Skip to the main content.

Modernize & Transform

Built to help you reimagine IT operations, empower your workforce, and leverage AI-powered tools to stay ahead of the curve.

Untitled design (3)

Empower My Team

We bring together the best of Microsoft’s cloud ecosystem and productivity tools to help your people thrive.

Untitled design (3)

Build My Infrastructure

We offer a comprehensive suite of infrastructure services tailored to support your business goals today and scale for the future

Untitled design (3)

IT Services

Our managed and co-managed IT service plans deliver a responsive and innovative engagement to support your IT needs, improve employee experience, and drive growth for your business. 

Untitled design (3)

Cybersecurity Services

Sourcepass offers innovative solutions, including SOC, GRC, Security Assessments, and more to protect your business.

Untitled design (3)

Professional Services

Grow your business with cloud migrations, infrastructure refreshes, M&A integrations, staff augmentation, technical assessments, and more.

Untitled design (3)

Industries

We understand what most managed service providers don’t – when it comes to industry-specific technology, one-size-fits-all solutions don’t exist.

Untitled design (3)

Public Sector

Sourcepass GOV, a division of Sourcepass, is dedicated to providing specialized IT solutions for the public sector.

Untitled design (3)

Locations

We have coverage across the United States, with phyiscal locations across 8 states. Wherever you are, Sourcepass has your back.

Untitled design (3)

Resource Library

Stay ahead, stay connected, and discover the future of IT with Sourcepass.

Untitled design (3)

Events & Webinars

Dive into a dynamic calendar of webinars and in-person gatherings designed to illuminate the latest in managed IT services, cybersecurity, and automation.

Untitled design (3)

Resources by Role

Explore key resources, eBooks, video trainings, and more curated for CEOs, CFOs, CIOs, CISOs, and technology leaders!

Untitled design (3)

The Sourcepass Story

Sourcepass aims to be different. It is owned and operated by technology, security, and managed services experts who are passionate about delivering an IT experience that clients love.

Untitled design (3)

The Sourcepass Experience

At Sourcepass, we’re rewriting the IT and cybersecurity experience by helping businesses focus on what they do best, while we deliver the infrastructure, insights, and innovation to help them thrive.

Untitled design (3)

 

Security Awareness Metrics That Actually Matter

 
Security Awareness Metrics That Actually Matter

Many organizations invest time and resources in security awareness training, yet struggle to answer a simple question: are employees becoming better at identifying and responding to real threats?

For SMBs operating in Microsoft 365 environments, measuring training completion alone provides limited insight. Employees may complete assigned courses while still falling for phishing emails, mishandling suspicious links, or overlooking signs of business email compromise. As phishing, social engineering, and AI-assisted scams continue to evolve, organizations need security awareness metrics that focus on behavior change rather than participation.

Microsoft 365 provides valuable signals for measuring user behavior. Through Microsoft Defender for Office 365, organizations can run phishing simulations, track user responses, and identify areas where additional coaching may be needed. Microsoft's guidance on Attack Simulation Training and Attack Simulation Training insights reinforces the importance of using simulation outcomes to identify learning gaps and improve security behaviors over time.

For growing SMBs, the most meaningful security awareness metrics help leaders understand risk trends, prioritize coaching efforts, and support measurable reductions in human-driven security incidents.

Why Training Completion Is Not a Meaningful Security Awareness Metric

Training completion is easy to measure, which is why many organizations rely on it. However, completion rates provide little evidence that employees are making better security decisions.

An employee can complete a training course and still:

  • Click a malicious link
  • Engage with a phishing email
  • Approve a fraudulent request
  • Share sensitive information inappropriately
  • Fail to report suspicious activity

Security awareness programs should focus on outcomes rather than attendance. The goal is to improve user behavior and strengthen organizational resilience, not simply achieve a high completion percentage.

Measure Behavior Instead of Participation

Effective awareness programs monitor how users react to realistic security scenarios.

Key questions include:

  • Are employees identifying suspicious messages more often?
  • Are fewer users interacting with phishing simulations?
  • Are security incidents being reported more quickly?
  • Are repeat mistakes decreasing over time?

These measurements provide operational insight into whether awareness efforts are influencing behavior.

The Security Awareness Metrics That Matter Most

Organizations benefit most from a small set of practical metrics that can drive decisions and support continuous improvement.

Phishing Report Rate

The phishing report rate measures how often users actively report suspicious messages.

This is one of the strongest indicators of security awareness maturity because it reflects positive behavior rather than merely avoiding mistakes.

A rising report rate often indicates that employees:

  • Recognize suspicious content more effectively
  • Understand reporting procedures
  • Participate in the organization's security culture

Improved reporting can also help security teams investigate threats earlier and reduce the likelihood of broader impact.

Phishing Click Rate

The phishing click rate tracks how many users interact with simulated phishing emails.

This metric helps identify:

  • User groups that require additional coaching
  • Trends across departments
  • Effectiveness of awareness campaigns
  • Areas where technical protections may need improvement

A declining click rate over multiple review periods generally suggests progress in user awareness.

