Many organizations today participate in some form of Security Awareness training. Whether it be something that is produced internally or supplied by a third-party vendor, the goals are very much the same: educate the end user to prevent becoming the next big breach news story. We all know the phrase ‘you can't patch humans', but what metrics can we use to see if our awareness efforts and methods are effective? Believe it or not, as Security Analysts, we have a lot of valuable information at our fingertips that can show us just how effective these programs are… and no, I'm not just talking about the results of your last phishing campaign.