Data Protection & Information Security
6 Jul 2026

Building a security awareness program: microlearning, KPIs, frequency

Bridgly Editorial Team
Reading time:
8
minutes
Team from the DACH region planning a security awareness program on a whiteboard with a timeline and sticky notes
Table of contents

What makes a security awareness program

A security awareness program is a permanent, plannable process that systematically builds, trains, and measures the security consciousness of the workforce. The difference from the classic annual training course lies in continuity: Instead of imparting knowledge once a year that quickly fades again, a program combines short, recurring learning units with practical exercises and clear metrics. If you are looking for the basics, you will find them in the article What is security awareness?; this article shows which building blocks an effective program consists of. The Data Protection & Information Security category brings together further articles on the topic.

The effort is worthwhile because the human factor is involved in most security incidents – according to ENISA, phishing, at around 60%, is one of the most common initial attack vectors (Threat Landscape 2025). At the same time: Designing a program yourself, continuously supplying it with content, managing the frequency, and evaluating the results ties up considerable internal resources. How this effort can be reduced with standardized formats without losing effectiveness is addressed at the end of this article.

Building block 1: regularity instead of one-off training

The most important lever is frequency. People quickly forget what they have learned if it is not repeated – an effect illustrated by the "forgetting curve" described by Hermann Ebbinghaus. Specific percentages on this (such as "after one day, half is forgotten") circulate frequently but are more illustrative than precisely proven. The principle is undisputed: distributed, repeated learning anchors knowledge permanently, one-off training courses do not.

In practice, this means: short learning units of a few minutes, spread over the year (microlearning), instead of a mandatory event lasting several hours. Small units are easier to integrate into everyday work, are postponed less often, and keep the topic present. The background in learning psychology is called spaced repetition: Content that is repeated at increasing intervals is transferred more reliably to long-term memory than knowledge crammed once.

In addition, accompanying campaigns, short reminders, posters, or event-related notices – for example after a real wave of attacks – keep attention high. The dramaturgy over the year is important: a thorough basic training course as the start, followed by a steady stream of small impulses. This keeps the effort per session low, while the overall effect grows through repetition.

A practicable annual rhythm can look like this: a detailed basic training course to begin with, then a short learning unit on a focus topic every month and a phishing simulation every quarter. What matters is not perfect timing, but that a reliable, recurring rhythm emerges at all, one that the organization can sustain permanently – better small, consistent steps than an ambitious plan that peters out after two months.

Building block 2: the right content

A program is only as good as its topics. A core that covers the most common attack surfaces has proven effective:

  • Phishing & social engineering – recognizing fake messages and psychological manipulation
  • Secure passwords & multi-factor authentication – using strong login credentials and additional layers of security
  • Safe handling of email and attachments – correctly assessing suspicious links, macros, and file attachments
  • Secure mobile work and working from home – keeping an eye on devices, Wi-Fi, and screen lock even on the go
  • Handling sensitive and personal data – confidentiality and processing in compliance with data protection law
  • Recognizing and reporting incidents – passing on suspected cases early and without hesitation

The content should be role- and risk-oriented: Anyone who deals a lot with payments needs more on Business Email Compromise; employees without a fixed screen workstation – for example in production or care – need short formats that can be accessed on mobile devices instead of long desktop courses. Management, in turn, bears special responsibility and is a preferred target of attacks, which is why it receives its own tailored content. A brief needs analysis at the beginning – which roles work with which risks – saves a lot of readjustment later and ensures that nobody is bored with irrelevant content and that everyone experiences the training as relevant to them.

Just as important as the selection is being up to date: Threats change quickly. Topics such as AI-supported phishing, deepfakes, or QR code fraud should be added regularly so that the training does not miss reality. This ongoing content maintenance is one of the biggest cost drivers – courses must be revised regularly so that they remain relevant and do not train on yesterday's state of knowledge.

Building block 3: phishing simulations

Knowledge shows in behavior. Phishing simulations – controlled, harmless test emails – make visible how the workforce really reacts and give those affected an immediate learning opportunity: Anyone who clicks on a simulation immediately receives a short explanation of how the fake could have been recognized. At the same time, they provide the data basis for measuring success.

A staged process makes sense: A first, unannounced campaign establishes the baseline, followed at intervals by further campaigns with increasing difficulty – from the crude mass email to targeted, personalized spear phishing. The purpose is important: Simulations serve learning, not exposing individuals; results are ideally aggregated and evaluated without personal sanctions. When introducing them, co-determination and data protection aspects must be taken into account – such as involving the works council and data-minimizing evaluation – which require separate consideration in detail.

For simulations to work instead of causing frustration, implementation is key: transparent communication in advance that such tests will take place, factual rather than punitive follow-up, and a clear, simple reporting channel through which genuine suspected cases can also be reported with one click. This turns the test into a learning opportunity that strengthens the reporting culture instead of undermining it. Anyone who clicks should report it – not hide.

Building block 4: measuring success – the most important KPIs

Without metrics, a program remains a gut feeling. Three KPIs have become established:

  • Phishing click rate (Phish-prone Percentage) – share of employees who click on the lure in a simulation
  • Reporting rate of suspicious messages – share of those who actively pass on suspicious emails via the reporting channel
  • Time-to-report – how quickly a suspicious message is reported after receipt

What matters is reading the metrics in context: A falling click rate with a simultaneously rising reporting rate is the real picture of success – the workforce falls for scams less often and reports more actively. A low click rate alone can be deceptive if hardly anyone reports. That is why the three KPIs should always be considered together and over time as a trend, not as a snapshot.

