Skip to content
  • Home
  • Resources
  • Blog
  • Security Awareness Training: How Phin Improves Reporting for MSPs

Security Awareness Training: How Phin Improves Reporting for MSPs

Blog graphic with the headline “Why Phin only reports what matters” in large navy text, with the word “reports” highlighted in orange. To the left is a tilted example of a Phin monthly security awareness report for a fictional Joe’s Pizza Shop, showing phishing simulation results, training completion grades, and a pie chart. Layered blue waves run across the bottom of the cream-colored background.

Key Points/TLDR

  • Reporting maturity isn't just more charts. It means using the right cybersecurity awareness training metrics to demonstrate measurable reductions in human risk and support client decision making.
  • Long-term behavioral trends are more useful than isolated campaign results. For example, Phin partner Kelley Create recorded a 72.66% reduction in overall phishing clicks across 148 clients from month 1 to month 36. That tells you ongoing training creates long-term value.
  • Phin Security helps MSPs improve reporting maturity by highlighting the metrics that matter most, making it easier to demonstrate ROI, support cyber insurance and compliance conversations, and deliver more meaningful Quarterly Business Reviews (QBRs).


Businesses invest in cybersecurity awareness training for one simple reason: they want to reduce human risk. Yet when it comes time to prove whether that investment is paying off, many MSPs unintentionally bury the answer beneath pages of charts, graphs, and percentages.

Modern security awareness platforms can produce an enormous amount of reporting data. That's useful from an administrative perspective, but it doesn't always help clients understand whether their employees are becoming better at recognizing threats.

This is where reporting maturity comes in. Mature reporting doesn’t obsess over more metrics and more data - it helps clients understand how their security posture is improving over time with quality, relevant data

If your clients leave every QBR understanding exactly how their organization has become more resilient, your reporting is doing its job.

 

What is reporting maturity?

Reporting maturity is the ability to collect meaningful data, interpret it correctly, and communicate it in a way that supports better business decisions.

An immature reporting process often focuses on quantity. Every available metric gets exported into a report because more feels better “Look at all this data” they say “and pat us on the back”. The result is often a document full of statistics but short on insight. We’re not talking about immaturity in the most common sense. People aren’t going into meetings armed with reports covered in phallic doodles like in Superbad (as funny as that may be to some).

A mature reporting process looks a bit different. Instead of asking "What can we measure?" it asks "What does our client actually need to know?"

For most clients, that comes down to a handful of pretty straightforward questions:

  • Are employees becoming better at identifying phishing emails?
  • Are users engaging with their security awareness training?
  • Is risky behavior decreasing over time?
  • Are we reducing the organization's overall exposure to social engineering attacks?

If your reporting answers those questions clearly, you've already achieved something far more valuable than producing another twenty-page report.

 

More data doesn't mean better reporting

It's easy to assume that adding more charts makes reporting more impressive, but it often has the opposite effect.

Imagine visiting your doctor for a routine check-up. Instead of explaining that your blood pressure is slightly high and suggesting a few practical lifestyle changes, they hand you a folder containing every measurement every machine in the hospital was capable of recording. The information might be accurate, but it wouldn't necessarily be useful if you don’t know what to look for and what it means.

Security awareness reporting works the same way. Clients rarely need to know every statistic your platform records. What they need is confidence that their investment is reducing risk. Reporting maturity means filtering out the noise and focusing on the metrics that tell that story.

Phin applies this principle to the product itself. For instance, Phin removes the "Phishes Reported" statistic from performance reports for companies that don’t have the Report Phishing Button enabled. If the metric isn't meaningful in context, there's little value in displaying it simply because the platform can.

 

The cybersecurity awareness training metrics that matter most

Every organization is different, but there are a few metrics that consistently demonstrate whether a security awareness training program is delivering meaningful results.

Phishing simulation click rates

One of the clearest indicators of behavioral change. Looking at a single campaign in isolation can be misleading. Perhaps a simulation was intentionally more difficult, or maybe it coincided with a busy period for the organization. Long-term trends tell a much more useful story.

If phishing simulation click rates have steadily fallen over six or twelve months, that's strong evidence that employees are becoming more effective at recognizing suspicious emails. Rather than saying "This month's click rate was 7%," a mature report explains "Click rates have fallen from 19% to 7% over the past six months." The percentage becomes evidence of progress rather than just another number.

Email reporting rates

One of the biggest misconceptions in cybersecurity awareness training is that more reported emails indicate more problems. In reality, higher reporting rates can demonstrate that employees are paying attention. Verizon's 2025 Data Breach Investigations Report found that users who had received training within the previous 30 days reported simulated phishing emails at a rate of around 21%, compared with a base rate of 5%.

An employee who reports a legitimate email because they aren't completely sure is usually behaving more safely than someone who confidently ignores every suspicious message. Tracking reporting rates alongside phishing simulation performance helps MSPs demonstrate improvements in security culture rather than simply measuring mistakes.

