GNSAC
Resources
Security Awareness

Phishing Simulation Metrics That Actually Matter

A practical guide to phishing-simulation metrics that help security teams assess behaviour, reporting and improvement over time.

GNSAC Security Team5 February 20264 min

Beyond Click Rates

While click rates are commonly reported, they do not describe the full picture. Organisations need a more nuanced approach to measuring security-awareness outcomes.

Key Metrics to Track

1. Report Rate

The percentage of employees who correctly report phishing attempts is often more informative than click rate alone. A strong report rate may indicate:

  • Active security awareness
  • Familiarity with reporting procedures
  • A security-conscious culture

2. Time to Report

How quickly do employees report suspicious e-mails? Earlier reporting can support faster triage and may reduce the period in which a real message remains uninvestigated.

3. Repeated Interactions

Review repeated interactions across comparable campaigns to identify groups that may benefit from additional, role-appropriate support. Use the metric for programme improvement, not individual blame.

4. Department-Level Performance

Different departments face different phishing risks. Track performance by department to identify high-risk areas needing additional focus.

Measuring Improvement Over Time

The most useful signal is change over time. Track trends across comparable, authorised campaigns to assess whether the security-awareness programme is improving.

Actionable Insights

Metrics should drive action. Use your data to:

  • Prioritise training resources
  • Identify groups that may benefit from additional support
  • Provide leadership with evidence about programme performance
  • Refine simulation difficulty over time

Review a controlled simulation workflow. GNSAC Phishing supports multi-channel campaigns, behavioural analytics and management reporting.

Product session

Review the same methodology for an authorised domain.

In a focused session, we review Vigil’s assessment workflow and representative findings. Customer-domain checks begin only after scope and authorisation are confirmed.

Phishing Simulation Metrics That Actually Matter | GNSAC