Essential Guide

Security Awareness Training: Examples, Metrics & Frameworks (2025)

Security awareness training turns people into a responsive ‘report first’ layer by pairing simulations with just-in-time learning and tracking how quickly threats are reported across the org.

Table of contents

About the author
Eliot Baker
Director of Content Marketing, Hoxhunt

share this guide
The short answer

A security awareness program works when people report real threats faster, so report rate and time-to-report tell you more than completion rates do. The audit trail comes from mapping the program to NIST CSF 2.0, ISO 27001 and CIS Controls v8, and the behavior change comes from short, role-relevant practice instead of an annual course.

What is security awareness training?

Security awareness training is an ongoing program that teaches your employees to recognize, report, and respond to everyday cyber risks (e.g., phishing, social engineering, data handling). Modern programs blend short, role-relevant lessons with realistic simulations and instant feedback, and track outcomes like report rate and time-to-report.

Security awareness training is the control that changes what people do, which is why its evidence base has a guide of its own, what actually reduces human cyber risk. The mechanics of building the program are here.

‍

Why security awareness training matters

Your program works when it changes day-to-day behavior rather than when it checks a box. Measure outcomes like reporting rate and time-to-report, keep your learning small and frequent, and bake compliance in without losing empathy or relevance. That’s how programs reduce human risk and support business goals.

What actually moves the needle:

  • Behavior > box-ticking. Training is information; behavior change is the goal. Shift success from completions to actions people take under pressure.
  • Ditch vanity metrics. Completion is an input and click rate is easily gamed. Prioritize reporting rate, real-threat reports, and dwell/time-to-report instead.
  • Faster signal, faster response. Track how quickly users report phishing simulations and real incidents; shrinking dwell time is tangible risk reduction.
  • Small, frequent, respectful. Replace annual marathons with micro-learning in-flow; cadence and timing beat volume.
  • Empathy & personalization. Speak the user’s language (e.g., Finance ≠ generic “watch invoices”). Role-based, context-rich nudges sustain engagement.
  • UX that lowers friction. One report phishing button and instant feedback create a repeatable habit and visible progress (dashboards, light gamification).
  • Compliance is the floor. Meet requirements, but design for behavior and culture so the program actually reduces cyber risk.

‍

Step 1: Baseline your security awareness training against the major frameworks

Anchor Security Awareness and Training to four pillars: NIST CSF 2.0 (PR.AT) for outcomes, NIST SP 800-53 (AT-1/AT-2/AT-3/AT-4) for controls, ISO/IEC 27001:2022 (Clauses 7.2/7.3 + Annex A 6.3) for governance, and CIS Controls v8 (Control 14) for practical tasks. Keep role-based training, auditable LMS reports, and records of course completions as evidence.

If you work with a US federal or contractor scope, add the NICE Workforce Framework for Cybersecurity (NIST SP 800-181r1) to your mapping. It gives you the role and task vocabulary auditors expect when you justify why a given track applies to a given job, which is the question that usually follows “who needs which training.”

Quick mapping (what each framework expects and what you show)

NIST CSF 2.0: PR.AT (Awareness & Training)

What it asks: People know risks and can do their tasks securely (PR.AT-01/-02).

Show as evidence: Training modules by audience, real phishing campaign drills, user awareness KPIs.

NIST SP 800-53 Rev.5: AT family

What it asks: AT-1 policy/procedures; AT-2 literacy with practical exercises (social engineering, suspicious comms); AT-3 Role-Based Training; AT-4 training records.

Show as evidence: your security awareness training policy; role catalogs; SCORM-compliant lessons; records of course completions; drill logs for simulated phishing attacks.

ISO/IEC 27001:2022 + 27002:2022

What it asks: Clause 7.2 (Competence), 7.3 (Awareness); Annex A 6.3 “Information security awareness, education & training.”

Show as evidence: skills matrix, course exam (where needed), certificate of completion, LMS reports, periodic refresh micro-modules.

CIS Controls v8: Control 14

What it asks: Ongoing awareness program with role-specific training and social-engineering practice.

Show as evidence: schedule of training campaigns, roster of high-risk roles, scenario library (BEC, spear phishing), outcome dashboards.

