As cited
Copy frozen at (site build).
threat intel
Companies may be measuring phishing resilience the wrong way
A study of 648 organizations and 123,692 users from June 1, 2025, to May 31, 2026, found that relying solely on click rates to assess phishing simulation program effectiveness may mask true resilience. The research indicates that a more complete measure should combine click metrics with credential submission data and additional indicators.
Why it matters: Security teams and executives responsible for measuring security awareness training need to revise their evaluation criteria, as click-only metrics may create false confidence in employee defenses and leave organizations vulnerable to credential theft.
- Source published
- First seen by Cybersecurity Tracker