Human Risk

Why Your Phishing Click Rate Tells The Board Nothing Useful

Click rate is the metric every board sees, and it predicts almost nothing about whether your organisation would catch a genuine phishing attack. Reporting speed, repeat-clicker concentration and click-to-report ratio predict far more.

Why Your Phishing Click Rate Tells The Board Nothing Useful

Click rate fools boards because it measures whether someone clicked a synthetic email once, not whether your organisation would catch, report, or contain a live attack. After fifteen years running security awareness and human risk programmes, I have watched click rate fall while incidents climbed, and boards never learned why.

Takeaways

  • Boards that receive only a click-rate percentage are seeing the least predictive number a security awareness programme produces, based on the pattern across the programmes I have run.
  • Verizon’s 2026 Data Breach Investigations Report found the human element present in 62% of breaches, up from 60% the year before, which means the metric a board tracks should follow behavior over time rather than one simulated email.
  • Proofpoint’s State of the Phish research found only 18.3% of simulated phishing emails were reported properly, showing reporting rate has far more room to improve than click rate does.
  • Proofpoint’s 2026 AI and Human Risk Landscape Report found 42% of organizations had already experienced a suspicious or confirmed AI-related incident, even though 87% had deployed AI assistants beyond a pilot stage.
  • A human risk score built only from click data and training completion repeats the same blind spot as click rate, so any score a programme adopts should count reporting behavior as a positive input too.
Human element 62% of breaches (2026 DBIR)
Reported rate 18.3% (Proofpoint, 2024)
AI-related incidents 42% of orgs (Proofpoint, 2026)
Gartner SBCP forecast 40% fewer incidents by 2026

Why does click rate fool boards?

Click rate fools boards because it collapses an entire year of behavior into one number generated by a single synthetic email. A board sees ‘click rate: 8%’ and reads it as a report card, when that number is highly sensitive to which template was sent, which department received it, what day of the week it arrived, and which device received it. I have watched the same population score 4% on a generic delivery-notice test and 22% on a well-targeted invoice-fraud test sent from a spoofed finance address, with no change in the underlying culture between the two tests. Verizon’s 2026 Data Breach Investigations Report found the human element present in 62% of breaches, up from 60% the year before according to Abnormal AI’s analysis of the report, with social engineering alone accounting for 16% of breaches per a separate review of the same DBIR data. The same report found engagement with mobile-based phishing simulations ran 40% higher than email-based ones, a detail covered by Help Net Security’s summary. A single percentage cannot carry that much variance, so it doesn’t.

What should you measure instead?

The four numbers worth reporting are reporting rate, median time-to-report, click-to-report ratio, and repeat-clicker concentration. Reporting rate tracks what share of a population used the report button rather than ignoring or clicking the email, which is the behavior a programme should try to increase. Proofpoint’s State of the Phish research found only 18.3% of simulated phishing emails were reported properly, and separately that 71% of working adults admitted to a risky action such as reusing a password or clicking a link from an unknown sender. Median time-to-report counts for more than whether someone reported at all, because a report arriving three days later cannot stop a live campaign already in progress. Click-to-report ratio and repeat-clicker concentration show where a population’s judgment breaks down under a well-crafted lure, which is exactly where an attacker finds success first.

Five metrics ranked by earliest warning

Ranked from earliest warning to latest confirmation, these five metrics are not equally useful to a security team:

  1. Time-to-report. A report arriving within minutes gives a security team a live chance to block a campaign before it spreads past the first few recipients.
  2. Reporting rate trend. A department-level drop in reporting across consecutive quarters tends to precede an incident by weeks, since it shows attention eroding before anyone exploits it.
  3. Repeat-clicker concentration. A small group that clicks on nearly every simulation is the group most likely to click on a well-targeted live lure, so this number identifies where to focus training before an incident, not after.
  4. Click-to-report ratio. This shows whether a population defaults to reporting or to clicking when it cannot tell whether an email is legitimate, which is the exact decision point inside a live attack.
  5. Click rate. This only confirms, after the simulation has already run, whether that specific template would have worked. It carries no information about what the population will do with a different lure next week.

Has AI broken the click-rate model?

AI has broken the click-rate model because generative tools now write phishing emails with the grammar, tone, cadence and internal references of a genuine colleague, closing the gap between a well-built simulation and a well-built attack. Proofpoint’s 2026 AI and Human Risk Landscape Report found 42% of organizations had already experienced a suspicious or confirmed AI-related incident, even though 87% had deployed AI assistants beyond a pilot stage. The same research, covered in Proofpoint’s own analysis and by Industrial Cyber, found email remains the most common threat vector at 63%, while exposure spreads across third-party SaaS and cloud apps at 47%, social and messaging platforms at 41%, and AI assistants or agents themselves at 36%. Gartner predicts AI applications will drive 50% of cybersecurity incident response efforts by 2028, per its March 2026 forecast, and separately that 25% of enterprise generative AI applications will have at least five minor security incidents a year by 2028, per its April 2026 release. Click rate was built for a world of typo-ridden templates and was never designed to measure this.

What counts as a good reporting rate?

A good reporting rate is one that keeps climbing quarter over quarter, not a single benchmark to hit once and forget. Proofpoint put properly reported simulated phishing at 18.3% across its 2024 State of the Phish sample of 7,500 working adults, which gives a rough floor for an untrained population. In the programmes I have run, the pattern I see is different: once reporting crosses roughly half a population on a given simulation, the security team starts hearing about suspicious emails from staff within hours instead of days, and that speed is what reduces dwell time in a live incident. I have also watched reporting rate climb while click rate stayed flat, which is a sign of progress a board asking only about click rate will never see.

How do you brief the board on this?

Brief the board with a trend line across at least four quarters, not a single snapshot, and tie every metric to something the board already funds: how fast the organisation would notice a live attack. I bring four charts instead of one bar to a board meeting: reporting rate over time by business unit, median time-to-report, repeat-clicker concentration against departments with financial or data access, and click-to-report ratio for the population as a whole. Gartner’s own framing has moved this direction. Its 2025 cybersecurity trends release and 2026 update both describe a move toward what it calls security behavior and culture programmes, measuring demonstrated behavior under a live threat rather than training completion. Boards that hear this framing tend to stop asking for a single percentage within one or two cycles.

Where do human risk scores go wrong?

Human risk scores go wrong when they combine click rate and training completion into one composite number and call it something new. Gartner predicts that enterprises combining generative AI with an integrated, platform-based security behavior and culture programme will see 40% fewer employee-driven cybersecurity incidents, a forecast repeated across its 2025 and 2026 trend releases. I hope that prediction comes true, but I have watched vendors ship a risk score built from the two weakest inputs available: whether someone clicked, and whether someone finished a training module. Neither measures whether the organisation would catch an attack in progress. A score built only from failure data tells every employee the programme is watching for mistakes, not effort, and that framing pushes the exact behavior no programme wants, which is staff who say nothing about a suspicious email rather than risk being flagged again. A risk score worth reporting has to include reporting behavior as a positive input, not just clicking as a negative one. If yours doesn’t, it is measuring what click rate always measured, wearing a better name.

Prompts you can use

Paste these straight in. Change the parts in square brackets and nothing else.

Board metrics rewrite
You are a security awareness and human risk advisor preparing a board update. I will paste our current phishing simulation results (click rate, report rate, and any other fields we track) for the last four quarters, broken down by business unit if available. Using only the data I provide, do four things: (1) identify which metrics show a genuine multi-quarter trend versus which are noisy single-quarter blips, (2) flag any business unit where reporting rate is falling while click rate stays flat, since that combination is a leading indicator worth board attention, (3) note any metric that has moved the wrong direction for two consecutive quarters, and (4) draft a one-page board narrative that leads with reporting rate and time-to-report rather than click rate, in plain language a non-technical board member would understand. If the data I paste is incomplete or ambiguous, ask me clarifying questions before drafting the narrative rather than guessing at missing numbers.

Will not produce accurate trends from incomplete or inconsistent data, so check its numeric summaries against your source spreadsheet before presenting them to anyone.

Reporting rate diagnostic
You are a data analyst helping a security awareness programme interpret its phishing simulation data. I will provide a table of individual simulation results: date sent, department, template difficulty, and whether each recipient clicked, reported, or did neither. Analyze this data to surface which departments have the highest repeat-clicker concentration (people who clicked more than once across the period), the median and mean time-to-report in hours, and whether click-to-report ratio is improving or worsening over the period covered. Present findings as a short table plus two or three sentences of plain-language interpretation, and explicitly say if the sample size for any department is too small to draw a conclusion. Ask me for department headcounts if you need them to judge sample size.

Needs clean, consistent column data to work well; if your simulation platform exports dates or department names inconsistently, clean those first or describe the format before pasting.

AI phishing tabletop exercise
You are a security awareness programme lead designing a tabletop exercise about AI-generated phishing and vishing for a group of non-technical staff, including finance and HR. Build a 45-minute exercise with four parts: a realistic scenario involving an AI-generated email or voice message impersonating an executive requesting an urgent wire transfer or credential reset, a set of five decision points where participants must choose what to do next, a short list of red flags participants should have noticed, and a debrief script that explains what made the deception convincing without teaching participants how to build one themselves. Keep the language non-technical, define any jargon like 'deepfake' in plain terms before using it, and flag any part of the scenario that could be mistaken for real instructions if it leaked outside the exercise. Ask me how many participants and what industry before finalizing details specific to our threat model.

Review the scenario yourself before running it live, since a model unfamiliar with your industry’s actual approval workflows may invent a process that doesn’t match reality and confuses participants.

Questions people actually ask

Is phishing simulation click rate a good KPI?

Click rate is a weak KPI on its own because it measures reaction to one template on one day, not sustained behavior. Verizon’s 2026 DBIR found the human element in 62% of breaches, a figure no single click-rate percentage can explain. Reporting rate, time-to-report and repeat-clicker concentration track the underlying behavior far more consistently.

What is a good phishing click rate benchmark?

There isn’t a universal benchmark worth chasing, because click rate swings heavily with template difficulty and targeting. Proofpoint’s research found only 18.3% of simulated phishing emails were reported properly across a 7,500-person sample, which is a more useful floor to compare against than any published click-rate average.

How do you measure security awareness ROI for the board?

Report trend lines, not snapshots: reporting rate by business unit over at least four quarters, median time-to-report, repeat-clicker concentration, and click-to-report ratio in departments with financial or data access. Tie each line to how much faster the organisation would notice a live attack, which is the outcome the programme is funded to produce.

Does AI-generated phishing get past simulations more easily?

Yes, because generative tools now match the grammar, tone and internal references of a genuine colleague, closing the gap between a simulation and a live attack. Proofpoint’s 2026 AI and Human Risk Landscape Report found 42% of organizations had already experienced a suspicious or confirmed AI-related incident, even with security controls in place.

What is human risk management versus security awareness training?

Security awareness training measures whether staff completed a module. Human risk management measures ongoing behavior, including simulated response, reporting habits and credential exposure, to produce a score per person or team. Gartner has pushed this framing in its recent cybersecurity trend releases, though the score is only as good as what feeds it.

Sources

  1. 2026 Data Breach Investigations Reportverizon.com
  2. Abnormal AI’s analysis of the reportabnormal.ai
  3. a separate review of the same DBIR databreacher.ai
  4. Help Net Security’s summaryhelpnetsecurity.com
  5. State of the Phish researchproofpoint.com
  6. 2026 AI and Human Risk Landscape Reportproofpoint.com
  7. Proofpoint’s own analysisproofpoint.com
  8. Industrial Cyberindustrialcyber.co
  9. March 2026 forecastgartner.com
  10. April 2026 releasegartner.com
  11. 2025 cybersecurity trends releasegartner.com
  12. 2026 updategartner.com

What happens next

Expect more security teams to follow Gartner’s push toward security behavior and culture programmes that measure demonstrated behavior rather than training completion, a trend flagged in its 2025 and 2026 cybersecurity trend releases. Expect boards to start asking about AI-related incidents directly, since Proofpoint’s 2026 research already ties incident rates to AI assistants and agents rather than email alone. Treat any vendor’s incident-reduction prediction as a hypothesis to test against your own reporting-rate data, not a number to repeat unverified.

Share this
About the author
Vinayak Kapoor
Vinayak Kapoor

Vinayak started at seventeen on a call centre floor and climbed every rung himself over fifteen years: millions of customer conversations for some of the world's largest brands, self-taught design, video and web work, a profitable e-commerce brand of his own, and now human cyber risk, where he has built customer success journeys for national critical infrastructure and leads business growth at HumanFirewall. Nobody groomed him. He learned every skill alone, including the AI he now builds with daily as founder of Quarry, MaaSify and HuMatrix. He writes here so your career gets the guide his never had.

Read next
Come find me

The daily thinking
lives on the feeds.

Long form here. The working notes, the arguments and the things that did not fit go out most days.

← All writing