It is important to set realistic goals: Pushing a click rate to zero overnight is neither feasible nor necessary. A step-by-step goal makes more sense – for example, noticeably lowering the baseline in the first year and increasing the reporting rate in parallel. In addition, it is worth looking at soft indicators such as the participation rate in learning units or the number of voluntary reports of genuine suspected cases, which show whether the security culture is actually taking hold and not just the obligation being fulfilled.

How much this can develop is shown by the 2025 phishing benchmark report from the provider KnowBe4 (based on more than 14 million users): The average click rate was initially 33.1%, fell by around 40% after three months of training and to 4.1% after twelve months. These figures come from a provider with its own interests and are to be understood as a guide, not as official statistics – but the order of magnitude matches industry experience that continuous training significantly reduces the click rate.

Building block 5: frequency and maturity

How often is enough? There is no universally applicable statutory frequency. A rhythm of initial training during onboarding, annual refreshers, and accompanying microlearning over the year, supplemented by regular simulations, has proven effective. What makes sense is maturity-level thinking in stages: At the beginning come the basics, a first baseline measurement, and establishing a simple reporting channel. In the intermediate stage, role-specific content, regular simulations, and first metric targets are added. In the mature stage, security is part of the corporate culture: Reports are a matter of course, managers lead by example, and the program is readjusted based on data.

The goal shifts over time – from "building knowledge" to "making secure behavior a habit". It is important to assess your own maturity level realistically and to aim for the next stage instead of lumping every organization together. A small team with a first baseline faces different tasks than a corporation with an established reporting process – the next sensible step is different in each case.

At the same time, awareness is part of recognized frameworks: ISO/IEC 27001 requires awareness raising and training, and within the scope of NIS-2, "basic training and awareness-raising measures" are among the minimum measures (Section 30 (2) of the BSI Act (BSIG)). A documented program thus contributes directly to regulatory requirements and, in the event of an inspection or audit, provides proof that awareness raising is carried out in a planned and recurring manner.

Common pitfalls

Many programs fail not because of a lack of will but because of avoidable mistakes. The most common:

  • One-off annual training course instead of continuous training
  • Exposing individuals in simulations
  • Outdated content that ignores current threats
  • Lack of success measurement and KPIs
  • Lack of backing from management
  • No open reporting culture

It is striking that most of these mistakes are organizational rather than technical in nature. They can be avoided with clear responsibilities, a fixed editorial plan for the content, and visible support from the management level – the latter often has a stronger effect than any single training module because it signals that security is a matter for the top. Anyone who avoids these points is halfway there – the rest is consistent, lasting implementation.

Build it yourself or use a ready-made solution?

The building blocks show: An effective program is less a question of good will than of ongoing implementation – maintaining content, keeping up the frequency, running simulations, evaluating KPIs, and providing follow-up training. Anyone who does not want to handle this ongoing effort entirely internally can fall back on standardized formats.

A note on our own behalf: This is exactly where ready-made solutions come in. Bridgly bundles microlearning, up-to-date content, phishing simulations, and evaluation in standardized awareness and information security training courses that can be rolled out via a learning platform and verified with documentation – without a program having to be designed internally from scratch. The building blocks described thus result in a program that can be operated with manageable internal setup effort and evaluated using the metrics mentioned.

FAQ

How often should awareness training take place?

There is no fixed statutory frequency. A three-part rhythm has proven effective: initial training during onboarding, an annual refresher, and accompanying microlearning spread over the year, supplemented by regular phishing simulations. What matters is less the exact timing than continuity – a reliable, recurring rhythm that the organization sustains permanently has a stronger effect than infrequent large events.

Which KPIs are most important for an awareness program?

The most common are three metrics: the phishing click rate (Phish-prone Percentage), the reporting rate of suspicious messages, and the time-to-report. They are only meaningful in combination – a falling click rate with a simultaneously rising reporting rate shows that knowledge is actually turning into secure behavior. Considered individually, each of these figures can be deceptive and should therefore always be read as a trend.

What is microlearning in the awareness context?

Microlearning consists of short, focused learning units of a few minutes that are spread over the year and repeated at increasing intervals. They counteract the forgetting curve, are easier to integrate into everyday work than long individual training courses, and keep the topic of security permanently present instead of dealing with it once a year in a mandatory event lasting several hours.

Are phishing simulations legally permissible?

They are a widespread and, in principle, permissible instrument but touch on co-determination and data protection. As a rule, the works council must be involved, and the evaluation should be data-minimizing and without personal sanctions – the goal is learning, not exposing individuals. The specific design should be legally reviewed on a case-by-case basis and properly documented.

Sources

More blog posts

Insights into the future of digital learning, with a focus on AI, compliance, and modern training solutions. Discover the latest posts and articles to gain practical insights into legally compliant, efficient, and automated corporate training.

Note: Some text, images, and videos on this website were generated using artificial intelligence.
All content is for informational purposes and has been carefully reviewed from a journalistic perspective, but does not claim to be exhaustive or legally binding.