Cofense Says Phishing Training Should Measure Behavior Change, Not Compliance

Summary
Cofense argues that phishing defense should measure employees’ ability to recognize threats and connect that competency with real-world phishing and remediation signals, rather than relying on training completion or risk scores alone.
Key points
- The article argues that training completion, simulation results and risk scores do not by themselves show whether employees can recognize and respond to phishing.
- Cofense distinguishes phishing simulations, which provide practice, from observations of how people respond to real malicious emails.
- Its competency approach assesses knowledge across 26 phishing threat topics to help identify organizational strengths and gaps.
- Cofense says it plans to connect competency measures with real-world phishing reports and remediation signals from its platform.
- The article says measurements should guide different actions: targeted learning for knowledge gaps or stronger protection against sophisticated threats.
Article Details
- Topic
- Measuring phishing-recognition competency alongside real-world reporting and remediation to improve secure behavior
Vendors
Products
Cofense Command CenterIt’s why I’m excited about the Cofense Command Center. In October, I’ll go deeper into the first part of that work: how we are measuring competency, what the Competency Dashboard tells security teams, and where we areCompetency DashboardI’ll go deeper into the first part of that work: how we are measuring competency, what the Competency Dashboard tells security teams, and where we are taking it next.