Make auditors (and learners) happy

  • Keep one report phishing path and log everything (reports, landing page completions, LMS reports).
  • Run role-based training (finance, IT admins, exec support) tied to phishing templates that reflect real security threats.
  • Store evidence centrally: policy, mappings, records of course completions, exports of report-rate/TTR, and a quarterly executive summary.
FrameworkControls / ClausesWhat it expectsEvidence to keep
NIST CSF 2.0, PR.AT (Awareness & Training)PR.AT-01, PR.AT-02, PR.AT-03People understand security threats and can do their jobs securely; training is ongoing, role-aware, and measurable.Role-Based Training matrix; phishing campaign schedule; report-rate & Time-to-Report (TTR) trend; sample landing page; incident handoff SOP.
NIST SP 800-53: AT familyAT-1, AT-2, AT-3, AT-4Policy/procedures, awareness for all, Role-Based Training for specific duties, and maintained records.Security awareness training policy; interactive eLearning course + micro modules (SCORM v2004); LMS reports; records of course completions; certificate of completion.
ISO/IEC 27001:2022 (+27002)Clause 7.2, Clause 7.3, Annex A 6.3Competence and awareness measured and maintained; education integrated into the ISMS; periodic refresh.Skills matrix; Training Modules and nano videos; course exam (where required); audit-ready LMS exports; quarterly awareness comms.
CIS Controls v8: Control 14 (Security Awareness & Skills)14.1, 14.2, 14.3Ongoing program with role-specific coverage and social-engineering practice (e.g., spear phishing).Scenario library & phishing templates; FortiPhish/other simulation logs; departmental KPIs; manager sign-offs.
Public sector add-ons (US/DoD/Agency)Rules of Behavior, CUI/CI training, Trusted Workforce 2.0Coverage for Controlled Unclassified Information, Classified Information, and Derivative Classification where applicable.Compliance training module list; attestations; refresher cadence; references to DODM 5200.01 Vol. 3; accessible content per WCAG.

‍

Step 2: Decide what your security awareness training should cover

Prioritize behaviors, not topics. Build security awareness training around employees’ reality (their tools, time, workflows), then reinforce with short, role-relevant lessons and phishing simulations. Focus first on recognizing/reporting suspicious messages (email/QR/SMS/voice), identity hygiene, and safe data handling, measured by reporting rate and time-to-report rather than completion alone.

If you are choosing what to put in front of people first, the shortlist of security awareness topics for employees works through them by risk rather than by calendar.

Curriculum (behaviors first)

  • Email & social engineering (multi-channel): Train people to spot phishing attempts across email, QR (“quishing”), SMS, and voice and to report quickly via one clear button. Measure median time-to-report and reporting rate; avoid “too many buttons” confusion.
  • Identity & access (in the flow of work): Cover SSO resets, MFA fatigue, and credential harvesters using short, contextual nudges tied to everyday tools; keep it small, frequent, respectful.
  • Data handling & collaboration hygiene: Teach safe sharing in mail/Teams/Slack, link previews, and attachment handling as part of daily workflows. Embed learning so it helps people do their jobs instead of pausing them.
  • Reporting & incident response habits: Make “see it → report it” the win condition. Provide instant feedback on reports and show progress in dashboards (trends, high-risk patterns).
  • Culture guardrails (avoid backlash): Keep lures professional; don’t punish mistakes. Empathy and relevance drive engagement; punitive, school-style training backfires with busy professionals.
Program principle: Design for people rather than policies. Adapt by role and evolve with the threat landscape so users build real-world habits instead of just checking the box. You can read our full guide to security awareness training topics here.

Security Awareness Curriculum Planner

Behavior-first, role-aware.

TopicPractice this (behaviors)Drill (simulation / micro-lesson)Measure
Phishing & social engineering (multi-channel)Report suspicious email/QR/SMS/voice quickly via one button; verify unusual requests out-of-band.Credential-harvester simulation → 60-sec landing page; add QR/SMS when plumbing is stable.↑ Reporting rate, ↓ Time-to-report (sim & real), ↓ Credential-submission
Security of credentials (passwords, MFA, SSO)Use unique passwords; enable MFA; pause on unexpected login prompts; use a password manager.Mock SSO reset & fake MFA fatigue prompt → micro-lesson on verification & manager setup.↓ Credential-submission, ↑ MFA adoption, ↓ Repeat failures
Malware & payload awarenessDon’t open unknown attachments; beware links inside attachments; report suspicious downloads.Attachment with embedded link (common tactic) → landing page explaining payload chains.↓ Unsafe downloads, ↑ Reports of suspicious attachments
Safe internet usage & Wi-FiUse VPN off-network; prefer HTTPS; avoid shady downloads; recognize watering-hole risks.Micro-lesson carousel with quick checks; optional browser safety quiz.↑ VPN usage, ↓ Risky site clicks (proxy), ↑ Policy acknowledgment
Social media & OSINT hygieneLock down privacy; verify connection requests; avoid oversharing exploitable details.Impersonation scenario (brand/colleague) → short ‘spot the tell’ exercise.↑ Reports of suspicious DMs, ↓ Successful impersonation tests
Environmental / physical securityLock screens; secure devices in public; challenge tailgating; prevent shoulder surfing.Checklist + quick quiz; poster prompts near doors; 30-sec lock-screen habit nudge.↑ Screen-lock compliance spot checks, ↓ Tailgating incidents
Clean desk & workspace hygieneClear sensitive notes/devices when away (office/home); use secure storage.Micro-lesson timed to end-of-day; before/after workspace photo prompt (optional).↓ Exposed data findings in walk-throughs
Data handling & classificationClassify before sharing; least-privilege access; use approved channels & link-sharing.Interactive “classify this” mini-game; safe-sharing tip in mail/Teams/Slack.↓ Mis-shares, ↑ Correct classification choices
Device security (laptop/mobile/BYOD)Use screen lock/biometrics; keep OS/apps patched; install from trusted stores only.Self-service device hardening checklist; patch reminder with 2-click walkthrough.↑ Patch/AV coverage, ↑ Screen-lock adoption
Removable media & rogue peripheralsNever plug unknown USB/cables; use company-approved encrypted devices only.“Parking lot USB” awareness clip → quick pledge & reporting instructions.↓ Unknown media incidents, ↑ Reports of found devices
Reporting & incident response habitSee something → hit report → resume work. Expect instant, friendly feedback.Monthly ‘report-only’ drills (no penalty); gratitude nudges for correct reports.↑ Reporting rate, ↓ Time-to-report, ↓ SOC ping-pong

