← Back to news 14.07.2026

Awareness is not measured in attendance

The mandatory training is completed, the attendance rate looks good, the auditor is satisfied. And still, part of the workforce clicks on the next simulated phishing mail. Why attendance rate and click rate tell two different truths, and how simulation, findings and targeted training become a loop instead of a box-ticking exercise.

A familiar picture: the annual awareness training is done, attendance sits at 95 percent, the evidence for the audit is clean. Three weeks later a simulated phishing mail goes through the company, and a noticeable share of the workforce clicks. Both numbers are correct. They just do not measure the same thing.

Two numbers, two truths

The attendance rate is a compliance number: it proves that training happened, and that evidence has its firm place, from ISO 27001 to NIS2. The click rate is a behavior number: it shows what the training actually delivers in everyday work, under time pressure, between two meetings, facing a deceptively real sender address. For risk, the second number is the one that counts. And without simulation, you simply do not have it.

From annual event to loop

A simulation becomes interesting through what happens afterwards. Whoever clicked does not need a sanction but the right training, as promptly as possible, while the moment is still fresh. Then you measure again. Training as a yearly event becomes a loop: simulation, finding, targeted training, next measurement. Only in repetition does the real metric appear, namely the direction: does the click rate drop from round to round?

How isidaten closes the loop

In isidaten, phishing simulations run directly from the platform, with your own templates, landing pages and sending configuration, or connected via GoPhish. Whoever clicks is assigned the configured awareness course automatically, without anyone reconciling lists. Results from SoSafe, from e-learning progress to simulation data, flow into the same evaluation via API. And the e-learning module, which also supports SCORM-compliant packages as course content, documents attendance and certificates for audit evidence. Both numbers then live in one place: the one for the audit and the one for the risk.

More on training and evidence is shown on the e-learning module page; the connections are covered by the connector pages for GoPhish and SoSafe.

Matching solution isidaten for ISO/IEC 27001

Questions about this update?

Talk to us – we are happy to show you this feature in a demo.