I come across organisations that have been offering awareness training for years and still see a lot of risky behaviour in a first phishing simulation. Such a result is mainly a useful starting point: You know where extra attention is needed and can measure later whether the approach has any effect.
This article helps you compare providers, choose useful indicators and build a program that supports employees in their daily work.
Safe behaviour and technique are part of each other
Firewalls, endpoint detection and patch management cover the technical attack surfaces. But a large part of the successful cyber attacks start with human action: a click on a phishing link, a password that is reused, an attachment that is opened too quickly. Human action plays a role in many incidents, in addition to technical and organisational shortcomings.
Phishing and social engineering as the most widely used attack vectors
Phishing attacks have fundamentally changed in recent years. Name, function and organizational context are processed in messages that appear to be legitimate at first sight: a fake email from the own IT department, an invoice that looks like that of a permanent supplier, or a message that appears to come from the director with an urgent payment request. Social engineering responds to three psychological triggers: pressure of time, authority and trust. An administrative employee at a transport company receives an e-mail from "planning" with an attachment containing an urgent instruction. No time to doubt. Click. Access granted.
Why technical measures do not solve this problem
Even well-configured security solutions cannot compensate for an employee who deliberately or inadvertently opens the door. Both the NIS2 Directive and the GDPR require organisations to implement technical and organisational measures. NIS2 explicitly includes security awareness within the duty of care, while the GDPR requires demonstrable organisational safeguards for personal data, including appropriate employee training. This is now a clear governance responsibility. Board members must complete cybersecurity training themselves and be able to demonstrate that employees are trained as well.
Measuring change of behaviour with security awareness trainings: the KPIs that matter
A completed training mainly shows that someone participated; Additional measurements are required for behavioural change. You get a better picture of the effect by measuring behaviour before, during and after the training. Phishing simulations are the most commonly used instrument in the Netherlands, but some organisations use them wrongly, as a sanction instead of as a learning tool. That undermines trust and effectiveness.
Click percentages as starting point, not as end goal
For untrained employees in Dutch organisations, click rates are on average between 20 and 35 percent for the first simulation, with outliers of 40 percent. After a structured programme of 12 months, the percentages fall to 5 to 6 percent. Well-designed security awareness trainings reach levels below 10% after three months. For example, Guardey reports 70 percent less clicks after three months of training; Phished uses a residue-click rate of 4 to 15 percent as a realistic end level. But the click rate is just the starting point. An important signal for behavioural change is the reporting rate: How many employees actively report a suspicious message instead of ignoring it or clicking on it?
KPIs that convince governance and oversight
A board report on security awareness training needs more than a degree of completion. A practical KPI set that makes behavioural change detectable shall consist of the following elements:
- Click percentage per department: Which teams are more vulnerable and where is additional attention needed?
- Reporting rate and time to report: active resilience, not just knowledge.
- Repeat clickers: employees who do click again after intervention ask for a different approach.
- Completion rate by module and quarter score development: basic indicators for compliance.
- Incidents caused by human action: the strongest corporate impact KPI for governance and oversight.
A decreasing trend on click percentage combined with an increasing reporting rate is proof that a program works. That's what you're putting before the board, not a list of completed courses.
Sector differences that create or break a program
A generic e-learning about phishing works differently in a healthcare establishment than in a transport company. Threats vary, the roles of employees differ and the regulations differ. A programme that does not fit in with the daily practice of the target group will have little lasting effect.
Care and childcare: personal data as a primary risk
Special personal data are central to care and childcare. Employees work with client files, care portals and means of communication that contain sensitive information. AVG awareness training is inextricably linked to information security training.
Attackers actively abuse the high workload and the service setting of care workers: social manipulation via e-mail, text, telephone and physical observation at the workplace are all relevant attack vectors in this sector. An effective care program takes into account limited digital skills, high flow of temporary staff and short available attention span. Role-related scenarios, non generic e-learning, are the norm here.
Transport, logistics and manufacturing: continuity as core
In transport and logistics, operational systems and supply chain communication are the vulnerable places. Ransomware attacks via phishing targeting logistics employees are above average in this sector, with the aim of disrupting planning systems or gaining access to customer data. In the manufacturing industry, operational technology systems and access management play a major role: cyber training should be coordinated with operational security and process availability. Employees in these sectors often work in fragmented teams on site, with limited time behind a screen. Short, repeatable and contextual trainings, coupled with their own working environment, are more effective than extensive e-learning modules.
