User Awareness

The User Awareness domain provides security, IT, and business teams a continuous, data-driven view of how well your organisation is building cyber-aware behaviours across its people

Beyond tracking user awareness results, it now encompasses user training program performance, including completion rates, SLA adherence, and flags when privileged access accounts go without recent training. By connecting people data to device, application, and business context, User Awareness metrics and measures help you move from point-in-time campaign reporting to genuine, ongoing measurement of human risk across the organisation.

Benefits

  • See your awareness and training programme through a business lens, not just a headcount. Understand performance by the people who matter most - users with access to sensitive data, those managing business-critical services, or business units where human risk is highest.
  • Move beyond phishing click rates to a complete picture of training effectiveness. Track whether assigned training is being completed, whether SLA deadlines are being met, and whether repeat failures are clustering around the same individuals, teams, or business units.
  • Identify and act on compound risk before it becomes a control gap. Surface users who hold privileged access but have not completed recent training, one of the harder-to-find combinations that traditional awareness reporting misses.
  • Recognise your champions and hold the right people accountable. Use consistent, historical data to identify improving behaviours, reward progress, and build the case for a stronger security culture backed by evidence, not anecdotes.

Spotlight metric

User awareness KPIS over time

Analyze how user awareness KPI performance is trending over time.

These metrics show how different parts of the business are performing against user awareness KPIs you’ve set for the users clicking phishing links. This data can be segmented by business dimensions such as geography, business unit or job role.

Example connectors

KnowBe4

Proofpoint

Cofense

Available metrics

Type
Name
Description
Informational
Active phishing campaigns
The number of active phishing awareness campaigns
Informational
Phishing links clicked
The number of links clicked in phishing awareness emails
Informational
Phishing emails sent
The number of phishing emails sent for all awareness campaigns
Informational
Phishing emails sent for active campaigns
The number of phishing emails sent for currently active awareness campaign
Informational
Employees clicked multiple links
The number of employees who clicked a URL on more than one phishing awareness email
Informational
Employees clicked links
The number of employees who clicked a URL on one or more phishing awareness emails
Coverage
Employees not included in phishing awareness
The number of eligible employees that have not been sent any phishing emails
Policy
Employees failed phishing test
The number of employees who failed a phishing test
Policy
Employees repeatedly failed phishing test
The number of employees who failed a phishing test more than once
Informational
Employees sent phishing test
The number of employees that have been sent one or more phishing awareness emails
Informational
Employees received phishing test
The number of employees that have received one or more phishing awareness emails
Informational
Employees for phishing awareness campaigns
The number of employees with email addresses eligible for phishing awareness tests
Informational
Total number of reports of suspected phishing emails
Total number of reports of suspected phishing emails
Informational
The count of distinct users who have reported a suspected phishing email
The number of unique users who have made at least one report of a suspected phishing emai
Informational
Phishing links clicked
The percentage of phishing links clicked per phishing emails sent
Informational
Employees clicked multiple links
The percentage of tested employees who clicked a URL on more than one phishing email
Informational
Employees clicked link
The percentage of tested employees who clicked a URL on one or more phishing awareness emailS
Coverage
Employees not included in phishing awareness campaign
The percentage of eligible employees that have not been sent any phishing emails
Policy
Employees failed phishing test
The percentage of employees who failed a phishing test
Policy
Employees repeatedly failed phishing test
The percentage of employees who failed a phishing test more than once
Informational
Employees received phishing test
The percentage of eligible employees that have received one or more phishing emails
Informational
Users Reporting Suspected Phishing Emails
The percentage of users reporting suspected phishing emails
Compound risk
Device coverage and Vulnerabilities with owner phishing tests
The number of devices with vulnerabilities and who's owner has received a phishing test

New metrics for 2026

Type
Name
Description
Policy
User Training Completion
Monitors timely completion of assigned cybersecurity training
Diagnostic
Employees who passed user training
The percentage of employees who have passed user training
Diagnostic
Employees who completed user training
The percentage of employees who have completed user training
Diagnostic
Employees who completed training past SLA deadline
The percentage of employees who completed user training past the SLA deadline
Informational
Employees who passed user training
The number of employees who passed user training
Informational
Employees enrolled in user training
The number of employees enrolled in user training
Informational
Employees who completed user training
The number of employees who completed user training
Informational
Employees who completed training past SLA deadline
The number of employees who completed user training past the SLA deadline
Compound Risk
Employees with privileged access accounts who have not completed phishing training
The number of employees with privilege access accounts who have not completed phishing trainings that were active within the last 30 days
Coverage
Employees not sent any phishing tests
The percentage of eligible employees who were not sent any phishing awareness tests
Informational
Employees for phishing awareness campaigns
The number of employees eligible for phishing awareness campaigns
Informational
Phishing awareness campaigns
The number of phishing awareness campaigns

Privileged Access Management metrics

Previous page

Cloud Configuration metrics

Next domain