12 August 2026 • Work safe & secure
A security awareness baseline measurement maps how your employees deal with phishing and other digital threats today, before any training has started. In practice it combines an unannounced phishing simulation with a short knowledge assessment. The outcome is your starting point: the set of numbers that every later measurement is compared against.
Skip that starting point and you are running a security awareness program on gut feeling. You can still train, but you cannot show what the training changes. In this article we explain what a baseline measurement looks like, which numbers matter and how you run one in five steps.
What is a security awareness baseline measurement?
A baseline measurement is the first structured measurement of how security-aware your organization really is. It answers two questions: what do employees know about digital threats, and what do they actually do when one lands in their inbox? You measure knowledge and behavior separately, because the two rarely match. Plenty of people who can describe phishing perfectly still click on a convincing fake email.
A complete baseline measurement therefore has two or three components:
- A phishing simulation. A realistic but harmless fake phishing email that measures actual behavior: who clicks, who enters credentials and who reports the message.
- A knowledge assessment. A short quiz on themes such as phishing, passwords and safe remote working, which shows where the knowledge gaps sit.
- Optional: a short culture survey. Do people dare to report a mistake, and do they see security as part of their job at all? Attitude predicts how the numbers will move later.
Why start with a baseline measurement?
The most important reason is simple: without a baseline you cannot demonstrate progress. “Awareness has improved” is an opinion. “The click rate dropped from one in four to one in twenty” is a result. That difference matters when you ask management for budget, and it matters to auditors.
- It makes the effect of training visible. Every follow-up measurement is compared against the baseline, so you see whether behavior actually changes instead of assuming it does.
- It provides compliance evidence. Frameworks such as NIS2 and ISO 27001 expect organizations to train employees and to show that the training works. A baseline plus periodic re-measurement is exactly that evidence.
- It shows where to aim. Results per department and per theme tell you who needs what, so the training effort goes where it pays off.
- It creates urgency. Generic statistics are easy to shrug off; numbers from your own organization are not. According to Verizon’s Data Breach Investigations Report, the human element plays a role in roughly six out of ten breaches. A baseline measurement shows what that means for your organization specifically.
What do you measure? The four numbers that matter
A good baseline measurement produces a small set of numbers you can keep tracking over time. Four metrics do most of the work:
- Click rate. The percentage of recipients who click the link in the simulated phishing email. The most quoted number, but not the most important one.
- Data entry rate. The percentage who go one step further and enter credentials on the fake login page. This is where the real damage would happen.
- Reporting rate. The percentage who report the suspicious email. The most underrated metric of all: one alert employee who reports quickly protects every colleague who received the same message.
- Knowledge score. The average score on the knowledge assessment, ideally split per theme, so you know whether the gap sits in phishing, passwords or somewhere else entirely.
Measure at group level: per team, department or location. The goal of a baseline measurement is to improve the organization, not to put individuals on display. That choice also keeps you comfortably on the right side of privacy legislation.
Curious where your organization stands today?
Set up a Security Awareness Training with Guardey in minutes and collect your baseline without the hassle.
Try Guardey free for 14 daysHow to run a baseline measurement in five steps
- Set the scope and get the basics in order. Decide who takes part, preferably everyone with a mailbox, including management. Make sure your security policy mentions in general terms that phishing simulations are part of it, and involve the works council. Announce the policy, never the moment.
- Run an unannounced phishing simulation. Use a realistic, current pretext and spread the sending over several days, so colleagues cannot warn each other and the element of surprise survives. A good phishing simulation tool randomizes this for you and tracks clicks, data entry and reports automatically.
- Add a short knowledge assessment. Ten to fifteen questions across the core themes is enough. Keep it short: you want a high response rate, not an exam. Curious which tools can handle this? We compared nine of them in our overview of security awareness assessments.
- Analyze per department and per theme. Combine behavior (the simulation) with knowledge (the assessment). A department that scores high on knowledge but still clicks needs different follow-up than one that simply never heard of quishing.
- Set targets and schedule the re-measurement. For example: reporting rate up, data entry rate down. Plan a re-measurement each quarter, with the same metrics and comparable difficulty, so you compare like with like.
From baseline to program: making the numbers move
A baseline measurement without follow-up is an expensive snapshot. The value appears when the measurement flows into a program. The recipe that works is the opposite of the yearly awareness session: short, recurring training moments that keep the topic alive week after week. That is exactly how modern security awareness training is built: challenges of a few minutes, gamification to keep participation up and fresh scenarios that follow the actual threat landscape.
Then re-measure on a fixed rhythm. Expect the click rate and data entry rate to fall and, at least as important, the reporting rate to rise. Share the group results with the whole team and celebrate the reporters: a rising reporting rate is the clearest sign that awareness is turning into behavior.
Common mistakes with a baseline measurement
- Announcing the exact moment. Then you measure how alert people are during an announced test week, not how they behave on an ordinary Tuesday.
- Naming and shaming. Reporting results per individual kills the reporting culture you are trying to build, and creates privacy problems on top.
- Staring at the click rate only. The reporting rate says more about your resilience than the click rate does. An organization where nobody reports is fragile, however low the click rate.
- Treating it as a one-off. A baseline measurement only earns its name when a second measurement follows. Numbers age fast.
- Making the first simulation extreme. An impossible spear phishing email or an obvious fake both produce useless numbers. Pick a mid-level difficulty that resembles what your organization actually receives.
Frequently asked questions about the security awareness baseline measurement
How often should you repeat the measurement?
Once per quarter is a common and workable rhythm. Repeat the same metrics with comparable difficulty, otherwise the trend says nothing. After a year you have five data points: the baseline plus four re-measurements, and a story you can tell management and auditors.
Are unannounced phishing simulations allowed?
Yes, provided you handle them carefully. Make sure employees know in general terms that simulations are part of the security policy, report results at group level and never attach sanctions to a wrong click. Involve the works council before you start. Handled this way, a simulation is a training tool and fits within the GDPR.
What is a good click rate for a first measurement?
There is no universal benchmark: the result depends heavily on the difficulty of the simulation and the sector. Double digits are no exception in a first measurement, so do not be shocked by the number. The baseline is not a grade, it is a starting point. What matters is the direction in the measurements that follow.
How long does a baseline measurement take?
Count on two to four weeks in total: a simulation spread over several days, a week for the knowledge assessment and some time for the analysis. The setup itself is quick with modern tooling; the calendar time mainly ensures the measurement stays unannounced and representative.
The baseline measurement is the least spectacular part of a security awareness program, and quietly the most important one. It replaces assumptions with numbers and turns training from a checkbox into something you can actually steer. Measure first, then train: everything you do afterwards works better because of it.
Want to turn your baseline into lasting behavioral change?
In a 45-minute demo we show how Guardey combines phishing simulations with gamified security awareness training, including the reports that prove your progress.
Request a demo