← All white papers

White paper for IT Security & CISO

After the Click.

Why the reporting rate is the right metric, how simulations can train instead of shame — and what decision training has over slide decks.

The problem this is about

Phishing remains the most common way into companies — and at the same time the topic with the most training hours. That both are true at once is systemic: the test is built as a trap, the course is an annual appointment, and the slides numb people.

The core problem is the metric. Click rates fluctuate with the difficulty of the bait. What counts is the reporting rate and the time to first report: it decides whether IT contains a real attack after four minutes or hears about it after four hours.

What is inside

  • Why the click rate measures how good the bait was — not how alert the organisation is
  • The culture question: why “I clicked and I am reporting it right away” is the most valuable sentence of the whole exercise
  • Simulation as training: learning page instead of pillory, automatic follow-up training, aggregated reporting
  • Decision training instead of slides: story courses, dialogue simulations, micro series against knowledge decay

For everyone who wants to measure awareness by outcomes — not by completed appointments.

Download for free

7 pages, PDF · As of August 2026. You get the download link right here on this page.

That didn’t work — please check the e-mail address and try again.

Your download is ready.

Thank you! Here is the paper — the link keeps working later, feel free to save it.

Download PDF (7 pages)

All papers provide general information and are not legal advice.

Ready for training that sticks?

Try it free for 14 days — from 1 user, no credit card, ends automatically.

Start free trial