The Click Rate Problem
Ask most security teams how they measure phishing resilience and they will point to one number: the percentage of employees who clicked a simulated phishing email. That figure has become the default KPI for awareness programmes across industries, and organisations spend considerable time and budget trying to push it down. The problem is that click rate, on its own, is a poor proxy for actual resilience. Pistachio's Phishing Behaviour Report 2026 — which analysed 648 organisations and 123,692 users across a full 12-month period from June 2025 to May 2026 — challenges the assumption that a low click rate means a workforce is well-prepared. The research finds that phishing resilience is better understood through a combination of behavioural indicators, not a single pass/fail score on a simulated email. For UK and Australasian businesses running phishing simulation programmes, this is a significant finding. It suggests that organisations optimising solely for click reduction may be producing misleading confidence in their own security posture.
What Click Rates Actually Measure
Click rate captures one thing: whether an employee clicked a link in a test email. It tells you almost nothing about what happened next — whether the employee recognised something felt wrong and reported it, whether they entered credentials, or whether they simply navigated away without acting further. Here's the problem: simulation programmes designed to minimise clicks tend to use increasingly obvious phishing templates to make the metric look better. Employees learn to spot the simulations rather than the actual tactics attackers use. The result is a workforce that performs well in a controlled test environment but remains exposed to real-world attacks that deviate even slightly from the training material. There is also a reporting gap that click rate ignores entirely. An employee who spots a genuine phishing attempt and reports it is demonstrating active security behaviour. That action protects the organisation. An employee who does not click but also does not report adds nothing to the organisation's defences. Click rate treats both employees identically.
- Click rate does not distinguish between employees who recognised a threat and those who simply didn't see the email
- Low click rates can reflect easy simulations rather than genuine resilience
- The metric ignores reporting behaviour, which is a direct contribution to organisational defence
- It provides no signal about credential submission or post-click behaviour
What Phishing Resilience Actually Looks Like
The Pistachio report argues that resilience should be measured across a combination of behaviours. This framing aligns with how security teams should think about the human layer of defence: not as a pass/fail gate, but as a set of observable, improvable behaviours. A more complete picture of phishing resilience includes: Reporting rate: What percentage of employees who receive a suspicious email actively flag it? High reporting rates mean threats surface faster, giving security teams earlier visibility. Time to report: How quickly do employees raise the alarm? In a real attack, minutes matter. An organisation where employees report within ten minutes of receiving a suspicious email is meaningfully safer than one where reporting takes hours or does not happen at all. Repeat click behaviour: Are the same individuals clicking repeatedly across multiple simulations? Identifying persistent risk in specific users or departments allows targeted intervention rather than blanket retraining. Post-click behaviour: Did the employee submit credentials? Did they download an attachment? The severity of a real incident depends heavily on what happens after a click, not just whether the click occurred. Departmental variance: Which parts of the business carry the highest phishing risk? Finance, HR, and executive assistants handle the kinds of requests that social engineering attacks imitate. Understanding where risk concentrates allows proportionate investment.
Why This Matters for Security Teams Right Now
Phishing remains the entry point for a substantial proportion of successful breaches. The UK's NCSC consistently lists it among the most common initial access methods observed in incidents affecting British organisations. In New Zealand and Australia, the picture is similar — the Australian Cyber Security Centre's annual threat reports identify phishing as a persistent and effective attack vector across all sectors. Meanwhile, attackers are not standing still. Generative AI has lowered the barrier to producing convincing phishing content at scale. Business email compromise (BEC) attacks — which often require no malware at all, just a convincing impersonation — cost organisations globally billions of dollars annually. These attacks do not look like the template phishing emails that many simulation programmes rely on. If your measurement framework has not kept pace with how attacks have evolved, your programme is training employees to recognise yesterday's threats. A workforce that scores well on click rate against template simulations but has never encountered a spear-phishing attempt tailored to their organisation's context, their job role, or their current business activity is not resilient — it is untested. The Pistachio data covers nearly 124,000 users across 648 organisations. That is a meaningful sample, and the consistency of its finding — that multi-metric measurement produces a more accurate picture of resilience — carries weight.