How to use: Start with email sims and instant landing-page coaching. Add QR/SMS/voice later. Track reporting rate and time-to-report alongside compliance completion.

‍

Step 3: Choose how to deliver security awareness training

Ditch marathon courses. Deliver security awareness training as short, in-flow moments reinforced by phishing simulations and instant feedback. Use one report button, integrate with the SOC, and trigger just-in-time nudges from signals (e.g., Microsoft Defender). Personalize by role and adjust cadence when engagement plateaus.

Delivery is where most programs lose people. Gamified cyber security training covers what actually sustains engagement, and cybersecurity awareness month ideas gives you campaign formats you can run without a new budget line.

Delivery models (pick 2–3 to combine)

In-flow microlearning + signal-triggered nudges

Deliver 30–90-second tips where work happens (mail, chat, SSO). Fire nudges from detections/telemetry (e.g., risky sign-ins, policy hits) so lessons are timely and contextual. This replaces “annual noise” with habit formation.

Adaptive simulations + teachable landing pages

Treat simulations as practice and security awareness training as theory. They complement each other. Keep lures professional; pair each simulated phish with a 60-sec landing page and instant feedback to reinforce the report habit.

Role-based paths (finance, IT, exec support)

Swap generic content for job-specific drills (e.g., BEC for AP, SSO hygiene for Devs). Personalize cadence; refresh topics when engagement dips.

SOC-integrated reporting loop

Standardize on one report phishing button and pipe signals to triage. Give immediate feedback on real-threat reports to encourage repeat reporting and reduce false-positive noise.

Compliance overlay, not the program

Meet requirements, but design for behavior change. Short, dynamic lessons can satisfy compliance without derailing relevance.

What to measure to tune delivery

  • Reporting rate & time-to-report (sim + real) to prove faster detection.
  • Dwell time by department to target coaching where it lags.
  • Engagement plateaus → refresh content or cadence, not punishment.

‍

Step 4: Build role-based security awareness training for high-risk teams

Your role-based tracks work best when you pair short training modules with role-specific drills. Start with universal skills (spot & report) and add personalized training for Finance/AP, IT admins, executive support, and developers. Use realistic phishing templates (including spear phishing) and track by department .

What each audience needs (behaviors ▸ drill ▸ measure)

Finance / Accounts Payable

  • Practice: verify payment changes out-of-band; spot BEC and fake invoices.
  • Drill: BEC-style phishing campaign + “verify-and-callback” checklist (email → call-back SOP).

Executive support / assistants

  • Practice: gatekeeping for VIPs; verify urgent requests; handle spear phishing and vishing calmly.
  • Drill: exec-impersonation email → short voice callback script; optional SMS variant.

IT Administrators

  • Practice: challenge unexpected SSO resets, MFA prompts, and admin-panel notices.
  • Drill: credential-harvester sim (SSO reset) + micro-lesson on device posture and privileged access.

Developers / engineering

  • Practice: spot token steals, package-manager impostors, and pastebin “fixes.”
  • Drill: repo-notification lure + secure code training video on dependency trust.

HR / recruiting

  • Practice: protect candidate and employee data; handle attachments safely.
  • Drill: CV attachment with link-in-document (common drive-by download path) + landing-page teach-back.

All employees (foundation)

  • Practice: one-tap report habit across email/QR/SMS; beware urgency and curiosity hooks.
  • Drill: rotating phishing templates with instant feedback (micro modules or short videos).

