As cited
Copy frozen at (site build).
research
Phishing Research Challenges Conventional Security Awareness Testing
Research analyzing 2.47 million simulated phishing attacks suggests that traditional security awareness metrics like click rates may not reflect actual organizational risk. The study recommends measuring credential compromises and user reporting behavior instead to better evaluate employee susceptibility to phishing.
Why it matters: Security teams relying solely on click-through rates to validate awareness programs may miss credential theft risks and should reassess their testing and measurement approach to catch what matters most.
- Source published
- First seen by Cybersecurity Tracker