Compare providers of security awareness training on effectiveness, price and functions
The market for security awareness training in the Netherlands is large and unclear. There are providers that mainly sell e-learning, providers that combine phishing simulations with microlearning, and providers that deliver a fully managed program. The choice depends on three factors: what you want to measure, how you want to manage it and what it costs.
What a provider should offer at least
A serious provider delivers more than a course catalogue. The minimum requirements for a programme that can demonstrate behavioural change: phishing simulations with a notification button, department level reporting, sector-specific content, Dutch language modules and integration with existing systems via one-off application, learning management system or HR link. Suppliers like Guardey, Phished, SecureMij.nl and PhishWise are representative examples in the Dutch market, each with its own focus on management, simulation depth and reporting. Without practical simulations, it is more difficult to assess behavioural change. Completion rates alone are not a measure of effectiveness.
Price models and what you get for them
The market has three clear segments. Basic e-learning without simulations costs on average 10 to 20 euros per employee per year and is suitable as a supplement, but insufficient as an independent programme. Continuous programs with phishing simulations and reporting lie between €25 and €50 per employee per year and are the most widely used choice for SMEs. Classical sessions or custom training costs 495 to 3,500 euros per session, depending on group size and execution.
Smaller organisations without an internal security team benefit from a managed programme where the provider provides the planning, simulation and reporting. Larger organisations with their own IT or security team can set up more themselves and opt for a platform with more configuration options.
Starting with baseline assessment: accessible and directly usable
Before you choose a provider, you need to know where you stand. A baseline assessment provides insight into the current level of consciousness, the most risky departments and the threats most relevant to your organisation. Without that base, you buy a solution to a problem you don't know exactly.
What a baseline assessment looks like in practice
A baseline assessment may consist of a phishing simulation, a short questionnaire and an inventory of existing training measures. The outcome shows which groups require extra attention, whether employees are able to report suspicious messages and what information the board and executive management need. On that basis you can determine a feasible program and an appropriate reporting rhythm.
Set up continuous learning line after the first measurement
One-time training doesn't work. The NCSC confirms that phishing training has short-term effect, but without continuous programme that effect quickly disappears. An effective learning line consists of quarterly themes, monthly microlearnings of two to three minutes and periodic phishing simulations. The content forms shall be: short videos, interactive scenarios and dilemmas are more than long e-learning modules. Employees do not need to become security experts; They need to learn to recognize, report and stop.
Embed training results in governance and a viable roadmap
A awareness programme that is independent of the broader security strategy quickly loses its value. Click rates, reporting behaviour and completion should be reflected in board-level reports and lead to concrete improvement actions. This means that a loose training becomes a coherent program.
The role of a CISO as a Service in a sustainable programme
Many SMEs, healthcare organisations and public-sector bodies do not have an internal CISO. NIS2 nevertheless requires board members to be demonstrably informed about cybersecurity risks and the measures being taken. Through CISO as a Service, Kynexis Information Security helps organisations embed training outcomes in their wider information security policy by monitoring the learning programme, reporting to executive and supervisory boards and linking training data to the broader risk analysis. This provides ongoing guidance without the cost of a full-time officer.
From training data to prioritized improvement planning
Use training insights to choose targeted improvement actions. Which departments will receive extra attention in the next quarter? What threats require additional technical measures besides training? And how are improvements prioritised based on risk rather than available budget? The concrete starting point is simple: start with a baseline assessment, choose a provider that combines phishing simulations with department level reporting, and submit the results to the board with a plan for the next 12 months. You can start small and expand the approach based on the results.
Conclusion: behaviour does not change itself
Security awareness training, in the industry also referred to as security awareness training, works, but only if they are structurally embedded, sector specific and deliver measurable behaviour. Look beyond completion rates. Less risky clicks, more notifications and a faster response say more about developing safe behaviour.
Preferably choose a provider only after baseline assessment. Those who start without starting measurement will buy a solution to a problem that has not exactly been mapped. Otherwise, there is a risk of investing in an approach that does not fit and loses support from employees.
Start small, measure consistently and build from there. Do you want to know where your organisation is? Contact Kynexis Information Security for an independent baseline assessment. Within a few weeks, it is clear where the risks are and which programme is appropriate.


