Click rate answers too little.
It compresses different behaviors and contexts into one number. A scanner click, a curious click with no further action, a credential submission, and a prompt employee report should not have the same meaning. A department with greater exposure may also deserve more attention even when its raw rate looks average.
Click rate remains useful as one observation. The mistake is treating it as the program. It can be distorted by security infrastructure, scenario difficulty, sample size, delivery failure, shared devices, or a change in the campaign audience. It also gives the security team little guidance about the next action.
Build a model that can be explained.
A practical human-risk model combines multiple dimensions without pretending to predict a person’s character. The unit of analysis is exposure to a defined security scenario, not a permanent label attached to an employee.
| Dimension | Example evidence | Decision it can support |
|---|---|---|
| Event confidence | Human-like versus automated or uncertain traffic. | Whether the event should influence the score. |
| Behavior severity | Open, click, submission, report, or repeated action. | How strongly the event should be weighted. |
| Exposure and role | Relevant access, workflow, and authorized scenario context. | Which training or control matters most. |
| History | Patterns across comparable exercises and completed follow-up. | Whether risk is persistent, improving, or uncertain. |
| Protective behavior | Prompt reporting or correct verification. | Recognition and reinforcement, not only remediation. |
The model should publish its categories, allow an operator to inspect evidence, and avoid opaque precision. A level such as low, medium, or high with a clear explanation may be more useful than a score presented to two decimal places.
Connect evidence to a closed operating loop.
- Simulate: define a written, authorized scenario and an audience appropriate to the learning goal.
- Observe: preserve event timelines and classify known security-tool traffic.
- Prioritize: review evidence at individual, team, and campaign levels.
- Respond: assign focused awareness content or a process change where it is justified.
- Verify: use a later comparable exercise to see whether behavior and reporting improve.
This loop matters because generic annual training often ignores what the evidence actually shows. The goal is not to punish a click. It is to reduce the likelihood and impact of a real incident through proportionate learning and control changes.
Basic analytics and risk scoring are core. Advanced risk analytics, department views, PDF reporting, awareness training, and automation are licensed capabilities. See the versioned support matrix.
Design for fairness, privacy, and appeal.
A human-risk program can cause harm if it becomes a covert performance rating. Keep the authorized purpose narrow, minimize collected data, define retention, separate training decisions from unrelated employment decisions, and give operators a way to review disputed events. High-risk roles may need stronger controls, but stronger controls do not imply moral judgment about the people doing the work.
Share what the program measures and what it does not. Employees should understand that automated security traffic can exist, that evidence is reviewed, and that reporting suspicious messages is a positive outcome.
Measure operational change.
A mature scorecard tracks delivery quality, confidence-adjusted behaviors, reporting, time to report, repeated risk, training completion, later exercise outcomes, and the proportion of events left uncertain. It also records scenario and gateway changes so quarter-to-quarter comparison remains meaningful.
The best outcome is not a perfect dashboard. It is an organization that recognizes suspicious activity sooner, reports it through the right path, and learns where technical controls must carry more of the burden.