How to Fix Your Phishing Programme Measurement
Changing what you measure does not necessarily mean overhauling your entire training approach. In practice, most organisations can expand their measurement framework with adjustments to how they run simulations and what data they collect from them. Start by introducing a report button. If your employees have no mechanism to report suspicious emails, you are losing the most valuable signal available to you. Phishing simulation platforms that include reporting functionality let you track both click rate and report rate simultaneously, giving you a ratio that is far more informative than either figure alone. Next, segment your results. Organisation-wide click rate averages obscure the variance that matters. A company where the finance team clicks 22% of simulations and the engineering team clicks 4% has a very different risk profile from one where the rate is uniformly 10%. Identifying high-risk populations lets you apply targeted training where it will have the greatest effect. Increase simulation difficulty progressively. If every simulation uses a generic 'your password is expiring' template, employees will learn to identify simulations rather than phishing tactics. Introducing contextually relevant lures — ones that reference the organisation's industry, current news, or common internal processes — produces a more honest picture of where vulnerabilities sit. Finally, track behaviour over time rather than point-in-time scores. Resilience is built through repeated exposure and correction, not a single training exercise. An employee who clicked in January and reported correctly in March is demonstrating improvement. That trajectory matters and click rate alone will never capture it.
- Add a phishing report button and track report rate alongside click rate
- Segment results by department, seniority, and role — not just organisation-wide averages
- Use progressively difficult simulations that reflect real attack tactics, not generic templates
- Measure behaviour change over a full 12-month cycle, not individual simulation snapshots
- Track post-click actions (credential entry, downloads) not just whether a click occurred
The Technology Layer Cannot Be Ignored
Better measurement improves your training programme. It does not replace the need for technical controls that stop phishing attacks before employees encounter them. The human layer will always carry some residual risk. No matter how well-trained a workforce is, a sufficiently targeted and convincing phishing attempt will eventually succeed. Security programmes that treat employee behaviour as the primary control, rather than a supporting layer, place disproportionate burden on individuals and leave the organisation exposed when that layer fails. Effective phishing defence requires technical controls that filter malicious emails before delivery, detect and block credential theft in real time, and flag unusual account behaviour that indicates a compromised identity. Measurement reform tells you how your people are performing. The technology layer determines what threats they never have to face in the first place.
How to Protect Your Business from Phishing Attacks
If this analysis has prompted a review of how your organisation approaches phishing risk, there are two areas worth acting on immediately. First, the measurement problem: review what data your current phishing simulation programme actually captures. If you are only tracking click rate, you are operating with incomplete information. The Pistachio Phishing Behaviour Report 2026 provides a useful framework for expanding your metrics — reporting rate, repeat-click behaviour, and post-click actions all belong in the picture. Second, the technical controls problem: employee training reduces risk, but it does not eliminate it. The organisations that suffer the least damage from phishing are the ones that combine a well-measured training programme with email security controls that filter threats upstream. For UK businesses, Coro provides unified email, endpoint, and cloud security designed to intercept phishing attempts before they reach the inbox. Coro's email security layer analyses inbound messages for indicators of compromise, blocks credential-harvesting links, and flags business email compromise patterns that bypass basic spam filters. You can find out more about Coro at /products/coro. For organisations in New Zealand and Australia, ESET's enterprise endpoint protection provides a comparable layer of defence, with email threat scanning built into its protection stack. More detail is available at /products/eset. Beyond email filtering, Sophos MDR provides 24/7 managed detection and response — meaning that when a phishing attempt does succeed and an attacker gains a foothold, a team of analysts is actively hunting for signs of that compromise and can contain the threat before it escalates. Details at /products/sophos. If you want an honest picture of where your organisation's phishing exposure sits right now, talk to our team. We can assess your current email security controls, review your awareness programme measurement framework, and identify the gaps that carry the most risk for your specific business context. Contact Kyanite Blue at /contact to start that conversation.
Frequently Asked Questions
What is a good phishing click rate for employee training programmes?
Click rate alone is not a reliable measure of phishing resilience. Research from Pistachio's 2026 Phishing Behaviour Report, covering 123,692 users across 648 organisations, found that a combination of metrics — including report rate, time to report, and repeat-click behaviour — provides a far more accurate picture than click rate in isolation. A low click rate on easy simulations can mask significant underlying risk.
How should organisations measure phishing resilience?
Effective phishing resilience measurement tracks multiple behaviours simultaneously: what percentage of employees report suspicious emails, how quickly they do so, whether specific individuals or departments show repeat click behaviour, and what actions employees take after clicking. Organisations that measure only click rate often develop false confidence in their security posture, particularly as attackers adopt more convincing, contextually relevant lures.
Can phishing simulation training alone protect a business from phishing attacks?
No. Phishing simulation training reduces the likelihood that employees will fall for common attacks, but it cannot eliminate human error entirely. Technical controls — including email filtering that blocks malicious messages before delivery, and managed detection and response services that identify compromised accounts — are essential layers that work alongside employee training, not as replacements for it.