Completion vs. comprehension
Distinguish training assigned and marked complete from any evidence that comprehension or behaviour actually changed.
Independent IT security review
Technical anti-phishing controls are only half the system. This review checks whether the awareness and simulation program changes real reporting behaviour, instead of producing a completion certificate nobody reads.
A 100% completion rate proves people clicked through slides. It does not prove they would recognize or report a real attempt.
Distinguish training assigned and marked complete from any evidence that comprehension or behaviour actually changed.
Read simulated-phishing results over time, not one campaign, and compare click rate against report rate-not click rate alone.
Identify whether repeat clickers get a different response than a generic reminder email sent to the whole company.
A simulation that no longer resembles the phishing the organization actually receives trains people to recognize the wrong thing.
Compare simulated lures against real reported and quarantined messages to check the templates still match current tactics.
Confirm whether finance, executives, and other higher-risk roles receive scenarios matched to what actually targets them.
Review whether simulation design and consequences preserve trust in reporting, rather than teaching people that reporting gets punished.
A “report phishing” button is only a control if a person or process is actually watching what it collects.
Identify who reviews reported messages, how quickly, and what happens after hours or on weekends.
Check whether real threat signal from reports gets separated from routine spam before it reaches whoever triages it.
Confirm whether the person who reported a message ever learns whether it was real, which is what sustains future reporting.
A training program and mail-flow protection should reinforce the same message, not contradict each other.
Check that training guidance matches what the organization’s own anti-phishing and link protections actually do.
Track report and click trends after each simulation round instead of judging the program on a single snapshot.
Confirm leadership sees the trend, not just a vendor-provided completion score, when deciding whether the program is working.
Next step
Start with the trigger, decision, and known boundaries. Do not send passwords, recovery codes, or tenant exports.