‍

Step 5: Measure security awareness training effectiveness beyond completion rates

The most reliable security awareness metrics go beyond completion: track report rate, time-to-report, real-threat reporting coverage, and a resilience ratio (reports to fails). Prioritize psychological safety and behavior change: reporting should rise over time, even as click rates plateau, and insights should drive targeted coaching and faster incident response.

Before you pick targets, place yourself on the SANS Security Awareness Maturity Model. Its five stages run from non-existent, through compliance-focused, promoting awareness and behavior change, and long-term sustainment, to a metrics framework. Naming your stage tells you which metric is honest for you now: a compliance-stage program cannot claim behavior change, and a metrics-stage program should not still be reporting completions.

Before you set a target, read what is a good phishing failure rate. A low number usually means untested people rather than a safe workforce.

The KPI shortlist (what to track and why)

  • Simulated dwell time: How long it takes users to report a simulated phish once it lands. Lower is better. Speed turns instincts into a habit during practice. Track median.
  • Simulated threat reporting (report rate): % of people who report a training phish. This is the primary engagement and behavior signal in training, so optimize it before worrying about failure rates.
  • Real dwell time: Minutes from a real phishing email reaching inbox to the first user report. Shrinking this window reduces attacker dwell time and accelerates containment.
  • Real threat detection: Volume of real phishing reports from employees. Tie this to triage to show that training translates into live-fire detection. (Many teams normalize as “coverage”: % of active users who reported at least one real phish this quarter.)

Support metrics (use alongside the essentials)

  • Resilience ratio (reports : fails, in sims): A derived view of practice performance. Use it with report rate rather than as a substitute, and don’t over-index on failure rate; difficulty and timing skew it.
  • Repeat-clicker recovery: Time/attempts for repeat clickers to achieve consecutive correct reports after remedial coaching. Focus on positive, adaptive interventions over punishment.
  • Departmental deltas: Compare report rate/TTR across high-exposure roles (Finance/AP, IT, exec support) to target coaching where risk is concentrated.
Why this mix: Hoxhunt emphasizes dwell time + reporting in both simulated and real contexts to prove behavior change and risk reduction. Traditional “pass/fail” alone can mislead or be gamed.

Metrics That Matter (Security Awareness Training)

Use these four metrics to track real behavior change and reduce human cyber risk.

MetricDefinitionWhy it mattersTarget
Simulated dwell timeMinutes from opening a simulated phishing email to reporting it.Builds the “see it → report it” reflex in training.Trend down over time (median).
Simulated threat reporting% of users who report a training phish (per campaign).Measures the habit you want in the real world.Trend up month-over-month.
Real dwell timeMinutes from a real phishing email reaching inbox to first user report.Direct signal for faster detection/containment.Trend down (median; break out by role/region).
Real threat detection# of real phishing emails reported by employees (per month).Proves training translates to real protection.Trend up and diversify by channel (email/SMS).

‍

Step 6: Roll out your security awareness training program in 90 days

Set up a small rollout team, announce clearly before launch, deploy one report phishing path, and run an easy baseline phishing campaign with instant feedback. In weeks 3–10, keep comms flowing and add simple role tracks; by week 12, show trends and lock an ongoing cadence.

A rollout sits inside a wider program. The human risk management playbook sets out how the pieces connect once your training is running.

Week 0–2: Prep and plumbing

  • Form the team: program owner, IT/Sec, Comms and HR. Agree success metrics and channels (email, Teams/Slack, intranet).
  • Pre-launch comms: tell people what’s coming, why it helps, and how to report; use short, friendly messages and a simple “what to expect” page.
  • One reporting path: deploy a single report button (e.g., via M365/Exchange) and verify the route to triage.
  • Deliverability check: finish allowlisting so scanners don’t inflate opens/clicks; sanity-check QR/URL rewriting.

Week 3–4: Baseline and trust

  • Launch with a gentle baseline (easy credential harvester), plus a 60-sec landing-page lesson and a “this is practice, not punishment” reminder.
  • Keep talking: quick nudges in the first fortnight (newsletters/Slack posts) and a clear help path for questions.

Week 5–8: Calibrate by role (keep momentum)

  • Light role tracks: Finance/AP (vendor change), IT (SSO/MFA), exec support (verification/callback). Increase difficulty gradually, and never “gotcha.”
  • Recognition over reprimand: highlight good reports, use small rewards/leader shout-outs to build a reporting habit.
  • Communication cadence: follow a simple plan: announce → encourage → reinforce with short, repeatable templates.

Week 9–10: Add realism, responsibly

  • Broaden carefully: introduce QR/SMS only where appropriate; keep lures professional and supportive. Pair each drill with instant feedback.

