Insights  /  Compliance

The security training nobody finishes

Ninety-nine percent of organizations run a security awareness program. Sixty-eight percent of their employees knowingly take risky actions anyway. The gap is delivery, not content.

By McKinley Malbrough III, J.D., MS-HRM. Published September 26, 2026.

Why does the completion rate look fine when the click rate does not move?

Completion measures attendance. 84% of organizations still use training completion as a top program metric, which is the easiest number to export and the least connected to whether anybody behaves differently.

Microsoft's own measurement is the one worth sitting with: awareness training by itself produced roughly a 3% reduction in phishing click rates unless it was reinforced by policy and culture changes. Three percent is the return on a module people watched.

Meanwhile the programs that are built around behavior rather than attendance push reporting rates past 20%, about double the 10% that completion-based programs typically hold. Same topic, same hour, different design.

What actually moves the number?

Practice against the attack the person will actually see. Untrained employees fail simulations at a 33.2% baseline. After twelve months of continuous, role-based training with simulations, that falls to 4.2%, a 79% reduction across 42 million simulations and 64,000 organizations.

Notice what that sentence contains. Continuous, not annual. Role-based, not generic. Simulation, not slides. Those are three delivery decisions, and none of them is about the content of the module.

Does it have to be live?

Not all of it. The simulation runs itself and the microlearning can be asynchronous. The part that has to be live is the debrief, because the moment worth teaching is the one where somebody admits in front of peers that the invoice email looked real.

A recorded module cannot hold that moment. It also cannot answer the question the finance team actually has, which is what happens when the request comes from a voice that sounds exactly like the CFO.

When should we run it?

Immediately at hire, then continuously. New hires are 44% more likely to fall for phishing in their first 90 days, and 71% sit in that at-risk window. An annual cycle means a March hire waits ten months for the training that covers the period they are most exposed.

If you are reworking the onboarding week anyway, put it there. Onboarding week one covers what else belongs in that first five days.

How do I report it so the budget survives?

Stop leading with completion. Lead with click rate trend, mean time to report, and repeat-offender rate, and show the movement quarter over quarter.

Phishing and pretexting account for 22% of initial access in breach data. That is the line that makes the case, not an attendance figure. How to measure whether it worked has the five line report format.

Is shaming people after a failed simulation a problem?

Yes, and it is the most common own goal in this category. A program that punishes the click teaches people to hide the click, which raises the one number that matters most, which is how long an intrusion sits undetected.

Frame the tested employee as the detector, not the liability. Trained employees report real threats, with 64% surfacing at least one genuine phishing attempt within twelve months.


Where these numbers come from

KnowBe4 2026 Phishing by Industry Benchmarking Report33.2% baseline phish-prone rate falling to 4.2% after twelve months, drawn from 42 million simulations across 64,000 organizations.
Microsoft Digital Defense ReportAwareness training alone yielded about a 3% reduction in phishing click rates without reinforcing policy and culture changes.
Gartner, 2025 Secure Behavior Strategies Survey (n=65)84% of organizations use training completion as a top metric; 73% prioritize phishing reporting.
Hoxhunt Phishing Trends Report 2026Behavior-driven programs exceed 20% reporting rates against roughly 10% for completion-based training; 64% of trained employees report a real threat within twelve months.
Verizon Data Breach Investigations Report 2026Combined phishing and pretexting account for 22% of initial access.
Proofpoint68% of employees knowingly took risky actions although 99% of surveyed organizations already ran an awareness program.
Keepnet New Hires Phishing Susceptibility Report 2026New hires 44% more likely to fall for phishing in their first 90 days, with 71% at risk in that window.

Keep going

Why recorded training does not finish

The completion problem, one level up from security.

Harassment prevention that works

The other mandate everybody clicks through.

How to measure whether it worked

The five line report that protects a budget.

Want this run for your own managers?

Book twenty minutes and bring the session you are trying to build.

Book a free consult