{"id":46547,"date":"2026-09-15T21:16:01","date_gmt":"2026-09-15T19:16:01","guid":{"rendered":"https:\/\/smartfense.com\/?p=46547"},"modified":"2026-09-15T21:16:28","modified_gmt":"2026-09-15T19:16:28","slug":"prove-to-the-board-the-program-protects","status":"publish","type":"post","link":"https:\/\/smartfense.com\/en\/blog\/prove-to-the-board-the-program-protects\/","title":{"rendered":"How to prove to the board that your awareness program protects"},"content":{"rendered":"<p>The board always asks the same thing, and it asks it the same way. Does this protect us, or is it a compliance requirement we sign once a year? The four earlier pieces in this series followed a suspicious email from the button to the security team\u2019s decision. This last one looks at the same month from the meeting room, because reporting an email does not end when the case closes. It goes back into the awareness program and changes what each person gets afterwards. The numbers come from one specific organization, the same one as the earlier pieces, and not from sector averages.<\/p>\n<h2>What does a reported email say about the person who reported it?<\/h2>\n<p>There is a way of looking at email reporting that keeps it permanently on the operational security side. Somebody speaks up, somebody reviews, the case closes. It works, and it wastes half the information.<\/p>\n<p>When Luc\u00eda, in operations, reports a real email that felt wrong to her, she is demonstrating exactly the behavior the program set out to build. A report is a behavioral signal, because it identifies who recognizes an attack, with what judgement, and how long they take to speak up. That says more about the state of the culture than any training attendance percentage, and it should not die inside the case.<\/p>\n<p>Inside the platform that has two separate outcomes, and they are worth keeping apart.<\/p>\n<p>A reported real email can trigger a Nudge, which is a message the platform sends to a person when a given event happens. In email reporting there are five events that fire one.<\/p>\n<ul>\n<li>A user reports an email that is not a phishing simulation.<\/li>\n<li>A user reports a phishing simulation email.<\/li>\n<li>A reported real email is classified as phishing.<\/li>\n<li>A reported real email is classified as a false alarm.<\/li>\n<li>A reported real email is reclassified by hand.<\/li>\n<\/ul>\n<p>The first two happen at the moment of the report, so the answer goes out without waiting for any verdict. The next three happen when the case is resolved, and they are the ones that let you tell the person something that was not known yet when they pressed the button.<\/p>\n<p>That is where the answer Luc\u00eda actually notices comes from. The message reaches her by email, by Slack or by Microsoft Teams, and each channel carries its own subject and its own text. It is the same mechanism behind the <a href=\"https:\/\/smartfense.com\/en\/blog\/cybersecurity-nudges-timing-decides\/\">nudges at the right moment<\/a> this blog has covered, triggered this time by correct behavior instead of by a mistake.<\/p>\n<p>Simulations, on the other hand, feed the person\u2019s profile. Reporting a simulation counts towards their resilience ratio, which tracks how many simulations they report for every one they fall for, and it is what makes that person eligible for the awareness references report, the named list of the people who keep the good behavior going. There the report counts in their favor, next to the <a href=\"https:\/\/smartfense.com\/en\/blog\/human-risk-score-siem-signals\/\">signals that count against<\/a>.<\/p>\n<h2>How does the circle between the simulation and the report close?<\/h2>\n<p>Seen from a distance, the full journey has five legs.<\/p>\n<ol>\n<li><strong>You simulate<\/strong> an attack in a controlled setting.<\/li>\n<li>The person <strong>learns<\/strong> to recognize it and to report it, and that stays in their profile.<\/li>\n<li>Over time they <strong>report real emails too<\/strong>, which is the leap that actually matters.<\/li>\n<li>Those reports <strong>get classified without anyone stepping in<\/strong> and return a verdict instead of a task.<\/li>\n<li>The answer <strong>goes back to the person<\/strong> right away, and the month\u2019s activity stays visible in the reports console.<\/li>\n<\/ol>\n<p>The leg that was missing for years was the fourth, and without it the third burns out on its own. <a href=\"https:\/\/smartfense.com\/en\/blog\/phishing-reporting-habit-no-response\/\">The second piece in this series<\/a> explained why. A channel that never answers teaches the organization that speaking up is paperwork.<\/p>\n<h2>Which three phishing reporting metrics do program owners watch?<\/h2>\n<p>None of the three is the total number of emails processed.<\/p>\n<p><strong>How many simulations get reported.<\/strong> The report rate measures what share of the simulations received ended up reported, and the platform also places it against a sector benchmark so the figure is not left hanging. In the organization of this series it was 62%. It answers the question that comes before every other one. Do your people recognize an attack and speak up?<\/p>\n<p>Next to that rate sits a figure almost nobody looks at and that is worth as much. The exposure window of each campaign overlays the typical time it takes someone to fall with the typical time it takes someone to report. When the reporting curve runs ahead of the falling curve, your organization speaks up before it makes a mistake.<\/p>\n<p><strong>What the automatic analysis resolved this month.<\/strong> The dashboard separates the emails that automatic classification marked as phishing from the ones it dismissed as false alarms. In the month of this story that was 23 real attacks and 160 false alarms out of 183 reports. There is one caveat for reading that figure properly, which is that it only counts what the analysis resolved on its own within the current month, so an email somebody later reclassified by hand drops out of the figure.<\/p>\n<p>The reported-email listing shows who reported each one, so telling apart the people who speak up with judgement from the ones who report anything that strikes them as odd is a reading you do there and not an indicator the dashboard computes. They are two different conversations and both are useful, though neither gets settled by looking at an average.<\/p>\n<p>That 23 out of 183 reads easily as a user precision problem, and it is not one. Most reports turning out harmless is the expected consequence of having alert people, and <a href=\"https:\/\/smartfense.com\/en\/blog\/who-opens-the-phishing-reports\/\">the first piece in the series<\/a> argued that this is the healthy scenario. What matters is that the 23 showed up, and that people found them.<\/p>\n<p><strong>How many reports are still waiting for a decision.<\/strong> It is a running total with no date cut-off, so one left open three months ago still counts today. Before automatic triage that number was 47, and some had been waiting three days. It is the program\u2019s real debt and the only one of the three that should trend towards zero.<\/p>\n<h2>What do you answer when the board asks whether the program protects?<\/h2>\n<p>Two numbers, and neither of them is activity.<\/p>\n<p>The first, <strong>23 real phishing emails detected by employees in one month<\/strong>, and not by email security or by the firewall. People found them, because they saw something off and pressed a button.<\/p>\n<p>The second, <strong>four minutes between the report and the classification of the incident<\/strong>, instead of the three days the queue used to take. That is the window during which an attack stays alive in everyone else\u2019s inbox.<\/p>\n<p>Both answer the question the board is really asking, which is not how many people completed the training. And they come with an advantage over the quarterly report, because they are available the day somebody asks for them. If the underlying problem is that <a href=\"https:\/\/smartfense.com\/en\/blog\/board-level-reporting-ai-two-minutes\/\">the report reaches the meeting too late<\/a>, that gets solved separately.<\/p>\n<h2>What is worth watching six months from now?<\/h2>\n<p>Two things, and both are trends.<\/p>\n<p>The first is whether the habit is growing. Month after month, more people report, and they report outside of simulations too. The monthly activity of the last six months is on the dashboard for exactly that, because one month on its own says nothing and six in a row do.<\/p>\n<p>The second is the debt, measured in how many reports are still waiting for a decision. If that number falls while the first one rises, the program improved in both of the ways that matter at once, and neither of them cost extra hours.<\/p>\n<p>That crossover is also the answer to a fair objection that turns up in any board meeting. An awareness program that only shows more activity may be generating more internal work without reducing any risk. When activity rises and the queue does not, the organization moved to processing more threats with the same team, which is a different claim and a considerably harder one to argue with.<\/p>\n<h2>Is an empty mailbox a good sign?<\/h2>\n<p>It depends on why it is empty, and the two possible explanations are opposites. It may be that your organization is calm. It may be that it stopped speaking up.<\/p>\n<p>What you want is the opposite of an empty mailbox. People who report without hesitating, reports that get resolved without queuing, and a security team spending its time on the emails that deserve it.<\/p>\n<blockquote>\n<p>The report button is a human layer of defense with automatic analysis behind it.<\/p>\n<\/blockquote>\n<p>And when that layer has to talk to the rest of the organization, the same event can leave the platform. A Playbook calls your own system through a webhook, or notifies whoever needs to know by email, Slack or Microsoft Teams, from the area lead to the SOC on duty.<\/p>\n<p>That is how Smart Triage works inside the <a href=\"https:\/\/smartfense.com\/en\/platform\/reports-and-auditing\/\">reports console<\/a> of SMARTFENSE, over the emails your people report with the button. If you want to see these three numbers with your own organization\u2019s data, the shortest route is a <a href=\"https:\/\/smartfense.com\/en\/demo\/\">demo of the platform<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Which phishing reporting metrics program owners watch, how the report gets back to the person who sent it, and the two numbers that answer the board.<\/p>\n","protected":false},"author":2,"featured_media":46542,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[3,686],"tags":[454,2068,849,2197,2064],"class_list":["post-46547","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blog","tag-ciso-en","tag-metricas-de-seguridad","tag-phishing-en","tag-programa-de-concienciacion","tag-reporte-de-phishing"],"acf":[],"yoast_head":" \n<title>Prove to the board that your program protects<\/title>\n<meta name=\"description\" content=\"Which phishing reporting metrics program owners watch, how the report gets back to the person who sent it, and the two numbers that answer the board.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/smartfense.com\/en\/blog\/prove-to-the-board-the-program-protects\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Prove to the board that your program protects\" \/>\n<meta property=\"og:description\" content=\"Which phishing reporting metrics program owners watch, how the report gets back to the person who sent it, and the two numbers that answer the board.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/smartfense.com\/en\/blog\/prove-to-the-board-the-program-protects\/\" \/>\n<meta property=\"og:site_name\" content=\"SMARTFENSE\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-15T19:16:01+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-15T19:16:28+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/smartfense.com\/file\/2026\/09\/hero-en-2.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1920\" \/>\n\t<meta property=\"og:image:height\" content=\"1080\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Nicol\u00e1s Bruna\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Nicol\u00e1s Bruna\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"8 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/blog\\\/prove-to-the-board-the-program-protects\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/blog\\\/prove-to-the-board-the-program-protects\\\/\"},\"author\":{\"name\":\"Nicol\u00e1s Bruna\",\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/#\\\/schema\\\/person\\\/5494c12e79213c554fa449135589c24c\"},\"headline\":\"How to prove to the board that your awareness program protects\",\"datePublished\":\"2026-09-15T19:16:01+00:00\",\"dateModified\":\"2026-09-15T19:16:28+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/blog\\\/prove-to-the-board-the-program-protects\\\/\"},\"wordCount\":1539,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/blog\\\/prove-to-the-board-the-program-protects\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/smartfense.com\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/hero-en-2.png\",\"keywords\":[\"ciso\",\"m\u00e9tricas de seguridad\",\"phishing\",\"programa de concienciaci\u00f3n\",\"reporte de phishing\"],\"articleSection\":[\"Blog\",\"Blog\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/smartfense.com\\\/en\\\/blog\\\/prove-to-the-board-the-program-protects\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/blog\\\/prove-to-the-board-the-program-protects\\\/\",\"url\":\"https:\\\/\\\/smartfense.com\\\/en\\\/blog\\\/prove-to-the-board-the-program-protects\\\/\",\"name\":\"Prove to the board that your program protects\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/blog\\\/prove-to-the-board-the-program-protects\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/blog\\\/prove-to-the-board-the-program-protects\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/smartfense.com\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/hero-en-2.png\",\"datePublished\":\"2026-09-15T19:16:01+00:00\",\"dateModified\":\"2026-09-15T19:16:28+00:00\",\"description\":\"Which phishing reporting metrics program owners watch, how the report gets back to the person who sent it, and the two numbers that answer the board.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/blog\\\/prove-to-the-board-the-program-protects\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/smartfense.com\\\/en\\\/blog\\\/prove-to-the-board-the-program-protects\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/blog\\\/prove-to-the-board-the-program-protects\\\/#primaryimage\",\"url\":\"https:\\\/\\\/smartfense.com\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/hero-en-2.png\",\"contentUrl\":\"https:\\\/\\\/smartfense.com\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/hero-en-2.png\",\"width\":1920,\"height\":1080,\"caption\":\"Diagram of the full email reporting circle in five steps, simulate, learn, report, classify and give back, with an arrow that closes the loop and returns to the first step\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/blog\\\/prove-to-the-board-the-program-protects\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Portada\",\"item\":\"https:\\\/\\\/smartfense.com\\\/en\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"How to prove to the board that your awareness program protects\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/smartfense.com\\\/en\\\/\",\"name\":\"SMARTFENSE - Concienciaci\u00f3n en Ciberseguridad\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/smartfense.com\\\/en\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/#organization\",\"name\":\"SMARTFENSE\",\"url\":\"https:\\\/\\\/smartfense.com\\\/en\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/smartfense.com\\\/wp-content\\\/uploads\\\/2023\\\/08\\\/logo-smartfense-240x40-1.png\",\"contentUrl\":\"https:\\\/\\\/smartfense.com\\\/wp-content\\\/uploads\\\/2023\\\/08\\\/logo-smartfense-240x40-1.png\",\"width\":241,\"height\":40,\"caption\":\"SMARTFENSE\"},\"image\":{\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"description\":\"SMARTFENSE es una plataforma SaaS de concienciaci\u00f3n en seguridad de la informaci\u00f3n fundada en 2016. Combina capacitaci\u00f3n interactiva, simulaci\u00f3n de phishing, ransomware, smishing y USB drop, y m\u00e9tricas de riesgo humano. Dise\u00f1ada para Latinoam\u00e9rica, Espa\u00f1a, Portugal e Italia.\",\"foundingDate\":\"2016\",\"sameAs\":[\"https:\\\/\\\/www.linkedin.com\\\/company\\\/smartfense\\\/\"],\"knowsAbout\":[\"Concienciaci\u00f3n en ciberseguridad\",\"Security awareness training\",\"Simulaci\u00f3n de phishing\",\"Simulaci\u00f3n de ransomware\",\"Smishing\",\"Gesti\u00f3n del riesgo humano\",\"Cumplimiento normativo en seguridad de la informaci\u00f3n\"],\"areaServed\":[{\"@type\":\"Country\",\"name\":\"Argentina\"},{\"@type\":\"Country\",\"name\":\"Chile\"},{\"@type\":\"Country\",\"name\":\"Colombia\"},{\"@type\":\"Country\",\"name\":\"M\u00e9xico\"},{\"@type\":\"Country\",\"name\":\"Per\u00fa\"},{\"@type\":\"Country\",\"name\":\"Uruguay\"},{\"@type\":\"Country\",\"name\":\"Paraguay\"},{\"@type\":\"Country\",\"name\":\"Ecuador\"},{\"@type\":\"Country\",\"name\":\"Panam\u00e1\"},{\"@type\":\"Country\",\"name\":\"Costa Rica\"},{\"@type\":\"Country\",\"name\":\"Rep\u00fablica Dominicana\"},{\"@type\":\"Country\",\"name\":\"Guatemala\"},{\"@type\":\"Country\",\"name\":\"Bolivia\"},{\"@type\":\"Country\",\"name\":\"Brasil\"},{\"@type\":\"Country\",\"name\":\"Espa\u00f1a\"},{\"@type\":\"Country\",\"name\":\"Portugal\"},{\"@type\":\"Country\",\"name\":\"Italia\"}],\"slogan\":\"La plataforma online de concienciaci\u00f3n en Seguridad de la Informaci\u00f3n galardonada internacionalmente, que genera h\u00e1bitos seguros en los usuarios.\",\"founder\":{\"@type\":\"Person\",\"name\":\"Mauro Graziosi\",\"jobTitle\":\"CEO\",\"sameAs\":\"https:\\\/\\\/www.linkedin.com\\\/in\\\/mgraziosi\\\/\"},\"employee\":[{\"@type\":\"Person\",\"name\":\"Mauro Graziosi\",\"jobTitle\":\"CEO\",\"sameAs\":\"https:\\\/\\\/www.linkedin.com\\\/in\\\/mgraziosi\\\/\"},{\"@type\":\"Person\",\"name\":\"Mauro S\u00e1nchez\",\"jobTitle\":\"CTO\",\"sameAs\":\"https:\\\/\\\/www.linkedin.com\\\/in\\\/maurolsanchez\\\/\"},{\"@type\":\"Person\",\"name\":\"Leonardo Bally\",\"jobTitle\":\"COO\",\"sameAs\":\"https:\\\/\\\/www.linkedin.com\\\/in\\\/lbally\\\/\"},{\"@type\":\"Person\",\"name\":\"Nicol\u00e1s Bruna\",\"jobTitle\":\"Chief Product Officer\",\"sameAs\":\"https:\\\/\\\/www.linkedin.com\\\/in\\\/nicolasbruna\\\/\"},{\"@type\":\"Person\",\"name\":\"Carla Caggiano\",\"jobTitle\":\"Chief Content Officer\",\"sameAs\":\"https:\\\/\\\/www.linkedin.com\\\/in\\\/carla-v-caggiano\\\/\"},{\"@type\":\"Person\",\"name\":\"Salom\u00e9 Carpio\",\"jobTitle\":\"Global Head of Sales\",\"sameAs\":\"https:\\\/\\\/www.linkedin.com\\\/in\\\/salome-carpio\\\/\"},{\"@type\":\"Person\",\"name\":\"Andr\u00e9s Lista\",\"jobTitle\":\"Global Head of Alliances\",\"sameAs\":\"https:\\\/\\\/www.linkedin.com\\\/in\\\/andreslista\\\/\"},{\"@type\":\"Person\",\"name\":\"Ezequiel Azzarini\",\"jobTitle\":\"Sales Development Director\",\"sameAs\":\"https:\\\/\\\/www.linkedin.com\\\/in\\\/ezequielazzarini\\\/\"},{\"@type\":\"Person\",\"name\":\"Emilia Pal\u00e1\",\"jobTitle\":\"Head of People & Culture\",\"sameAs\":\"https:\\\/\\\/www.linkedin.com\\\/in\\\/mariaemiliapala\\\/\"},{\"@type\":\"Person\",\"name\":\"Florencia Carmel\u00e9\",\"jobTitle\":\"Administration Manager\",\"sameAs\":\"https:\\\/\\\/www.linkedin.com\\\/in\\\/mar%C3%ADa-florencia-carmele\\\/\"},{\"@type\":\"Person\",\"name\":\"Carolina Barlatay\",\"jobTitle\":\"Finance Manager\",\"sameAs\":\"https:\\\/\\\/www.linkedin.com\\\/in\\\/carolina-barlatay\\\/\"},{\"@type\":\"Person\",\"name\":\"Valeria Carena\",\"jobTitle\":\"Compliance Manager\",\"sameAs\":\"https:\\\/\\\/www.linkedin.com\\\/in\\\/valeriacarena\\\/\"}],\"numberOfEmployees\":{\"@type\":\"QuantitativeValue\",\"value\":63},\"address\":{\"@type\":\"PostalAddress\",\"streetAddress\":\"C\\\/ Santos Ovejero 1, Despacho P1-03\",\"addressLocality\":\"Le\u00f3n\",\"addressRegion\":\"Castilla y Le\u00f3n\",\"postalCode\":\"24008\",\"addressCountry\":\"ES\"},\"foundingLocation\":{\"@type\":\"Place\",\"address\":{\"@type\":\"PostalAddress\",\"addressRegion\":\"C\u00f3rdoba\",\"addressCountry\":\"AR\"}}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/smartfense.com\\\/en\\\/#\\\/schema\\\/person\\\/5494c12e79213c554fa449135589c24c\",\"name\":\"Nicol\u00e1s Bruna\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/b03096bf4c3dd886cfcffd7415eadf6f80d2c8126188409e7d4d1d1b6b911fcb?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/b03096bf4c3dd886cfcffd7415eadf6f80d2c8126188409e7d4d1d1b6b911fcb?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/b03096bf4c3dd886cfcffd7415eadf6f80d2c8126188409e7d4d1d1b6b911fcb?s=96&d=mm&r=g\",\"caption\":\"Nicol\u00e1s Bruna\"},\"description\":\"Product Manager de SMARTFENSE. Su misi\u00f3n en la empresa es mejorar la plataforma d\u00eda a d\u00eda y evangelizar sobre la importancia de la concienciaci\u00f3n. Ha escrito dos whitepapers y m\u00e1s de 150 art\u00edculos sobre gesti\u00f3n del riesgo de la ingenier\u00eda social, creaci\u00f3n de culturas seguras y cumplimiento de normativas. Tambi\u00e9n es uno de los autores de la Gu\u00eda de Ransomware de OWASP y el Calculador de costos de Ransomware, entre otros recursos gratuitos.\",\"sameAs\":[\"https:\\\/\\\/www.linkedin.com\\\/in\\\/nicolasbruna\\\/\"],\"url\":\"https:\\\/\\\/smartfense.com\\\/en\\\/author\\\/nicolas\\\/\"}]}<\/script>\n ","yoast_head_json":{"title":"Prove to the board that your program protects","description":"Which phishing reporting metrics program owners watch, how the report gets back to the person who sent it, and the two numbers that answer the board.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/smartfense.com\/en\/blog\/prove-to-the-board-the-program-protects\/","og_locale":"en_US","og_type":"article","og_title":"Prove to the board that your program protects","og_description":"Which phishing reporting metrics program owners watch, how the report gets back to the person who sent it, and the two numbers that answer the board.","og_url":"https:\/\/smartfense.com\/en\/blog\/prove-to-the-board-the-program-protects\/","og_site_name":"SMARTFENSE","article_published_time":"2026-09-15T19:16:01+00:00","article_modified_time":"2026-09-15T19:16:28+00:00","og_image":[{"width":1920,"height":1080,"url":"https:\/\/smartfense.com\/file\/2026\/09\/hero-en-2.png","type":"image\/png"}],"author":"Nicol\u00e1s Bruna","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Nicol\u00e1s Bruna","Est. reading time":"8 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/smartfense.com\/en\/blog\/prove-to-the-board-the-program-protects\/#article","isPartOf":{"@id":"https:\/\/smartfense.com\/en\/blog\/prove-to-the-board-the-program-protects\/"},"author":{"name":"Nicol\u00e1s Bruna","@id":"https:\/\/smartfense.com\/en\/#\/schema\/person\/5494c12e79213c554fa449135589c24c"},"headline":"How to prove to the board that your awareness program protects","datePublished":"2026-09-15T19:16:01+00:00","dateModified":"2026-09-15T19:16:28+00:00","mainEntityOfPage":{"@id":"https:\/\/smartfense.com\/en\/blog\/prove-to-the-board-the-program-protects\/"},"wordCount":1539,"commentCount":0,"publisher":{"@id":"https:\/\/smartfense.com\/en\/#organization"},"image":{"@id":"https:\/\/smartfense.com\/en\/blog\/prove-to-the-board-the-program-protects\/#primaryimage"},"thumbnailUrl":"https:\/\/smartfense.com\/file\/2026\/09\/hero-en-2.png","keywords":["ciso","m\u00e9tricas de seguridad","phishing","programa de concienciaci\u00f3n","reporte de phishing"],"articleSection":["Blog","Blog"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/smartfense.com\/en\/blog\/prove-to-the-board-the-program-protects\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/smartfense.com\/en\/blog\/prove-to-the-board-the-program-protects\/","url":"https:\/\/smartfense.com\/en\/blog\/prove-to-the-board-the-program-protects\/","name":"Prove to the board that your program