Week 11–12: Prove impact and operationalize

  • Show outcomes: early trends for report rate and time-to-report by department; share quick wins and next steps
  • Lock the loop: publish an ongoing cadence (monthly/quarterly), keep the comms rhythm, and store artifacts in one place for easy reuse.
Quick gut-check: if engagement dips, refresh the message and templates before increasing volume. Consistent communication and positive reinforcement in the first 8 weeks drive long-term results.

‍

How do you choose security awareness training software?

Pick security awareness training that changes behavior, not just completion. Prioritize one report phishing path with instant feedback, adaptive simulations and micro-lessons, strong Microsoft/Google integrations, reliable deliverability (no auto-click noise), and human risk-based analytics . Avoid punitive models; design for psychological safety and SOC workflows.

Your checklist, vendor-neutral and outcome-first

  1. One reporting path + instant feedback: Standardize the report button and give users immediate, specific feedback on both simulated and real reports. This builds the habit you actually want. Bonus: it reduces SOC ping-pong.
  2. Adaptive practice and micro-learning instead of annual marathons: Look for personalized difficulty, role-relevant content, and short lessons that trigger from events (e.g., risky sign-ins). This beats “set-and-forget” campaigns.
  3. Deliverability that reflects humans, not machines: Require clean allowlisting and proofs that tools won’t inflate clicks, because QR and URL rewriting can corrupt results if they are not handled. Ask vendors to show how they de-noise metrics.
  4. Microsoft/Google ecosystem fit: Verify native paths for Microsoft Defender / M365 and Gmail, with signals flowing to your SOC dashboards for triage and coaching triggers.
  5. Meaningful metrics: Beyond click rate, insist on report rate, time-to-report and real-threat reporting coverage. Dashboards should segment by role/region to target coaching.
  6. Positive reinforcement > punishment: Gamification and recognition sustain engagement; punitive approaches erode trust and suppress reporting. Check the vendor’s stance and defaults.
  7. Ethics, privacy, and regional compliance: Ensure responsible lures (no humiliation), data-minimised analytics, and guidance on smishing/vishing legality by country.
  8. Fresh, real-world content: Prefer libraries updated from real threats and the ability to import lures from your own intel.
  9. Admin efficiency & scale: Low-ops campaign automation, role scoping, and clear governance. Trial for usability with your team.
  10. Proof you can show the business: Ask for before/after examples tied to incident response outcomes, such as rising real-threat reports and shrinking dwell time, rather than vanity completion stats.
CriteriaWhat to look forQuestions to ask vendorsProof to verify
One reporting path + instant feedbackStandardize the report button and give immediate, specific feedback on both simulated and real reports. Builds the habit and reduces SOC ping-pong.Can we standardize to one report path across Outlook/Gmail? What does the user feedback look like and how fast is it delivered?Live demo of report → feedback flow; sample feedback message; routing diagram.
Adaptive practice and micro-learning instead of annual marathonsPersonalized difficulty, role-relevant content, and short lessons triggered from events (e.g., risky sign-ins). Beats set-and-forget campaigns.How does difficulty adapt per user/role? What signals trigger nudges? Typical lesson length and frequency?Rules/playbooks screenshot; micro-lesson samples; engagement trend report.
Deliverability that reflects humans, not machinesClean allowlisting; handling for QR and URL rewriting; metrics de-noise to avoid link-scanner inflation.Provide your allowlist guide. How do you detect/offset link-scanner clicks? How do QR tests avoid false positives?Pilot deliverability report; QR test walkthrough; rewritten-URL handling doc.
Microsoft/Google ecosystem fitNative Microsoft Defender/M365 and Gmail integration with signals flowing to SOC dashboards for triage and coaching triggers.Which events can we push to SIEM/SOAR? What scopes/permissions are needed? Any M365/Gmail limitations?Integration docs; sandbox demo; list of event fields and dashboards.
Meaningful metricsBeyond click rate: track report rate, time-to-report (TTR), and real-threat reporting coverage. Segment by role/region.Can dashboards segment by department/region? Is there an export/API? How is real-threat coverage defined?Sample dashboard; CSV/API export; metric definitions.
Positive reinforcement > punishmentGamification and recognition sustain engagement; punitive approaches suppress reporting. Confirm defaults and tone.Show default end-user notifications. Can we customise tone and rewards? How are repeat mistakes coached?Notification templates; coaching playbook; engagement vs. time chart.
Ethics, privacy, and regional complianceResponsible lures (no humiliation), data-minimised analytics, and guidance on smishing/vishing legality by country.Data retention, access, and de-identification options? DPA available? Telecom/legal guidance by region?DPA/ISO/SOC2 docs; privacy-by-design note; SMS/voice playbook.
Fresh, real-world contentLibraries updated from real threats; ability to import lures from your own intel.Content update cadence and threat sources? How do we convert our own phish into simulations?Content changelog; recent template examples; import workflow demo.
Admin efficiency & scaleLow-ops automation, role scoping, and clear governance. Try before you buy.Show campaign automation, RBAC/SSO/SCIM, and policy controls. What’s the support model?Admin workflow video; RBAC matrix; implementation plan.
Proof you can show the businessBefore/after examples tied to IR outcomes: rising real-threat reports and shrinking dwell time, rather than vanity completion stats.Provide case studies with report/TTR deltas. Do you supply board-ready summaries?Customer case study; sample quarterly exec report.

