Skip to main content
Category: Security Awareness & Training

Phishing Failure Rate

Also known as: Phishing Click Rate, Phish-prone Percentage, PPP
Simply put

Phishing failure rate is the share of employees who fall for a simulated phishing email during a security test, typically by clicking a link, opening an attachment, or entering credentials. It is used to gauge how susceptible a workforce is to phishing and to measure whether security awareness training is having an effect. A lower rate generally suggests employees are better at recognizing suspicious messages, though the number alone does not tell the full story.

Formal definition

Phishing failure rate is a security awareness metric expressing the proportion of recipients who perform a designated unsafe action (such as clicking a link, opening an attachment, or submitting credentials) during a simulated phishing campaign, relative to the total messages delivered. It is often tracked over time to assess the effectiveness of awareness programs, with reported benchmarks varying by source and methodology; for example, one vendor cited a cross-organization average failure rate of 4.93%, while another reported a global pre-training Phish-prone Percentage (a comparable measure) of 33.2% falling to roughly 4.2% after sustained training. Practitioners caution that a single aggregate figure can be misleading without context, such as which users clicked, their level of access, campaign difficulty, and how the metric is aligned to actual organizational risk, since some baseline click behavior persists regardless of training quality. A virtual or fractional CISO may use this metric to inform governance and program strategy, but the rate reflects human risk exposure rather than a guarantee of breach prevention, and its value depends on consistent measurement methodology and realistic simulation design.

Why it matters

Phishing remains one of the most common ways attackers gain an initial foothold in an organization, and the phishing failure rate gives security leaders a tangible, repeatable way to measure how susceptible their workforce is to these attacks. Because so many breaches begin with a single person clicking a malicious link or entering credentials on a fraudulent page, tracking this rate over time helps boards and executives understand human risk exposure in concrete terms rather than as an abstract concern. It also provides evidence of whether investments in security awareness training are producing measurable behavioral change.

That said, experienced practitioners caution against fixating on a single aggregate number. As noted in industry discussion, there is often excessive focus on one figure without considering context, who clicked, what level of access those users have, how difficult the simulation was, and whether the metric is aligned to actual organizational risk. Reported benchmarks vary considerably by source and methodology: one vendor cited a cross-organization average failure rate of 4.93%, while another reported a global pre-training Phish-prone Percentage of 33.2% falling to roughly 4.2% after sustained training. These figures are not directly comparable and should not be treated as universal targets.

Equally important, a meaningful number of people tend to click regardless of how good the training is. This baseline behavior is not a character flaw but a reflection of how convincing modern phishing can be. For this reason, a low failure rate should be interpreted as reduced human risk exposure, not as a guarantee of breach prevention. Security leaders who treat the metric as a single pass/fail scoreboard risk missing the more valuable signal it provides about where to focus training, technical controls, and monitoring.

Who it's relevant to

Virtual and Fractional CISOs
A vCISO or fractional CISO may use the phishing failure rate to inform program strategy, governance reporting, and prioritization of awareness efforts across one or more client organizations. In these advisory and directive roles, they typically help define how the metric is measured, ensure simulations are realistic, and interpret results in the context of actual risk. They generally do not administer the phishing simulation tooling or perform hands-on operational tasks unless explicitly contracted, and accountability for acting on the findings remains with the client organization.
Security Awareness and Training Leads
Those responsible for awareness programs rely on the failure rate to gauge whether training is producing measurable behavioral change over time. It helps them identify high-risk groups and tailor content, while keeping in mind that a meaningful number of people tend to click regardless of training quality, so the goal is risk reduction rather than a zero-failure outcome.
Executives and Boards
Leadership uses the metric as an accessible indicator of human risk exposure and as evidence of whether security awareness investments are working. It is important that executives understand the rate reflects susceptibility, not a guarantee against breaches, and that reported benchmarks vary by source and methodology, so figures should be interpreted with the accompanying context rather than as fixed targets.
Buyers Evaluating vCISO or Awareness Services
Organizations considering security leadership or awareness services can use the phishing failure rate to set expectations and evaluate progress, provided they understand its limitations. The metric's value depends on organizational maturity, consistent measurement, realistic simulation design, and cooperation from staff and stakeholders, and no provider can responsibly guarantee a specific rate or breach prevention as an outcome.

Inside Phishing Failure Rate

Simulated Phishing Campaign
A controlled exercise in which mock phishing emails are sent to employees to measure susceptibility. The phishing failure rate is typically derived from these simulations rather than from actual attacks.
Failure Event Definition
The specific actions counted as a failure, which often include clicking a link, opening an attachment, or submitting credentials. Definitions vary by provider and tool, so comparisons across organizations may not be equivalent.
Rate Calculation
The proportion of recipients who failed relative to those who received the simulation. The denominator, timing window, and whether repeat offenders are counted can materially change the reported figure.
Segmentation Data
Breakdowns of results by department, role, seniority, or location that help identify where targeted training or controls may be needed.
Trend Over Time
Tracking the metric across successive campaigns to gauge whether awareness efforts are influencing behavior, rather than treating any single measurement as definitive.
Reporting Rate (Complementary Metric)
The proportion of recipients who reported the simulated phishing message. This is often tracked alongside failure rate, as reporting behavior can be as meaningful as click behavior.

