Phishing Failure Rate
Phishing failure rate is the share of employees who fall for a simulated phishing email during a security test, typically by clicking a link, opening an attachment, or entering credentials. It is used to gauge how susceptible a workforce is to phishing and to measure whether security awareness training is having an effect. A lower rate generally suggests employees are better at recognizing suspicious messages, though the number alone does not tell the full story.
Phishing failure rate is a security awareness metric expressing the proportion of recipients who perform a designated unsafe action (such as clicking a link, opening an attachment, or submitting credentials) during a simulated phishing campaign, relative to the total messages delivered. It is often tracked over time to assess the effectiveness of awareness programs, with reported benchmarks varying by source and methodology; for example, one vendor cited a cross-organization average failure rate of 4.93%, while another reported a global pre-training Phish-prone Percentage (a comparable measure) of 33.2% falling to roughly 4.2% after sustained training. Practitioners caution that a single aggregate figure can be misleading without context, such as which users clicked, their level of access, campaign difficulty, and how the metric is aligned to actual organizational risk, since some baseline click behavior persists regardless of training quality. A virtual or fractional CISO may use this metric to inform governance and program strategy, but the rate reflects human risk exposure rather than a guarantee of breach prevention, and its value depends on consistent measurement methodology and realistic simulation design.
Why it matters
Phishing remains one of the most common ways attackers gain an initial foothold in an organization, and the phishing failure rate gives security leaders a tangible, repeatable way to measure how susceptible their workforce is to these attacks. Because so many breaches begin with a single person clicking a malicious link or entering credentials on a fraudulent page, tracking this rate over time helps boards and executives understand human risk exposure in concrete terms rather than as an abstract concern. It also provides evidence of whether investments in security awareness training are producing measurable behavioral change.
That said, experienced practitioners caution against fixating on a single aggregate number. As noted in industry discussion, there is often excessive focus on one figure without considering context, who clicked, what level of access those users have, how difficult the simulation was, and whether the metric is aligned to actual organizational risk. Reported benchmarks vary considerably by source and methodology: one vendor cited a cross-organization average failure rate of 4.93%, while another reported a global pre-training Phish-prone Percentage of 33.2% falling to roughly 4.2% after sustained training. These figures are not directly comparable and should not be treated as universal targets.
Equally important, a meaningful number of people tend to click regardless of how good the training is. This baseline behavior is not a character flaw but a reflection of how convincing modern phishing can be. For this reason, a low failure rate should be interpreted as reduced human risk exposure, not as a guarantee of breach prevention. Security leaders who treat the metric as a single pass/fail scoreboard risk missing the more valuable signal it provides about where to focus training, technical controls, and monitoring.
Who it's relevant to
Inside Phishing Failure Rate
Common questions
Answers to the questions practitioners most commonly ask about Phishing Failure Rate.