Tip: During pilots, run one report-only drill, validate allowlists, and baseline report rate and time-to-report by department before committing.

‍

Free & official resources by region (USA, EU, UK)

For the USA, anchor your program to NIST SP 800-50 Rev.1 and CISA phishing guidance. In the EU, use ENISA awareness/cyber-hygiene resources and CERT-EU security guidance. In the UK, rely on NCSC phishing playbooks and micro-exercises. If you’re on Microsoft 365, add Defender Attack simulation training docs.

United States (USA)

European Union (EU)

United Kingdom (UK)

Platform (Microsoft 365): global add-ons

‍

Integrations: connect training to security operations (M365, SOC, LMS)

Wire security awareness and training into your stack so practice turns into protection. Standardize one report phishing button that submits to Microsoft Defender, run campaigns from the Microsoft Defender portal, and feed outcomes to your SIEM/SOAR. Pair LMS SCORM packages with behavior metrics.

M365 & email security (make practice → protection)

  • Single route for reports. Use one add-in/report button and submit user-reported messages to Defender; the latest mail-based submission can auto-forward to Microsoft for analysis.
  • Campaigns where you work. Schedule and review phishing simulations in the Microsoft Defender portal (licensing: M365 E5 or Defender for O365 Plan 2).
  • Noise control. Finish allowlisting (proxies, VPNs, link-scanners) and account for URL/QR rewriting so opens and clicks reflect people rather than machines.

SOC/IR workflows (close the loop)

  • From report to response. Push user-reported events and training signals to your security operations center via the Microsoft APIs/SIEM connectors, then trigger playbooks (coach repeat clickers, escalate real threats).

LMS & HR systems (prove learning happened)

  • Publish cleanly. Export SCORM-compliant lessons (1.2 or v2004) to your LMS for LMS reports, records of course completions, and a certificate of completion. Keep behavior metrics alongside.
  • Provisioning at scale. Use SSO/SCIM from your identity provider to keep learner rosters in sync (Smart Groups/OU mapping for cohorts).

What “good” looks like (quick checklist)

  • One report path → Defender User reported messages → SIEM/SOAR.
  • Simulations scheduled in M365; allowlisting done; QR/URL rewriting tested.
  • SCORM course for onboarding + short refreshers; behavior KPIs (report rate, time-to-report) visible to managers.

‍

Common mistakes to avoid (so your security awareness training program doesn’t stall)

Most security awareness and training failures trace to avoidable basics: chasing completion over behavior, running “gotcha” phishing campaigns, splitting reports across multiple buttons, skipping allowlisting (metrics noise), one-size-fits-all content, and no SOC/LMS loop.

What breaks (and the simple fix)

MistakeWhat happensSimple fix
Measuring the wrong thingCelebrating completions and certificates while reporting behavior stays flat.Make report rate and time-to-report your headline metrics; show trends in Manager Dashboards.
“Gotcha” simulationsPunitive tone and panic-bait erode trust and suppress reporting.Keep lures professional; pair each sim with a short, teachable landing page and positive reinforcement.
Too many reporting routesHelpdesk emails and multiple buttons fragment data and slow incident response.Standardize one report phishing button to a single triage queue; auto-acknowledge submissions.
One-size-fits-all contentGeneric lessons miss real risks for Finance, IT admins, or exec support.Run Role-Based Training with relevant phishing templates; keep modules short.
Annual marathonsOnce-a-year long courses lead to low recall and disengagement.Use a light onboarding course + quarterly micro modules; pair each sprint with a small phishing campaign.
No SOC/LMS loopTraining signals never reach operations; coaching isn’t triggered.Pipe user-reported events to SOC; trigger coaching from signals. Keep SCORM for audits + behavior KPIs for leaders.
Accessibility & inclusivity gapsCaptions missing, weak contrast, keyboard traps, and people cannot complete training.Meet WCAG basics: captions/transcripts, keyboard navigation, strong contrast, alt text.

Tip: If engagement dips, refresh templates and comms before increasing volume. Reinforce good reports immediately.

