What is human risk reporting?

Human risk reporting turns phishing clicks, reports and training completion into a monthly trend leaders can act on. What it contains, the benchmarks, and how to use it.

Human risk reporting is the practice of turning your workforce's security behaviour — phishing clicks, suspicious-email reports, training completion, repeat mistakes — into a regular set of numbers a manager can read and act on. It is the reporting layer that sits on top of security awareness training and phishing simulations, and it answers the question neither of them answers on its own: is the human side of our security actually improving?

Key takeaways

What is human risk reporting?

Training produces completions. Simulations produce clicks and reports. Human risk reporting is what turns those raw events into something a business owner can read on the first Monday of the month and act on before lunch.

It has three levels:

  1. The organisation number — one figure for the whole workforce (click rate, report rate, average risk) that shows the overall direction.
  2. The per-person view — where the risk actually sits: who clicked, who has not completed training, who reported fastest.
  3. The trend line — the same measures month over month, because a single month proves nothing and the direction proves everything.

Without the third level, reporting degenerates into a monthly surprise. With it, security becomes a managed programme with evidence behind every claim.

What a human risk report contains

A useful monthly report covers six things, no more:

MetricWhat it tells youHealthy direction
Phishing click rateHow many staff engaged with the lureFalling month over month
Report rateWhether staff actively flag suspicious emailRising
Time to reportHow fast the human firewall reactsFalling
Training completionWhether assigned modules finish by due dateStaying above target
Repeat clickersWho keeps making the same mistakeShrinking list
Per-person risk trendWho needs coaching next monthNames at the top, shrinking

Click rate alone is the vanity number. A team can click slightly above average and still be healthy if they report fast and complete their training — the report exists so you can see that distinction instead of guessing at it.

Why report rate beats click rate

The behaviour that saves a business is not clicking less — it is reporting more. Filters miss things; when they do, a workforce that reports within minutes closes the window an attacker has to act. ASD's ACSC received more than 84,700 cybercrime reports in FY2024–25, one every 6 minutes, and business email compromise fraud was 15% of business cybercrime reports that year — an attack that starts with one convincing email in one inbox. The control that stops it spreading is a person who hits report instead of reply.

That is why mature programmes celebrate reporters by name and treat click data as coaching input, not evidence of guilt. Publish a shame list once and staff stop reporting, and an unreported real phish costs far more than a clicked simulation.

The benchmarks behind a good report

Industry data gives the trend lines your report should be judged against. KnowBe4's 2026 Phishing by Industry Benchmarking Report, built from 67.7 million simulated phishing tests across 14.5 million users, puts global phishing susceptibility at 33.2% before any training, 20.1% after 90 days, and 4.2% after twelve months of continuous training and testing — an 87% reduction. The largest gains land between months 3 and 12, which is exactly why the reporting has to keep running: a programme that stops measuring stops improving.

At the top end of the cost curve, IBM's 2026 Cost of a Data Breach Report puts the global average breach at USD 4.99 million, up 12% and a record high, with phishing the most common initial attack vector for the fourth year running. A monthly human risk report is how a small business shows its insurer, its board and itself that the cheapest attack vector is being actively managed.

How often to review human risk

Monthly is the standard, and it is the shortest interval at which behaviour change is visible above noise. Quarterly is the minimum for reporting to leadership; weekly reads invite overreaction to one difficult campaign. Read each month's numbers alongside what changed — a harder lure batch will legitimately dip the click component, and a holiday month will dip completion. The trend is the verdict; a single campaign is a data point.

From dashboard to action

A report nobody acts on is a compliance exercise. The working loop is short:

Cyber Aware's human risk reporting produces this automatically: click, report and completion metrics roll into dashboards per person and per organisation, and phishing simulations feed the numbers after every campaign. For a wider view of how platforms differ on reporting, the platform comparison breaks down what each vendor surfaces.

FAQ

What is human risk reporting? Regular reporting on workforce security behaviour — phishing clicks, reports, training completion and repeat patterns — organised so a manager can see the trend and act on the outliers.

How is it different from a phishing test result? A test result is one campaign's numbers. Human risk reporting runs the same measures every month, per person, and adds training behaviour — the trend is the point.

What is the most important metric in a human risk report? Report rate. Click rate measures mistakes; report rate measures the reflex that neutralises real attacks that get past every filter.

Can employees see their own numbers? In well-run programmes, yes — people improve what they can see, provided the number arrives with coaching and never with punishment.

How long before a report shows improvement? The click rate usually moves within the first few months; the KnowBe4 2026 benchmark places the full reduction — 33.2% to 4.2% — at the twelve-month mark of sustained training and testing.

Do MSPs use human risk reporting for clients? Yes — a per-client risk trend line is the proof a programme works, in one slide, and it is a common reason MSPs adopt a reporting-first platform.

One last thing

The best human risk report fits on one page and names three things: where we were, where we are, who we are helping next. Everything else is detail for the person running the programme — and if the report cannot fit on a page, leadership will stop reading it by month three.

Related guides

Ready to deploy

Same playbook.
Your brand.

Cyber Aware's Human Risk Score works the same way for every MSP partner - under your brand, on your cadence.