(And if there’s an influx of reported emails that becomes too overwhelming for your help desk, there’s a tool for that — free with Phin.)

Training completion

Training completion isn't the ultimate measure of success, but it remains an important indicator. Employees can't benefit from training they never complete.

Consistently high completion rates show that users are engaging with the program and give context to improvements in phishing simulation performance. Rather than treating completion as the end goal, mature reporting positions it as one part of a wider picture of behavioral change.

Trends over time

If there's one metric every MSP should prioritize, it's improvement over time. Clients aren't expecting perfection after a single phishing simulation or one training campaign. What they want to see is continuous improvement.

Showing how behaviors evolve across multiple quarters gives clients confidence that their investment is creating lasting change instead of temporary improvements. This long-term view also supports conversations around cybersecurity compliance standards and cyber insurance requirements, both of which increasingly emphasize ongoing security awareness rather than one-off training exercises.

Phin's own customer data demonstrates why that long-term view matters. Kelley Create manages SAT for 148 clients through Phin and recorded a 72.66% reduction in overall phishing clicks between month 1 and month 36. A single month's click rate couldn't tell that story, but three years of trend data can.

 

Turning reports into conversations

Great reporting doesn't end when the report is generated, or even when it’s read. It starts a conversation and suddenly instead of getting all “statisticsed out”, clients get an understanding of what those numbers actually mean for the business.

For example, saying that phishing simulation click rates have fallen by 60% is somewhat informative.

Explaining that this means significantly fewer employees are likely to compromise company credentials during a real phishing attack makes the value immediately understandable. The same applies to reporting rates, training engagement, and behavioral trends. The numbers matter, but the stories behind them matter even more.

This approach also helps clients communicate the value of cybersecurity awareness training internally, whether they're updating leadership teams, demonstrating progress during cyber insurance reviews, or preparing for compliance audits.

Check this blog out for more help speaking your clients’ language.

 

Signs your reporting process is becoming more mature

  • Clients ask better questions instead of more questions.
  • QBRs focus on business outcomes rather than individual charts.
  • Trends become more important than individual campaign results.
  • Recommendations naturally follow from the data.
  • Clients understand why you're recommending additional training.

 

Security Awareness Training Reporting with Phin Security

Phin Security provides automated security awareness training reporting designed specifically for MSPs, including behavioral performance metrics, phishing simulation results, training engagement data, and trends over time.

Reporting Quality

Rather than overwhelming users with unnecessary complexity, Phin's reporting focuses on the behavioral indicators that demonstrate whether (and how well) security awareness training is working.

Clear dashboards, straightforward trend reporting, and executive-friendly summaries make it easier to explain improvements during Quarterly Business Reviews and ongoing client conversations. Less time spent interpreting reports and more time discussing meaningful improvements to security posture.

For MSPs managing multiple customers, consistent reporting also creates a more repeatable QBR process. Every client receives reporting that’s focused, understandable, and aligned with the outcomes they actually care about.

Screenshot of part of Phin's reports with a fake company "Joe's Pizza Shop" displaying figurative metrics.

Ultimately, mature reporting boils down to consistently producing the most useful possible report, rather than the biggest one with the most charts and numbers.

By focusing on behavioral change instead of vanity metrics, and by making those insights easy to understand, Phin Security helps MSPs demonstrate the real impact of cybersecurity awareness training with confidence.

Reporting Consistency

Another piece of this is ensuring reports are sent when they’re supposed to. For MSPs like Krantz, a big reason they switched to Phin from another provider was because their previous provider was inconsistently sending reports that weren’t being sent to the right stakeholders. This means they weren’t able to accurately prove the value of the tool their clients’ money was going towards.

Secur-Serv and Fortify Technology also appreciate Phin’s automated reporting because it establishes a consistent process for reporting and saves their techs time because they don’t have to dig through the data themselves to build monthly reports.


Want a breakdown of metrics and what they mean that you can share with your clients? Check this out.


 

Frequently Asked Questions

What should I measure to know if security awareness training is working?

The most useful metrics include phishing simulation click rates, email reporting rates, training completion, and behavioral trends over time. Together, these provide a much clearer picture than any single statistic.

What security awareness training metrics are most useful to share with clients?

Focus on metrics that demonstrate business outcomes rather than platform activity. Clients generally benefit most from understanding how employee behavior has changed, how reporting habits have improved, and whether phishing risk is decreasing over time.

How often should MSPs share cybersecurity awareness training reports?

Most MSPs review results with clients during Quarterly Business Reviews for a better look at behavior change over time. However, it’s good to use monthly reports internally to keep a consistent pulse on trends and identify opportunities for additional training or phishing simulations.

How does Phin Security's reporting compare to other security awareness training platforms?

Many security awareness platforms provide extensive reporting capabilities. Phin Security focuses on presenting the behavioral metrics that matter most, making it easier for MSPs to communicate progress, demonstrate ROI, and have more meaningful conversations with clients.

 



 

Leave a comment: