VYPR
researchPublished Sep 11, 2026· 1 source

Phishing Research Challenges Traditional Security Awareness Metrics

New research analyzing 2.47 million simulated phishing attacks suggests organizations should prioritize credential leak and user reporting rates over simple click-through rates for more effective security awareness testing.

New research from security firm Pistachio, analyzing over 2.47 million simulated phishing attacks across more than 1,200 organizations, suggests a significant shift in how companies should measure the effectiveness of their security awareness training. The study, conducted between June 2025 and May 2026, indicates that traditional metrics like click-through rates may provide a misleading picture of an organization's true resilience against phishing.

Pistachio's analysis focused on three key user behaviors: clicking on phishing links, leaking credentials after clicking, and reporting suspicious emails. The findings reveal that while 30% of employees in tech development and IT roles clicked at least one simulated phishing attempt, nearly 20% of employees in construction and real estate actually leaked credentials. Financial services emerged as the most resilient sector, demonstrating superior performance across all three metrics.

The research highlights a critical distinction: a click alone is often a benign action, consuming employee time but not necessarily posing a direct risk. The real danger lies in the subsequent submission of sensitive information, such as login credentials. This underscores a potential flaw in conventional phishing simulation tests that heavily rely on click rates, as they may not accurately reflect the actual risk exposure.

"Click rate, the metric most phishing programs are judged on, is only part of the picture," stated Joe Jones, CEO and co-founder at Pistachio. "A strong indicator of improvement needs to go beyond click rate, and should look at how click, leak and report behaviors change together over time." He further elaborated that a low click rate can foster a false sense of security, as the critical actions of credential submission or reporting are more indicative of an organization's evolving security posture.

Pistachio's findings also challenge the assumption that technical teams are inherently low-risk. The study found that tech development and IT users had click rates exceeding 28%, with variations across different teams ranging from 26.35% in Design to 41.31% in Construction. This suggests that phishing susceptibility is not uniform and requires tailored training approaches.

Furthermore, the research indicates that sustained training is crucial. While more users reported suspicious emails than clicked them in their first simulation, click and leak rates initially rose during the first six months of Pistachio's program before beginning to decline. This pattern suggests that initial awareness training needs reinforcement to build lasting vigilance and reduce risky behaviors.

While the study provides valuable insights into industry and team-specific phishing behaviors, it notably lacks geographic analysis. The researchers acknowledge this limitation, suggesting that future studies could benefit from differentiating susceptibility across global regions, potentially informing targeted training for multinational organizations.

Ultimately, Pistachio's research advocates for a more nuanced approach to security awareness testing. Organizations are encouraged to re-evaluate their simulation strategies, focusing on metrics that more closely align with real-world threats and user responses, particularly credential submission and reporting rates, to build a more robust defense against sophisticated phishing attacks.

Synthesized by Vypr AI