upstream, the organisation may be materially safer even when click numbers do not fall neatly.
That is why awareness should be read as part of a wider control system. Awareness, reporting workflows, mail filtering, identity verification habits, and incident response reinforce each other. If you measure only the visible user action, you may miss the combined effect of the surrounding safeguards and underestimate the programme’s contribution to detection and response.
It also matters that click rate usually measures a moment in time, not an operating pattern. Real risk reduction depends on whether behaviour holds up across different lures, business periods, user groups, and attack styles. NIST Cybersecurity Framework 2.0 is useful here because it frames awareness as part of govern, protect, detect, respond, and recover rather than as an isolated training score.
What a better awareness programme should measure instead
The better question is not whether people clicked, but whether the programme improved the organisation’s ability to notice, avoid, report, and contain suspicious activity. That means looking at reporting rate, time to report, quality of reports, repeat exposure among high-risk populations, and whether frontline controls are reducing the need for human judgement in the first place.
This is where programme design becomes more important than the headline metric. NIST SP 800-53 Rev 5 Security and Privacy Controls is a good reference point because it supports a layered view of awareness, logging, incident handling, and access controls instead of treating training as a standalone defence.
For phishing-oriented exercises, behavioural maturity is often better reflected by whether a user reports, whether the report reaches the right team quickly, and whether the organisation can validate that suspicious traffic is being blocked or investigated. NIST AI Risk Management Framework is not a phishing standard, but it reinforces the broader point that measurement should track outcomes, not just activity.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AT-01 — Awareness and Training | Click-rate programmes measure awareness and training effectiveness. |
| DE.CM-01 — Monitoring for Unauthorized Personnel, Connections, Devices, and Software | Awareness exercises should improve detection and reporting of suspicious activity. | |
| Recommendation — Measure reporting and behaviour outcomes, not clicks alone. Use monitoring signals to validate whether awareness improves detection. | ||
| NIST SP 800-53 Rev 5 | AT-2 — Literacy Training and Awareness | Security awareness programmes are governed by training and awareness controls. |
| AU-6 — Audit Record Review, Analysis, and Reporting | Reporting and response quality are key outcomes that logs and reviews can confirm. | |
| IR-4 — Incident Handling | Awareness should feed faster escalation and handling of suspicious messages. | |
| Recommendation — Design awareness around role-specific risk and observable behaviour change. Review report handling and response data to validate programme effectiveness. Connect user reporting to incident handling and measure response timeliness. | ||
Practitioner Guidance
What to prioritise: Treat reporting behaviour and response quality as first-class outcomes. If a dashboard shows only click rate, it is under-reporting both control value and user resilience.
What to verify: Confirm whether the programme can distinguish between users who click, users who report, and users who repeatedly fail in the same scenarios. If it cannot, the metric is too blunt to guide action.
What good looks like: Low click rate is helpful, but the stronger signal is a workforce that recognises suspicious messages, reports them quickly, and benefits from supporting controls that reduce the chance of a single lapse becoming an incident.
Practitioner takeaway: Click rate is only a symptom metric; if it is the main measure, you risk optimising for the wrong outcome and missing whether the organisation is actually becoming harder to phish and faster to defend.