CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Companies may be measuring phishing resilience the wrong way

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 7052

As cited

Copy frozen at (site build).

threat intel

Companies may be measuring phishing resilience the wrong way

A study of 648 organizations and 123,692 users from June 1, 2025, to May 31, 2026, found that relying solely on click rates to assess phishing simulation program effectiveness may mask true resilience. The research indicates that a more complete measure should combine click metrics with credential submission data and additional indicators.

Why it matters: Security teams and executives responsible for measuring security awareness training need to revise their evaluation criteria, as click-only metrics may create false confidence in employee defenses and leave organizations vulnerable to credential theft.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary