Fixing the Flaw: Why Companies Are Measuring Phishing Resilience Wrong

www.news4hackers.com-fixing-the-flaw-why-companies-are-measuring-phishing-resilience-wrong-fixing-the-flaw-why-companies-are-measuring-phishing-resilience-wrong

Companies may be misjudging their employees’ cyber resilience by focusing solely on click rates, according to a new analysis.

Key Findings from the Phishing Behavior Report

A recent analysis of phishing simulation programs reveals that organizations may be misjudging their employees’ cyber resilience by focusing solely on click rates. According to Pistachio’s Phishing Behaviour Report 2026, resilience should be evaluated through a multifaceted approach that includes clicking behavior, credential submission, and reporting actions. The study examined 648 organizations with 123,692 users over a 12-month period from June 1, 2025, to May 31, 2026.

The Flawed Focus on Click Rates

Phishing performance metrics do not follow a linear trajectory. During training programs, click and credential submission rates often rise in the initial six months before declining. This pattern was observed across 354,962 simulations, with reporting behavior showing a similar trend. However, these stages do not track the same employees continuously. Instead, they compare overlapping groups of organizations and users at three-, six-, nine-, and 12-month intervals.

Simulation Trends and Employee Exposure

At six months, users encountered an average of 3.5 simulations per person, compared to 2.6 at three months and 2.8 at 12 months. Approximately 50.4% of simulations were classified as “Hard,” with difficulty levels remaining stable at around 50% after the six-month mark despite declining click and credential submission rates. The temporary increase in clicks may indicate more rigorous testing that uncovers vulnerabilities missed by simpler exercises, rather than a decline in employee resilience.

“A low click rate can create a false sense of security,” said Joe Jones, CEO of Pistachio. “Clicking a phishing link is just one moment in a longer chain of behavior. What matters is whether employees report the attack, recognize it, or prevent further action.”

Test Design and Reporting Behavior

Test design significantly influences results. Repeated use of familiar templates can lower click rates as employees learn to identify exercises, but this does not necessarily translate to better preparedness for novel attacks. A lower click rate is more meaningful when simulations remain challenging. Reporting behavior enhances organizational defenses by transforming employees into active threat detectors.

From the six-month peak to the 12-month stage, clicks dropped by 27%, credential leaks by 41%, and reports by 19%. The report-to-click ratio increased from 1.3 at three months to 1.8 at 12 months, indicating that suspicious messages were reported nearly twice as often as they were clicked. This early visibility allows security teams to investigate and mitigate threats before they spread.

Departmental Disparities and Training Needs

Simplifying the reporting process encourages participation. One-click reporting and immediate confirmation can reduce friction, enabling employees to flag threats efficiently. Departmental disparities highlight the need for targeted strategies. While no department faced consistently easier or harder simulations, construction and facility management showed the highest exposure to clicks and credential leaks.

Construction recorded a 41.31% cumulative click rate and a 16.47% leak rate, the highest figures among departments. Health had a low click rate but the lowest report rate at 13.17%, while logistics combined an above-average click rate with a below-average report rate of 17.11%. IT and tech development teams, despite awareness, still engaged with simulated phishing attempts, underscoring the gap between recognition and appropriate response.

Conclusion

These findings emphasize the limitations of organization-wide click scores in identifying specific vulnerabilities. Tailored training programs are necessary to address departmental weaknesses, such as exercises for teams that fail to recognize threats versus those that identify them but still submit credentials.



About Author

en_USEnglish