protects","isPartOf":{"@id":"https:\/\/smartfense.com\/en\/#website"},"primaryImageOfPage":{"@id":"https:\/\/smartfense.com\/en\/blog\/prove-to-the-board-the-program-protects\/#primaryimage"},"image":{"@id":"https:\/\/smartfense.com\/en\/blog\/prove-to-the-board-the-program-protects\/#primaryimage"},"thumbnailUrl":"https:\/\/smartfense.com\/file\/2026\/09\/hero-en-2.png","datePublished":"2026-09-15T19:16:01+00:00","dateModified":"2026-09-15T19:16:28+00:00","description":"Which phishing reporting metrics program owners watch, how the report gets back to the person who sent it, and the two numbers that answer the board.","breadcrumb":{"@id":"https:\/\/smartfense.com\/en\/blog\/prove-to-the-board-the-program-protects\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/smartfense.com\/en\/blog\/prove-to-the-board-the-program-protects\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/smartfense.com\/en\/blog\/prove-to-the-board-the-program-protects\/#primaryimage","url":"https:\/\/smartfense.com\/file\/2026\/09\/hero-en-2.png","contentUrl":"https:\/\/smartfense.com\/file\/2026\/09\/hero-en-2.png","width":1920,"height":1080,"caption":"Diagram of the full email reporting circle in five steps, simulate, learn, report, classify and give back, with an arrow that closes the loop and returns to the first step"},{"@type":"BreadcrumbList","@id":"https:\/\/smartfense.com\/en\/blog\/prove-to-the-board-the-program-protects\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Portada","item":"https:\/\/smartfense.com\/en\/"},{"@type":"ListItem","position":2,"name":"How to prove to the board that your awareness program protects"}]},{"@type":"WebSite","@id":"https:\/\/smartfense.com\/en\/#website","url":"https:\/\/smartfense.com\/en\/","name":"SMARTFENSE - Concienciaci\u00f3n en Ciberseguridad","description":"","publisher":{"@id":"https:\/\/smartfense.com\/en\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/smartfense.com\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/smartfense.com\/en\/#organization","name":"SMARTFENSE","url":"https:\/\/smartfense.com\/en\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/smartfense.com\/en\/#\/schema\/logo\/image\/","url":"https:\/\/smartfense.com\/file\/2023\/08\/logo-smartfense-240x40-1.png","contentUrl":"https:\/\/smartfense.com\/file\/2023\/08\/logo-smartfense-240x40-1.png","width":241,"height":40,"caption":"SMARTFENSE"},"image":{"@id":"https:\/\/smartfense.com\/en\/#\/schema\/logo\/image\/"},"description":"SMARTFENSE es una plataforma SaaS de concienciaci\u00f3n en seguridad de la informaci\u00f3n fundada en 2016. Combina capacitaci\u00f3n interactiva, simulaci\u00f3n de phishing, ransomware, smishing y USB drop, y m\u00e9tricas de riesgo humano. Dise\u00f1ada para Latinoam\u00e9rica, Espa\u00f1a, Portugal e Italia.","foundingDate":"2016","sameAs":["https:\/\/www.linkedin.com\/company\/smartfense\/"],"knowsAbout":["Concienciaci\u00f3n en ciberseguridad","Security awareness training","Simulaci\u00f3n de phishing","Simulaci\u00f3n de ransomware","Smishing","Gesti\u00f3n del riesgo humano","Cumplimiento normativo en seguridad de la informaci\u00f3n"],"areaServed":[{"@type":"Country","name":"Argentina"},{"@type":"Country","name":"Chile"},{"@type":"Country","name":"Colombia"},{"@type":"Country","name":"M\u00e9xico"},{"@type":"Country","name":"Per\u00fa"},{"@type":"Country","name":"Uruguay"},{"@type":"Country","name":"Paraguay"},{"@type":"Country","name":"Ecuador"},{"@type":"Country","name":"Panam\u00e1"},{"@type":"Country","name":"Costa Rica"},{"@type":"Country","name":"Rep\u00fablica Dominicana"},{"@type":"Country","name":"Guatemala"},{"@type":"Country","name":"Bolivia"},{"@type":"Country","name":"Brasil"},{"@type":"Country","name":"Espa\u00f1a"},{"@type":"Country","name":"Portugal"},{"@type":"Country","name":"Italia"}],"slogan":"La plataforma online de concienciaci\u00f3n en Seguridad de la Informaci\u00f3n galardonada internacionalmente, que genera h\u00e1bitos seguros en los usuarios.","founder":{"@type":"Person","name":"Mauro Graziosi","jobTitle":"CEO","sameAs":"https:\/\/www.linkedin.com\/in\/mgraziosi\/"},"employee":[{"@type":"Person","name":"Mauro Graziosi","jobTitle":"CEO","sameAs":"https:\/\/www.linkedin.com\/in\/mgraziosi\/"},{"@type":"Person","name":"Mauro