Common questions

Answers to the questions practitioners most commonly ask about Phishing Failure Rate.

Does a low phishing failure rate mean our organization is protected from phishing attacks?
No, and treating it that way is a common mistake. A phishing failure rate measures how many recipients clicked, submitted credentials, or otherwise interacted with a simulated phishing message during a controlled test. It is an indicator of susceptibility to the specific scenarios you tested, not a measure of actual protection against real-world attacks, which may use more sophisticated lures, targeted spear-phishing, or techniques your simulations did not cover. A low rate on easy templates can create false confidence. It should be read alongside other measures such as reporting rates, technical email controls, and the difficulty of the simulations used.
Is running phishing simulations and tracking the failure rate the responsibility of a virtual CISO?
This depends heavily on scope, and it is worth clarifying up front. A virtual CISO typically advises on the security awareness strategy, helps set targets, interprets the failure rate in the context of overall risk, and recommends how results should inform training and governance. The hands-on operational work of configuring the simulation platform, launching campaigns, and administering the tool is often out of scope for a strategy-level engagement unless explicitly contracted. In many engagements this operational execution is handled by internal staff or a separate vendor, with the vCISO providing direction and oversight rather than running the campaigns.
How should we set a target phishing failure rate for our organization?
Targets vary by organization and should account for your starting baseline, workforce composition, industry risk exposure, and the difficulty of the simulations you run. Rather than adopting a single fixed number, it is often more useful to establish an initial baseline, then track the trend over successive campaigns while gradually increasing simulation difficulty. Comparing a rate from easy templates against a target derived from harder ones can be misleading. Any target should be treated as a directional benchmark that may vary by provider and program maturity rather than a guaranteed outcome.
How often should phishing simulations be run to make the failure rate meaningful?
Frequency depends on organizational maturity, workforce size, and program goals, so there is no universal cadence. Running simulations too infrequently makes it hard to measure whether awareness efforts are working, while running them too often can cause fatigue or gaming of the tests. Many programs use a recurring cadence with varied scenarios and difficulty so the failure rate reflects genuine susceptibility over time rather than familiarity with a single template. The value of the metric depends on consistent methodology, so changes to frequency or difficulty should be documented when interpreting results.
What should we measure alongside the phishing failure rate?
The failure rate is more informative when paired with complementary measures such as the reporting rate, which shows how many recipients recognized and reported the simulated message, and the time to report. Tracking repeat clickers, results segmented by department or role, and the difficulty level of each simulation also adds context. Because the failure rate alone can be skewed by easy templates or narrow scenarios, reviewing it alongside these measures gives a more accurate picture of susceptibility and the effectiveness of awareness efforts.
How should phishing failure rate results feed into our broader security program?
Results are most useful when they inform decisions rather than sit as standalone statistics. A trend in the failure rate can guide the focus and frequency of awareness training, highlight roles or groups that may need targeted attention, and support governance reporting to leadership. The metric can also help evaluate whether technical email controls and process changes are having an effect. Its usefulness depends on organizational cooperation, consistent methodology, and integrating findings into training and risk management rather than using the number to assign blame, which can discourage reporting.

Common misconceptions

A low phishing failure rate means the organization is protected from breaches.
The metric reflects behavior in a controlled simulation at a point in time and depends heavily on scenario difficulty and campaign design. A low rate does not guarantee resistance to real, more sophisticated attacks, and no engagement or metric can guarantee breach prevention.
The phishing failure rate is a standardized number that can be compared directly across companies or providers.
Failure definitions, calculation methods, campaign difficulty, and denominators vary by tool and provider. Comparisons are often not equivalent unless the underlying methodology is the same.
Improving the phishing failure rate is primarily a technical task a virtual CISO executes hands-on.
A virtual CISO typically advises on awareness strategy, governance, and program design rather than administering the phishing simulation platform or running campaigns, unless that operational work is explicitly contracted. Accountability for acting on results generally remains with the client organization.

Best practices

Define clearly what counts as a failure (click, attachment open, credential submission) and apply that definition consistently across campaigns to make trends meaningful.
Track reporting rate alongside failure rate, since employees who recognize and report suspicious messages provide value that a click-only metric does not capture.
Vary scenario difficulty over time and avoid drawing strong conclusions from a single campaign, treating the metric as a directional trend rather than a definitive score.
Segment results by department, role, and location to target awareness efforts where susceptibility is highest, rather than applying uniform training.
Avoid presenting the metric to leadership as evidence of breach protection; frame it as one behavioral indicator within a broader risk and governance program.
Document the calculation methodology and campaign design so results are interpreted correctly and not misused for cross-organization comparisons.