Credential Submission Rate

Clicking a phishing link is one behavior. Entering credentials into a simulated phishing site represents a higher-risk action.

Tracking credential submission rates helps organizations understand:

  • Which users are most vulnerable
  • Whether high-risk behaviors are declining
  • Where targeted education should be prioritized

This metric often provides a more accurate picture of risk than click rates alone.

Repeat Failure Rate

A single simulation failure may reflect inattention, distraction, or unfamiliarity with a specific tactic.

Repeat failure rates reveal a different challenge.

Users who consistently fail phishing simulations may require:

  • Additional coaching
  • Different training methods
  • Manager involvement
  • More targeted awareness campaigns

Reducing repeat failures is often a stronger indicator of program effectiveness than increasing completion rates.

Follow-Up Training Completion

Follow-up training should be measured differently than general awareness training.

Instead of tracking whether all employees completed annual training, organizations should monitor whether vulnerable users complete remediation activities after a failed simulation.

This helps ensure corrective actions are occurring where they are needed most.

Using Microsoft Defender for Office 365 to Measure Security Awareness

Microsoft Defender for Office 365 includes Attack Simulation Training capabilities that support behavior-based measurement.

According to Microsoft's documentation on Attack Simulation Training insights, organizations can evaluate outcomes such as user interactions, compromised-user indicators, and learning effectiveness.

Segment Metrics by Risk and Business Function

Organization-wide averages can hide important trends.

A more useful approach is to examine performance by:

  • Department
  • Job function
  • Risk level
  • Geographic region
  • User type
  • Leadership group

For example, finance teams may face different phishing risks than operations teams. Executive users may require targeted simulations that reflect approval fraud or business email compromise attempts.

Segmentation helps organizations allocate training resources where risk is highest.

Measure Trends Instead of Individual Events

A single phishing simulation provides limited value.

The most meaningful insights come from reviewing trends over time, such as:

  • Increasing phishing report rates
  • Declining click rates
  • Lower credential submission rates
  • Reduced repeat failures
  • Improved training completion among targeted users

These trends help determine whether awareness efforts are producing sustainable improvements.

Microsoft's reporting capabilities, including information available through the Microsoft Defender reporting framework, support ongoing analysis and program evaluation.

Turning Awareness Metrics Into Measurable Risk Reduction

Security awareness metrics create value only when they influence decisions.

Organizations should use awareness data to improve both user behavior and technical controls.

Connect Metrics to Operational Decisions

If phishing report rates are low, reporting procedures may require simplification.

If specific departments consistently struggle with simulations, targeted coaching may be more effective than organization-wide training.

If credential submission rates remain high, additional identity security controls such as Conditional Access, multifactor authentication, or phishing-resistant authentication methods may be appropriate.

The objective is to use awareness data to drive action rather than simply generate reports.

Create a Practical Security Awareness Scorecard

For most SMBs, a simple scorecard is sufficient.

A practical scorecard may include:

  • Phishing report rate
  • Phishing click rate
  • Credential submission rate
  • Repeat failure rate
  • Follow-up training completion rate
  • Trend comparison from previous reporting periods

This approach gives leadership a clear view of whether organizational security behaviors are improving.

Reinforce Positive Security Behaviors

Awareness programs are most effective when they continuously reinforce good habits.

Employees should understand:

  • How to identify suspicious communications
  • How to report concerns
  • How to verify unusual requests
  • When to escalate issues

Over time, consistent measurement and reinforcement help create a culture in which security becomes part of routine decision-making rather than an annual training event.

For Microsoft-first SMBs, that cultural shift often provides greater long-term value than any individual awareness campaign. Employees become more disciplined in how they handle email, Teams messages, links, attachments, and approval requests because behavioral expectations are consistently measured, reviewed, and reinforced.

FAQ

What are the most important security awareness metrics?

The most valuable security awareness metrics include phishing report rate, phishing click rate, credential submission rate, repeat failure rate, and completion of targeted follow-up training. These measurements focus on user behavior rather than training attendance.

Why is training completion not enough?

Training completion only shows that employees attended a course. It does not demonstrate whether users can recognize phishing attempts, report suspicious activity, or make safer security decisions in real-world situations.

How does Microsoft Defender for Office 365 support security awareness measurement?

Microsoft Defender for Office 365 includes Attack Simulation Training capabilities that allow organizations to conduct phishing simulations, measure outcomes, identify vulnerable users, and track behavior changes over time.

What is a phishing report rate?

A phishing report rate measures how often users report suspected phishing messages. A higher reporting rate often indicates stronger user awareness and engagement in organizational security practices.

How often should security awareness metrics be reviewed?

Most organizations benefit from reviewing security awareness metrics monthly or quarterly. Regular reviews help identify trends, measure improvement, and determine where additional coaching or technical controls may be needed.

How do security awareness metrics reduce cybersecurity risk?

Security awareness metrics help organizations identify risky user behaviors, measure improvement over time, and target training efforts where they will have the greatest impact. This supports measurable reductions in human-driven security incidents and strengthens overall cybersecurity resilience.