S\u00e1nchez","jobTitle":"CTO","sameAs":"https:\/\/www.linkedin.com\/in\/maurolsanchez\/"},{"@type":"Person","name":"Leonardo Bally","jobTitle":"COO","sameAs":"https:\/\/www.linkedin.com\/in\/lbally\/"},{"@type":"Person","name":"Nicol\u00e1s Bruna","jobTitle":"Chief Product Officer","sameAs":"https:\/\/www.linkedin.com\/in\/nicolasbruna\/"},{"@type":"Person","name":"Carla Caggiano","jobTitle":"Chief Content Officer","sameAs":"https:\/\/www.linkedin.com\/in\/carla-v-caggiano\/"},{"@type":"Person","name":"Salom\u00e9 Carpio","jobTitle":"Global Head of Sales","sameAs":"https:\/\/www.linkedin.com\/in\/salome-carpio\/"},{"@type":"Person","name":"Andr\u00e9s Lista","jobTitle":"Global Head of Alliances","sameAs":"https:\/\/www.linkedin.com\/in\/andreslista\/"},{"@type":"Person","name":"Ezequiel Azzarini","jobTitle":"Sales Development Director","sameAs":"https:\/\/www.linkedin.com\/in\/ezequielazzarini\/"},{"@type":"Person","name":"Emilia Pal\u00e1","jobTitle":"Head of People & Culture","sameAs":"https:\/\/www.linkedin.com\/in\/mariaemiliapala\/"},{"@type":"Person","name":"Florencia Carmel\u00e9","jobTitle":"Administration Manager","sameAs":"https:\/\/www.linkedin.com\/in\/mar%C3%ADa-florencia-carmele\/"},{"@type":"Person","name":"Carolina Barlatay","jobTitle":"Finance Manager","sameAs":"https:\/\/www.linkedin.com\/in\/carolina-barlatay\/"},{"@type":"Person","name":"Valeria Carena","jobTitle":"Compliance Manager","sameAs":"https:\/\/www.linkedin.com\/in\/valeriacarena\/"}],"numberOfEmployees":{"@type":"QuantitativeValue","value":63},"address":{"@type":"PostalAddress","streetAddress":"C\/ Santos Ovejero 1, Despacho P1-03","addressLocality":"Le\u00f3n","addressRegion":"Castilla y Le\u00f3n","postalCode":"24008","addressCountry":"ES"},"foundingLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressRegion":"C\u00f3rdoba","addressCountry":"AR"}}},{"@type":"Person","@id":"https:\/\/smartfense.com\/en\/#\/schema\/person\/5494c12e79213c554fa449135589c24c","name":"Nicol\u00e1s Bruna","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/b03096bf4c3dd886cfcffd7415eadf6f80d2c8126188409e7d4d1d1b6b911fcb?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/b03096bf4c3dd886cfcffd7415eadf6f80d2c8126188409e7d4d1d1b6b911fcb?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/b03096bf4c3dd886cfcffd7415eadf6f80d2c8126188409e7d4d1d1b6b911fcb?s=96&d=mm&r=g","caption":"Nicol\u00e1s Bruna"},"description":"Product Manager de SMARTFENSE. Su misi\u00f3n en la empresa es mejorar la plataforma d\u00eda a d\u00eda y evangelizar sobre la importancia de la concienciaci\u00f3n. Ha escrito dos whitepapers y m\u00e1s de 150 art\u00edculos sobre gesti\u00f3n del riesgo de la ingenier\u00eda social, creaci\u00f3n de culturas seguras y cumplimiento de normativas. Tambi\u00e9n es uno de los autores de la Gu\u00eda de Ransomware de OWASP y el Calculador de costos de Ransomware, entre otros recursos gratuitos.","sameAs":["https:\/\/www.linkedin.com\/in\/nicolasbruna\/"],"url":"https:\/\/smartfense.com\/en\/author\/nicolas\/"}]}},"_links":{"self":[{"href":"https:\/\/smartfense.com\/en\/wp-json\/wp\/v2\/posts\/46547","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/smartfense.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/smartfense.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/smartfense.com\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/smartfense.com\/en\/wp-json\/wp\/v2\/comments?post=46547"}],"version-history":[{"count":3,"href":"https:\/\/smartfense.com\/en\/wp-json\/wp\/v2\/posts\/46547\/revisions"}],"predecessor-version":[{"id":46563,"href":"https:\/\/smartfense.com\/en\/wp-json\/wp\/v2\/posts\/46547\/revisions\/46563"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/smartfense.com\/en\/wp-json\/wp\/v2\/media\/46542"}],"wp:attachment":[{"href":"https:\/\/smartfense.com\/en\/wp-json\/wp\/v2\/media?parent=46547"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/smartfense.com\/en\/wp-json\/wp\/v2\/categories?post=46547"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/smartfense.com\/en\/wp-json\/wp\/v2\/tags?post=46547"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}