Certified Information Security Manager (CISM)Information Security Risk ManagementMedium

An organization is evaluating the effectiveness of its information security awareness training program. Post-training phishing simulations show a 15% click-through rate, which is higher than the industry average of 10%. The information security manager needs to report this to senior management and recommend improvements. Which of the following metrics would be MOST useful to present alongside the click-through rate to provide a comprehensive view of the program's impact?

  1. ANumber of security incidents reported by employees after training.
  2. BCost of the security awareness training program.
  3. CPercentage of employees who completed the training module.
  4. DTime taken for employees to complete the training.
Show answer & explanation

Correct answer: A. Number of security incidents reported by employees after training.

While click-through rate shows susceptibility, the ultimate goal of security awareness is to reduce actual security incidents. Reporting the number of security incidents (or lack thereof) post-training directly demonstrates the real-world impact and effectiveness of the program in mitigating risk, providing a more comprehensive view to senior management.

Why the other options are wrong

  • B. The cost is a budget metric, not a direct measure of program effectiveness in reducing risk.
  • C. Completion rate indicates reach but not necessarily understanding or behavioral change.
  • D. Time taken is an engagement metric, not a direct measure of security outcome or risk reduction.

Security Program Metrics

Quantifiable measures used to assess the performance, effectiveness, and maturity of an information security program.

  • Should align with business objectives.
  • Include operational, technical, and management metrics.
  • Used for reporting, decision-making, and continuous improvement.

Memory trick: Measure what matters: outcomes over efforts.

More Information Security Risk Management questions