Check what the event actually represents
Before discussing a result, define the event. Was it a page load, a link request, a form submission or a confirmed human interaction? Email-security tools and link previews can generate activity. The website does not claim a particular KeenSec filtering method; request evidence of the actual measurement pipeline.
Document how ambiguous events are treated. If you cannot distinguish automated and human activity, make that limitation part of the report rather than quietly treating every request as a click.
Keep the denominator visible
A percentage needs a population and a time window. Delivered messages, eligible recipients and people who actually encountered a scenario are not always the same group. Bounces, leave, new starters and repeat exposure can affect interpretation.
Show the numerator and denominator with the rate. Keep missing or excluded data visible so a reader can judge what the result covers.
Measure protective behavior too
Reporting can be a valuable response even when an employee initially interacts with a message. Consider whether the report arrived early enough to help, whether it contained useful context and whether the employee used the intended reporting path.
Do not collapse every behavior into a single success/failure outcome. A useful program distinguishes recognition, verification, reporting and unsafe actions, and connects them to the learning objective.
Reassess under comparable conditions
To understand a change over time, compare the audience, channel, scenario difficulty and requested action. A dramatic improvement after an easier test may tell you little about the original behavior.
Use a fresh scenario that tests the same decision. Record other changes that could matter, such as a new payment-verification process or reporting tool. Improvement may be associated with the intervention without proving it was caused by training alone.
Make the report actionable
A practical review can show the objective, baseline, intervention, next observation, coverage and limitations in one place. End with a decision: continue, adapt, investigate or gather more evidence.
NIST’s learning-program guidance emphasizes behavior change and ongoing evaluation. That supports using metrics to improve the program, rather than treating completion or a single campaign result as the final outcome.