A risk practitioner is asked to show whether the annual security awareness programme is actually reducing risk-relevant behaviour. Leadership currently sees only the percentage of staff who finished the online course. Which measure would best demonstrate that the training is changing behaviour rather than merely being completed or remembered?
- AThe proportion of staff who opened and read the full course content within the completion deadline that the learning management system enforces each year
- BThe average score employees achieve on the end-of-module knowledge quiz that the awareness platform delivers immediately after each annual course
- CThe total count of awareness sessions delivered and the number of staff registered for them across every business unit during the reporting period
- DThe change over time in the rate at which staff click simulated phishing links and the rate at which they report those suspicious messages to security Correct
Why A is wrong: Reading logs feel deeper than a pass mark, so they tempt as proof of engagement, but they still record consumption of content rather than any change in how staff behave once back at work.
Why B is wrong: Quiz scores look like a solid outcome and are easy to collect, yet they capture recall at the moment of testing, not whether staff apply that knowledge when a real suspicious message arrives.
Why C is wrong: Counting sessions delivered and staff registered is plausible activity reporting, but these are input and reach figures that say nothing about whether risk-relevant behaviour actually changed.
Why D is correct: Click and report rates from phishing simulations observe what staff actually do when tested, so a falling click rate alongside a rising report rate is direct evidence that behaviour has shifted.