Select a theme from the list.
Insights

From our experts

Latest
Phishing Study Finds Click Rates Are Hiding the Metrics That Actually MatterClaude Distillation Campaigns Turn AI Access Into an Industrial Data-Theft MarketCheck Point VPN Flaws Put Enterprise Gateways on an Urgent Patch ClockMicrosoft Maps the Hidden Attack Paths Connecting Serverless Apps to Cloud ControlBrevo Breach Turns Trusted Trezor Emails Into Wallet-Stealing PhishingCisco Firewall Manager Flaws Become Launchpads for Espionage and Qilin RansomwareGitLab File-Read Flaw Attracts Attackers Within a Day of DisclosureSogou Input Tool Turned a Trusted Windows Feature Into a Backdoor LauncherStolen Police Credentials Open Florida Driver Database to IntrudersGigabud Hides Banking Fraud Inside Android Work ProfilesSurfshark Test Server Breach Exposes the Security Gap Between Development and ProductionAI-Polished CEO Fraud Targets Finance Teams With Million-Email BlitzPhishing Study Finds Click Rates Are Hiding the Metrics That Actually MatterClaude Distillation Campaigns Turn AI Access Into an Industrial Data-Theft MarketCheck Point VPN Flaws Put Enterprise Gateways on an Urgent Patch ClockMicrosoft Maps the Hidden Attack Paths Connecting Serverless Apps to Cloud ControlBrevo Breach Turns Trusted Trezor Emails Into Wallet-Stealing PhishingCisco Firewall Manager Flaws Become Launchpads for Espionage and Qilin RansomwareGitLab File-Read Flaw Attracts Attackers Within a Day of DisclosureSogou Input Tool Turned a Trusted Windows Feature Into a Backdoor LauncherStolen Police Credentials Open Florida Driver Database to IntrudersGigabud Hides Banking Fraud Inside Android Work ProfilesSurfshark Test Server Breach Exposes the Security Gap Between Development and ProductionAI-Polished CEO Fraud Targets Finance Teams With Million-Email Blitz
Security Insight

Phishing Study Finds Click Rates Are Hiding the Metrics That Actually Matter

Phishing Study Finds Click Rates Are Hiding the Metrics That Actually Matter
Photo by Miguel Á. Padriñán on Pexels

Research based on 2.47 million simulated phishing attempts suggests that click rates alone provide an incomplete picture of employee risk. Credential submission and incident reporting offer more meaningful measurements, while sustained and role-aware exercises appear more useful than occasional generic tests.

News Date: 2026-09-11

A large analysis of simulated phishing activity is challenging one of the most common measurements used in corporate security-awareness programs. After examining 2.47 million simulations sent to more than 123,000 employees at over 1,200 organizations, researchers concluded that counting clicks can create a misleading picture of human risk.

A Click Is Not Necessarily a Breach

Opening a simulated phishing link may waste time or indicate poor judgment, but it does not automatically produce a security incident. The more consequential actions occur afterward, such as submitting credentials, approving an authentication request, downloading a file or failing to report the suspicious message.

The research separated employee behavior into clicking, leaking information and reporting. On their first simulation, more employees reportedly submitted a warning than clicked, yet 1.57 percent still disclosed credentials. In a company with 500 employees, that percentage could represent several accounts placed at immediate risk during a real campaign.

The data also challenges the assumption that technical departments are naturally resistant to social engineering. Approximately 30 percent of technology-development employees and more than 28 percent of IT personnel clicked at least one simulation. Results varied considerably across sectors and job functions, demonstrating why a single company-wide percentage can hide high-risk teams.

Building a Better Measurement Program

  • Track credential submissions, file execution and authentication approvals separately from clicks.
  • Measure how quickly employees report suspicious messages.
  • Compare results by department, role and access level.
  • Run sustained exercises rather than relying on an annual simulation.
  • Provide immediate, relevant coaching after risky behavior.
  • Combine training with phishing-resistant authentication and conditional-access controls.

The study found that reporting improved over time and eventually occurred nearly twice as often as clicking. However, click and credential-leak rates initially increased before declining, suggesting that short testing periods may produce unreliable conclusions.

Expert View

In my view, security leaders should stop presenting click rate as the primary measure of workforce resilience. A useful program should answer three questions: who exposed something valuable, who recognized the threat and who alerted the organization quickly enough to protect others? Training remains important, but it cannot carry the entire defense. Strong authentication, restricted privileges, rapid reporting channels and automated containment are necessary when a convincing message reaches someone who makes the wrong decision.

Talk to our team →

Latest

Phishing Study Finds Click Rates Are Hiding the Metrics That Actually MatterSep 14, 2026Claude Distillation Campaigns Turn AI Access Into an Industrial Data-Theft MarketSep 14, 2026Check Point VPN Flaws Put Enterprise Gateways on an Urgent Patch ClockSep 14, 2026Microsoft Maps the Hidden Attack Paths Connecting Serverless Apps to Cloud ControlSep 13, 2026Brevo Breach Turns Trusted Trezor Emails Into Wallet-Stealing PhishingSep 13, 2026Cisco Firewall Manager Flaws Become Launchpads for Espionage and Qilin RansomwareSep 13, 2026

Most read

1Microsoft Redraws the Security Boundary for Edge AI2Ted Implant Turns Compromised HAProxy Servers Into Invisible Interception Points3French Hospital Fine Turns Weak Identity Controls Into a GDPR Warning4IDScan Lawsuits Put Mass Identity Collection Under the Microscope5Scattered Spider's Cyberattack on Marks & Spencer Exposes Retail Vulnerabilities6Microsoft Prepares Windows Customers for a Faster Era of AI-Driven Patching