‍

Ethical guardrails & user trust

Fair phishing simulations build skills; unfair ones break the trust you depend on. Keep your lures professional, explain the “why,” and use positive reinforcement rather than penalties. Standardize one report phishing path, give instant landing page feedback, and collect the minimum data needed. Avoid sensitive topics and humiliation. Transparent comms and quick coaching sustain employee engagement and a security-first culture.

Plain rules (easy to follow)

  • State the purpose upfront. Training is practice. Success means fast reporting rather than “never clicking.”
  • Keep lures professional. Use work-relevant phishing templates (e.g., delivery, meeting, BEC) and avoid shock tactics.
  • Coach, don’t punish. Use end-user notifications with a helpful tone; enable notification options for managers to send kudos.
  • Match difficulty to risk. Calibrate by role and past behavior; escalate gently.
  • Protect privacy. Minimise data, limit access, and summarise results at team level when possible.
  • Close the loop fast. Instant, specific landing page feedback after simulated or real reports reinforces the habit.
  • Respect local rules. For SMS/voice (smishing/vishing), check regional policies and obtain approvals.

Topics to avoid (or handle with care)

  • Personal/medical details, pay/benefits changes, layoffs/reorgs, emergency alerts, political/religious content.
  • Anything likely to induce panic or real-world harm (e.g., urging users to cancel credit cards).
  • If in doubt, run a quick “no-harm test” with Comms/HR before sending.
DoDon’t
Explain purpose upfront; practice over punishment.Use humiliation, fear, or highly personal hooks.
Use work-relevant, professional lures (e.g., delivery, BEC, meeting notes).Target sensitive moments (salary, layoffs, health) without approvals.
Give instant, specific landing-page feedback for every report.Run “gotcha” emails that reward secrecy over reporting.
Standardize one report path; send positive reinforcement notifications.Collect more data than needed or expose individual errors widely.
Calibrate by role and past behavior; keep difficulty humane.Mix multiple report routes; it fragments data and slows response.
Minimize personal data; show team-level trends to leaders.

‍

How Hoxhunt enables behavior-first security awareness

Hoxhunt pairs adaptive phishing simulations with bite-size micro-learning and instant, positive feedback. It plugs into the Microsoft Defender portal, your SIEM/SOAR, and LMS, so security awareness training proves behavior change rather than just completions.

What you get out of the box

  • Adaptive practice and micro-modules. Individual learning paths automatically tune simulated phishing difficulty by role, skill, and location; users receive short, interactive micro-training after each simulation to reinforce behaviors. Training typically lands about every ~10 days.
  • Instant, human feedback. When people report suspected phishing attacks, they get real-time, plain-English guidance (what was risky and why), reducing SOC back-and-forth while accelerating learning.
  • One reporting route. A single report phishing button in Outlook/Gmail (desktop, web, and mobile) standardizes the habit; reports can flow into Defender and downstream tooling for IR.
  • Multi-channel realism, responsibly: Email first, then optional QR more advanced, multi-channel simulations (including deepfakes) where policy allows.
  • Metrics that matter: Built-in dashboards emphasize report rate, time-to-report, resilience ratio, and real-threat reporting coverage, so you can show behavior change rather than just completions.
  • Admin time-savers. Centralized Outlook add-in deployment, SSO/SCIM user provisioning, attribute-based targeting, and a clean admin portal cut ops overhead.
 
   
      See Hoxhunt in action    
   
      Drastically improve your security awareness & phishing training metrics while automating the training lifecycle.    
   
★ 4.8 G2 · ★ 4.8 Gartner Peer Insights
 
      Book 30-min demo  

Proof (real-world outcomes)

Legacy security awareness training fell short of engaging the AES workforce to reduce human risk. They needed a solution that fixed this, while supporting effective scaling of training in multiple languages, positive security culture and enthusiasm for cybersecurity, and automated analysis of reported threats.

Hoxhunt performance vs. AES’s previous security awareness software tools:

  • Reporting rate increased by 526%, from the 3-tool aggregate of 11.5% to 60.5% (this only reflects the proportion of AES employees whose work is computer-based)
  • Failure rate decrease by 79%, from the 3-tool aggregate of 7.6% to 1.6%  
  • Miss rate decreased by 58%, from the 3-tool aggregate of 80.9% to 34%
  • Resilience ratio increased by 2533%, from 1.5 to 38
  • Full case study here
Hoxhunt security awareness training case study

