# Completion is not success

A randomised anti-phishing study with 19,500 employees found no significant relationship between recent annual training completion and phishing susceptibility. Embedded training after a click reduced clicking by only about 2%. That is why this programme does not treat completion as the headline.

### Measures we use (kept separate — never collapsed into one opaque score)

| Layer | Example | Why it matters |
|---|---|---|
| Reach | Eligible people who started | Coverage only |
| Engagement | Sessions done, minutes used | Detects burden — not success |
| Learning | Change from baseline | Shows acquisition |
| **Retention** | Unprompted delayed score at 30 / 60 / 90 days | Tests durability |
| **Transfer** | Performance on a new scenario | Tests use beyond the memorised item |
| **Behaviour** | Manager observation or system event | Tests workplace execution |
| **Business** | Incident, quality, rework, time, or customer measure you already trust | Tests organisational value |
| Guardrail | Opt-outs, time cost, complaints, subgroup gaps | Detects harm |

### North-star for a Pilot

Percentage of critical objectives meeting a **pre-agreed delayed-readiness threshold** at the target date.

### What we refuse to sell as proof

- End-of-module quizzes as competence  
- Certificates of attendance  
- Satisfaction scores alone  
- Immediate post-tests without a delayed check  
- Vendor case studies from other industries presented as your expected result  

### What “good” looks like in the room

- People can explain a decision in their own words after a gap  
- Managers can point to the behaviour without reading a dashboard essay  
- The readout names failures as clearly as wins  

---
