Because completion measures administration, not resilience. A workforce can finish training and still remain highly vulnerable to realistic fraud, especially when attacks use trusted relationships and normal business context. Readiness should be measured by whether behaviour changes under simulation, not by whether a module was completed.
Why completion rate is the wrong signal
Training completion is an administrative metric, not a behavioural one. It tells you that people clicked through content, not that they can recognise a convincing lure, resist urgency, or verify an unusual request under pressure. For phishing, the real question is whether awareness shows up in live decision-making, not whether a module reached 100% completion.
Completion rates also flatten the difference between passive exposure and demonstrated resilience. A team can pass a course and still fall for a message that uses familiar branding, routine business language, or a trusted sender relationship. That is why completion is best treated as a compliance input, not as evidence of readiness.
In practice, completion is a leading indicator only for programme administration. It is useful for proving coverage, scheduling refreshers, and checking that a baseline message was delivered, but it does not measure whether the training changed how people behave when a real attack lands in an inbox or collaboration tool.
What actually measures phishing readiness
Readiness is measured by observed behaviour under simulation and by follow-on actions that show people know what to do. That includes whether users report suspicious messages, whether they pause before acting on urgent requests, whether they challenge unexpected payment or credential prompts, and whether the organisation can detect and respond quickly once a lure is identified.
The best measures are scenario-based: click rate, credential submission rate, reporting rate, time to report, and the quality of escalation. A useful metric set looks at both exposure and response, because a low click rate means little if suspicious messages are ignored, and a high reporting rate is only valuable if the security team can triage and act on those reports.
This is why SANS Security Resources is more useful for readiness thinking than completion-only reporting, because practitioner guidance on detection and incident handling aligns with behaviour, escalation, and response rather than attendance alone.
Why phishing defeats training completion as a proxy
Phishing succeeds when it exploits trust, context, and timing. Completion rates do not capture whether a person will respond differently when a message appears to come from finance, HR, a colleague, or a vendor they actually work with. That gap matters because realistic phishing is designed to look like normal business, not like obviously malicious spam.
Completion also ignores variation across roles and attack types. A finance user, an executive assistant, and a developer face different lure patterns, different pressure points, and different consequences. A single completed course cannot tell you whether the person is resilient against credential theft, invoice fraud, OAuth consent abuse, or a supplier-based social engineering chain.
For that reason, training completion can coexist with meaningful exposure. A workforce may complete the same content and still show very different susceptibility when the attack uses a trusted relationship, a believable business process, or a time-sensitive request that bypasses careful review.
Risk and Threat Considerations
Completion-based reporting creates false confidence, which can delay control fixes and make social engineering easier to succeed at scale. The risk is not that training exists, but that leaders mistake delivery for effectiveness and underinvest in simulated testing, reporting pathways, and process controls around high-value actions.
Failure mechanism: The organisation tracks attendance or module completion instead of measuring how people behave when confronted with realistic lure content, so weak spots remain invisible until an actual phishing attempt or fraud event occurs.
Impact: Attackers can convert routine trust relationships into account compromise, payment diversion, data exposure, or malware delivery while the business believes it is “covered” because training was completed.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
CIS Controls v8, NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| CIS Controls v8 | CIS-17 — Incident Response Management | Phishing readiness depends on report-and-respond behavior, not only training completion. |
| Recommendation — Measure phishing readiness through reporting, triage, and response performance, not attendance. | ||
| NIST CSF 2.0 | PR.AT-01 — Awareness and Training | Training must build awareness, but readiness needs evidence that behavior changes under realistic simulation. |
| DE.CM-08 — Vulnerability information and threats are monitored | Simulation outcomes and reporting behavior provide monitoring evidence for human-side exposure. | |
| Recommendation — Assess whether awareness training changes user behavior in phishing simulations. Track phishing simulation and reporting signals as monitoring data for user susceptibility. | ||
| NIST SP 800-53 Rev 5 | AT-2 — Awareness Training | Awareness training is relevant, but the question is whether completion proves readiness. |
| IR-6 — Incident Reporting | Phishing readiness is reflected in whether people report suspicious messages quickly. | |
| Recommendation — Separate training delivery from effectiveness by testing behavior after training. Make suspicious-message reporting a tested and measured control outcome. | ||
Practitioner Guidance
What to prioritise: Use completion only as a hygiene metric, then prioritise simulation results and reporting behaviour as the real readiness signal. If a programme cannot show change in click, report, and escalation behaviour, it is not proving resilience.
What to verify: Check whether simulations reflect the organisation’s actual lure landscape, including branded messages, internal impersonation, and process-based fraud. A generic phishing test can overstate readiness if it does not resemble the attacks users actually see.
Decision rule: If completion is high but reporting and safe response are weak, treat the programme as content delivery, not control effectiveness, and adjust the measurement model before claiming improved readiness.
Practitioner takeaway: The most reliable phishing metric is not whether people finished training, but whether they behave more safely when the message looks real, urgent, and operationally plausible.
Related resources from NHI Mgmt Group
- Why do completion rates and quiz scores fail as indicators of training effectiveness?
- What breaks when organisations only measure vishing training by completion rates or simulation click rates?
- Why do standalone phishing scores and training completion rates create a false sense of security?
- Why do phishing programmes often fail even when completion rates are high?
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org