Skip to content
Calcrivo

Security Awareness Coverage Calculator

Score awareness programme coverage from completion rates, role-specific training, simulation cadence and behaviour change.

Inputs

people
people
people

Finance, HR, developers, administrators, executives

people
per year
%
%
%

Awareness Coverage Score

59.5/ 100

Completion Rate

86.0%

Role-Specific Coverage

56.3%

Click Rate Reduction

55.6%

Report-to-Click Ratio

2.50×

Programme Rating

D — Weak

Biggest Gap

Contractors and third parties are excluded — they hold the same access and get none of the training

Step by step

  1. Values used

    People in scope = 2,500 people; Completed the annual module = 2,150 people; Contractors and third parties included = No; People in high-risk roles = 320 people; High-risk roles with role-specific training = 180 people; Phishing simulations per year = 4 per year; Click rate at programme start = 18 %; Click rate now = 8 %; Report rate now = 20 %

  2. Security Awareness Coverage

    coverage = (0.28×completion + 0.22×roleSpecific + 0.30×behaviourChange + 0.20×cadence) × scopeAdjustment, where behaviourChange combines click-rate reduction and the report-to-click ratio.

  3. Awareness Coverage Score

    = 59.5 / 100

  4. Completion Rate

    = 86.0

  5. Role-Specific Coverage

    = 56.3

  6. Click Rate Reduction

    = 55.6

  7. Report-to-Click Ratio

    = 2.50 ×

  8. Programme Rating

    = D — Weak

How it works

Completion is necessary and nearly meaningless on its own, so measured behaviour carries the largest single weight: whether clicking went down and whether reporting went up. Role-specific training is scored separately because the attacks aimed at finance, developers and executives have nothing in common with a generic module. Excluding contractors caps the score, since they typically hold equivalent access. A 98% completion rate with an unchanged click rate means you have documented training, not changed behaviour — and only one of those affects an incident.

Formula

Security Awareness Coverage

coverage = (0.28×completion + 0.22×roleSpecific + 0.30×behaviourChange + 0.20×cadence) × scopeAdjustment, where behaviourChange combines click-rate reduction and the report-to-click ratio.

completion
Share of in-scope people who finished the module
roleSpecific
High-risk roles receiving targeted content
behaviourChange
Measured improvement in click and report rates
scopeAdjustment
0.85 if contractors are excluded from scope

Frequently Asked Questions

How is Security Awareness Coverage calculated?

coverage = (0.28×completion + 0.22×roleSpecific + 0.30×behaviourChange + 0.20×cadence) × scopeAdjustment, where behaviourChange combines click-rate reduction and the report-to-click ratio. Completion is necessary and nearly meaningless on its own, so measured behaviour carries the largest single weight: whether clicking went down and whether reporting went up. Role-specific training is scored separately because the attacks aimed at finance, developers and executives have nothing in common with a generic module. Excluding contractors caps the score, since they typically hold equivalent access.

Why does Security Awareness Coverage matter?

A 98% completion rate with an unchanged click rate means you have documented training, not changed behaviour — and only one of those affects an incident.

What values do I need to enter?

This calculator takes 9 inputs: People in scope, Completed the annual module, Contractors and third parties included, People in high-risk roles, High-risk roles with role-specific training, Phishing simulations per year, Click rate at programme start, Click rate now, Report rate now. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.

Is a report-to-click ratio above 1 realistic?

Yes, and mature programmes exceed 2. It comes from making reporting a single button, acknowledging every report, and never penalising a false report — people stop reporting the moment it feels risky or tedious.

Should simulation failures have consequences?

Punitive approaches reliably reduce reporting, which is worse than the clicks. Use extra coaching for repeat clickers and reserve formal process for wilful policy breaches rather than falling for a well-crafted lure.

You might also need