Security Awareness Coverage Calculator
Score awareness programme coverage from completion rates, role-specific training, simulation cadence and behaviour change.
Inputs
Finance, HR, developers, administrators, executives
Awareness Coverage Score
59.5/ 100
Completion Rate
86.0%
Role-Specific Coverage
56.3%
Click Rate Reduction
55.6%
Report-to-Click Ratio
2.50×
Programme Rating
D — Weak
Biggest Gap
Contractors and third parties are excluded — they hold the same access and get none of the training
Step by step
Values used
People in scope = 2,500 people; Completed the annual module = 2,150 people; Contractors and third parties included = No; People in high-risk roles = 320 people; High-risk roles with role-specific training = 180 people; Phishing simulations per year = 4 per year; Click rate at programme start = 18 %; Click rate now = 8 %; Report rate now = 20 %
Security Awareness Coverage
coverage = (0.28×completion + 0.22×roleSpecific + 0.30×behaviourChange + 0.20×cadence) × scopeAdjustment, where behaviourChange combines click-rate reduction and the report-to-click ratio.
Awareness Coverage Score
= 59.5 / 100
Completion Rate
= 86.0
Role-Specific Coverage
= 56.3
Click Rate Reduction
= 55.6
Report-to-Click Ratio
= 2.50 ×
Programme Rating
= D — Weak
How it works
Completion is necessary and nearly meaningless on its own, so measured behaviour carries the largest single weight: whether clicking went down and whether reporting went up. Role-specific training is scored separately because the attacks aimed at finance, developers and executives have nothing in common with a generic module. Excluding contractors caps the score, since they typically hold equivalent access. A 98% completion rate with an unchanged click rate means you have documented training, not changed behaviour — and only one of those affects an incident.
Formula
Security Awareness Coverage
coverage = (0.28×completion + 0.22×roleSpecific + 0.30×behaviourChange + 0.20×cadence) × scopeAdjustment, where behaviourChange combines click-rate reduction and the report-to-click ratio.
- completion
- Share of in-scope people who finished the module
- roleSpecific
- High-risk roles receiving targeted content
- behaviourChange
- Measured improvement in click and report rates
- scopeAdjustment
- 0.85 if contractors are excluded from scope
Frequently Asked Questions
How is Security Awareness Coverage calculated?
coverage = (0.28×completion + 0.22×roleSpecific + 0.30×behaviourChange + 0.20×cadence) × scopeAdjustment, where behaviourChange combines click-rate reduction and the report-to-click ratio. Completion is necessary and nearly meaningless on its own, so measured behaviour carries the largest single weight: whether clicking went down and whether reporting went up. Role-specific training is scored separately because the attacks aimed at finance, developers and executives have nothing in common with a generic module. Excluding contractors caps the score, since they typically hold equivalent access.
Why does Security Awareness Coverage matter?
A 98% completion rate with an unchanged click rate means you have documented training, not changed behaviour — and only one of those affects an incident.
What values do I need to enter?
This calculator takes 9 inputs: People in scope, Completed the annual module, Contractors and third parties included, People in high-risk roles, High-risk roles with role-specific training, Phishing simulations per year, Click rate at programme start, Click rate now, Report rate now. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.
Is a report-to-click ratio above 1 realistic?
Yes, and mature programmes exceed 2. It comes from making reporting a single button, acknowledging every report, and never penalising a false report — people stop reporting the moment it feels risky or tedious.
Should simulation failures have consequences?
Punitive approaches reliably reduce reporting, which is worse than the clicks. Use extra coaching for repeat clickers and reserve formal process for wilful policy breaches rather than falling for a well-crafted lure.
You might also need
- Email Security Score CalculatorCommonly used together
- Insider Threat Risk CalculatorCommonly used together
- Phishing Risk CalculatorCommonly used together
- Kill Chain Coverage CalculatorAlso in Forensics & Emerging Threats
- Enterprise Cybersecurity Health Score CalculatorAlso in Forensics & Emerging Threats
- LLM Prompt Injection Risk CalculatorAlso in Forensics & Emerging Threats