‍

Security awareness training FAQs

‍

How often should we train without causing fatigue?
Run a light course for onboarding, then refreshers of 5–10 minutes. Layer practice with monthly or quarterly simulated emails; adjust cadence when report rate plateaus rather than turning up volume.
What metrics matter beyond completion?
Prioritize report rate, time-to-report (TTR) for both real and simulated threats. Use a resilience view (reports : fails) for context. Keep LMS reports for audits, but brief leaders on behavior deltas and reduced cybersecurity risks.
Do we really need SCORM?
If you have an LMS, yes. Publish SCORM-compliant lessons (ideally SCORM v2004) to capture user progress, records of course completions, and a certificate of completion. Then pair those artifacts with operational KPIs from your reporting pipeline.
Is spear-phishing simulation ethical?
Yes, when it is professional and transparent. Avoid humiliation or highly personal lures, keep scenarios work-relevant, and focus on coaching, not penalties.
We saw a spike in false positives after a campaign. Is that a bad sign?
It’s a good, temporary sign of user awareness. Reinforce what to report, keep a single button, refresh phishing templates, and add 60-second “why this was risky” landing pages to tune signal quality.

Glossary: quick definitions

These are the terms you will meet most often once your program is running, and the ones worth having to hand when you are writing program documents, briefing stakeholders or answering an auditor.

  • Adversary-in-the-middle (AiTM): Intercepts sessions (often MFA-backed) to steal tokens and replay sign-ins. Why it matters: raises the bar for “verify links only” coaching; train for out-of-band verification and device posture checks.
  • Adversary-on-the-side (AotS): Observes traffic but can inject packets before the real server replies. Why it matters: explains “sudden reply” risks in thread workflows.
  • Browser-in-the-browser (BitB): Fake OAuth/SSO pop-up framed inside a page to capture credentials. Why it matters: teach users to check the real browser address bar (not the modal).
  • Email thread hijacking: Actor joins an existing chain (often via EAC) and drops malicious links/attachments mid-conversation. Why it matters: reporting habit must include suspicious replies, not just first-touch emails.
  • Right-to-left override (RTLO): Unicode trick flips filename extensions to hide payloads (e.g., “.gpj.exe”). Why it matters: update attachment drills and mail-gateway rules.
  • Authority impersonation: Impersonates a “can’t-ignore” sender (CXO, government). Why it matters: build verify-and-callback SOPs; great scenario for simulated phishing.
  • Business email compromise (BEC): Payment or data change via trusted-party impersonation; often paired with invoice manipulation. Why it matters: Finance/AP role training and vendor verification are non-negotiable.
  • Email account compromise (EAC): Real mailbox taken over to send authentic-looking mail. Why it matters: detection shifts from domain checks to behavior anomalies and rapid report rate.
  • Phishing kit / template: Prebuilt lures and pages sold as “PaaS,” enabling at-scale campaigns. Why it matters: expect rapid reuse; rotate phishing templates in training to mirror kits.
  • Secure email gateway (SEG): Mail filtering layer (spam/malware/auth checks). Why it matters: align SEG policies with training so gateway behavior doesn’t contradict user guidance.
  • DMARC / DKIM / SPF: Email-auth trio that reduces spoofing, not social-engineering risk. Why it matters: keep coaching users even with DMARC set to “reject,” because BEC and EAC attacks still land.
  • QR-code phishing (“quishing”): QR image routes to fake login or payment page; often used in delivery or “policy update” lures. Why it matters: add mobile URL-checking drills and scanner-bypass tests.
  • Postal/courier impersonation: Delivery updates used as pretext (increasingly with QR). Why it matters: safe, relatable scenario for baseline simulations and micro-lessons.
  • Vendor impersonation: Spoofs a supplier to change banking details or invoices. Why it matters: connect security awareness training with procurement controls and out-of-band verification.

‍

Report, coach, adapt: a quick demo

See how Hoxhunt turns phishing simulations into daily habits: one report phishing path in Outlook/Gmail, instant teachable landing pages, adaptive micro-learning, and metrics that matter.

What you’ll do in 60 seconds

  • Open a realistic simulated phishing email.
  • Tap the Report phishing button (Outlook toolbar).
  • See instant, friendly feedback on a teachable landing page.
  • Watch how Hoxhunt’s gamification keeps employees engaged.

Find out more about Hoxhunt’s security awareness training here.

‍

Sources

Building a Cybersecurity and Privacy Learning Program (NIST SP 800-50 Rev.1) (NIST, 2024)
NIST Cybersecurity Framework 2.0
(NIST, 2024)
Security and Privacy Controls (NIST SP 800-53 Rev.5, AT family)
(NIST, 2020)
CIS Control 14: Security Awareness & Skills Training
(Center for Internet Security, 2025)
Recognize and Report Phishing
(CISA, 2025)
Phishing attacks: defending your organisation
(UK NCSC, 2025)
Awareness & Cyber Hygiene (campaign hub)
(ENISA, 2025)
Security Guidance 22-001: Cybersecurity Mitigation Measures
(CERT-EU, 2022)
Get started with Attack simulation training
(Microsoft Learn, 2025)

Hoxhunt logo