News Date: 2026-09-11
A large analysis of simulated phishing activity is challenging one of the most common measurements used in corporate security-awareness programs. After examining 2.47 million simulations sent to more than 123,000 employees at over 1,200 organizations, researchers concluded that counting clicks can create a misleading picture of human risk.
A Click Is Not Necessarily a Breach
Opening a simulated phishing link may waste time or indicate poor judgment, but it does not automatically produce a security incident. The more consequential actions occur afterward, such as submitting credentials, approving an authentication request, downloading a file or failing to report the suspicious message.
The research separated employee behavior into clicking, leaking information and reporting. On their first simulation, more employees reportedly submitted a warning than clicked, yet 1.57 percent still disclosed credentials. In a company with 500 employees, that percentage could represent several accounts placed at immediate risk during a real campaign.
The data also challenges the assumption that technical departments are naturally resistant to social engineering. Approximately 30 percent of technology-development employees and more than 28 percent of IT personnel clicked at least one simulation. Results varied considerably across sectors and job functions, demonstrating why a single company-wide percentage can hide high-risk teams.
Building a Better Measurement Program
- Track credential submissions, file execution and authentication approvals separately from clicks.
- Measure how quickly employees report suspicious messages.
- Compare results by department, role and access level.
- Run sustained exercises rather than relying on an annual simulation.
- Provide immediate, relevant coaching after risky behavior.
- Combine training with phishing-resistant authentication and conditional-access controls.
The study found that reporting improved over time and eventually occurred nearly twice as often as clicking. However, click and credential-leak rates initially increased before declining, suggesting that short testing periods may produce unreliable conclusions.
Expert View
In my view, security leaders should stop presenting click rate as the primary measure of workforce resilience. A useful program should answer three questions: who exposed something valuable, who recognized the threat and who alerted the organization quickly enough to protect others? Training remains important, but it cannot carry the entire defense. Strong authentication, restricted privileges, rapid reporting channels and automated containment are necessary when a convincing message reaches someone who makes the wrong decision.
