Almost every security programme measures the same thing: how many staff clicked? The number is supposed to fall, quarter after quarter. That sounds reasonable and is still misleading.
A click rate can be pushed down at will. Make the test obvious enough and nobody clicks. What you are measuring then is not your resilience, but the quality of your own template.
The more useful question
What happens when someone does click?
A team where someone clicks and reports it within two minutes is safer than a team that neither clicks nor reports. When it is real, what matters is not whether a person was fooled. That happens. What matters is how quickly you find out.
Two numbers that say more
- The report rate. Someone who ignores it protects themselves. Someone who reports it protects everyone else too.
- The response time. The gap between the click and the report is your real window before a mistake becomes an incident.
Optimise only for click rate and you train avoidance. Measure report rate and response time and you build an early warning system out of people.
The difference does not show up in reporting. It shows up on the day the attack is real.