CRYPTOITDATACRYPTOITDATA

Cybersecurity

Phishing simulation: click rate is not the real metric

In a phishing simulation the same team clicks between 1.8% and 30.8%, depending on the lure. What to measure, what the click-rate report hides, what to ask for.

10 min read

At Tohan SA, a company in the ROMARM group, the attackers needed two email accounts. They compromised them, set up message forwarding so they could read the correspondence quietly, then edited the documents already circulating in ongoing threads. The result, recorded in the 2025 annual report of DNSC, Romania’s national cyber security directorate: fraudulent bank transfers of more than EUR 20,000. No phishing simulation run the month before would have produced a number that predicted this.

The natural reaction to a case like that is to buy security training and a simulation against your mailing list. It is a good reaction. The problem starts with the report that follows: almost everyone looks at a single number, the percentage of employees who clicked, and draws conclusions that the number cannot support.

The click rate of a phishing simulation says more about the lure than about your people

The largest randomised experiment published on this ran for eight months at UC San Diego Health, across more than 19,500 employees and ten campaigns, and was presented at the IEEE Symposium on Security and Privacy 2025 (Ho, Mirian, Luo, Savage, Voelker et al.). In the same population, over the same period, a “password update” lure produced a 1.82% click rate. A “change to the vacation policy” lure produced 30.8%. Roughly seventeen times as many, from the same people.

The practical consequence is uncomfortable for anyone who has ever presented a slide with a downward arrow. “We cut the click rate from 22% to 9%” means nothing if the lures changed between rounds — and in practice they almost always do, because the vendor rotates templates so they do not become predictable. What you measured is how hard the lure was, not how alert the team is.

The second thing the number hides is the measurement window. In the first month, around 10% of employees clicked. Across the full eight months, more than 50% clicked at least one simulated link. Same organisation, same people: “10%” and “more than half” are both true, and they describe the same thing measured differently.

The third is the effect of the training itself. The training page shown immediately after a click, the industry-standard format, produced a statistically significant reduction — but of roughly 1.7 percentage points in the average failure rate. And between having recently completed the mandatory annual security training and the odds of falling for phishing, the study found no significant relationship. Not a transformation, not the dramatic drop on a sales page: 1.7 percentage points.

  • Different lures between rounds — comparing one round with the next becomes meaningless.
  • Different measurement windows — one month and eight months produce figures that look like they contradict each other.
  • An employee who clicked and reported it immediately and one who clicked and said nothing look identical in the report.
  • Employees who spotted the lure and did nothing about it do not appear at all — they are invisible in the click rate.
  • The number says nothing about what happened after the click: whether a password was entered, whether the second factor held, whether the session was stolen.

And the Romanian context leaves no room for complacency. According to the DNSC annual report for 2025, phishing incidents rose by 70.6%, from 2,917 to 4,975; account compromise rose by 353%, to 1,125 cases; fraud and attempted fraud rose by 91%, from 2,061 to 3,937. Over the same period, brute-force attacks fell by 72.7% (from 172 to 47) and DDoS by 52.8% (from 72 to 34). Attackers have not given up — they have moved their effort off brute force and onto people.

What you should actually measure: reporting, and time to report

The 2024 edition of the Verizon DBIR measured a median of 21 seconds from opening the email to clicking the link, and another 28 seconds to entering data. Under a minute, end to end. Nobody intervenes inside that window. A filter that did not catch the message on delivery will not catch it in 21 seconds, and a person who has already decided does not change their mind at second 40.

The one thing an employee does better than a filter is raise their hand. A click is an event about one person; a report is an event about the organisation, because it triggers a check for everyone else who received the same message and has not opened it yet. Two figures therefore matter more than the click rate: what share of recipients reported the message, and how long it took, in median terms, from delivery to the first report. Both stay comparable from round to round even when the lure changes, because they measure a behaviour rather than the difficulty of a trap.

Same team, same period: 1.82% or 30.8%. The difference was not in the people. It was in the subject line.

The same study explains why average training moves the number so little: 75% of users spent at most one minute on the training material, and around a third closed it without any interaction. The only format associated with a real drop in future failures — roughly a 19% relative reduction — was interactive training that was actually completed. But the subgroup that finishes a training is self-selected: these were probably the more attentive people to begin with. That is a reasonable hypothesis, not causal proof. It does suggest where the problem sits, though: not in the content, but in completion.

Training is layer 2 of 3, not the whole defence

Before deciding how much to invest in the human layer, it is worth knowing how much that layer weighs. Here the sources appear to contradict each other, and it matters to say why. ENISA Threat Landscape 2025, covering roughly 4,900 incidents observed in the EU between July 2024 and June 2025, puts phishing first among initial intrusion vectors at 60% of cases, against 21.3% for vulnerability exploitation. Verizon DBIR 2026, which counts confirmed breaches globally and assigns each breach a single initial access vector, puts phishing at 16%, below vulnerability exploitation (31%) and close to credential abuse (13%). They do not actually disagree: they count different things, observed incidents versus confirmed breaches. On either reading phishing sits in the top three; in the DNSC 2025 report it is the leading identified vector; and the human element appears, again per DBIR 2026, in 62% of breaches. That is the size of it — no more, no less.

Layer one is everything that never reaches a person. Of the attacks blocked by email gateways, DBIR 2026 shows, 80% were credential or session phishing, 10% malware delivery, 5% callback phishing and 3% business email compromise. Layer two is training and simulation. Layer three is what happens after someone clicks anyway — and here the only category of authentication that CISA and NIST recognise as effective against modern account takeover is phishing-resistant MFA: FIDO2/WebAuthn, device-bound passkeys, certificates. The reason is technical rather than commercial: it cryptographically binds authentication to the domain. SMS, TOTP codes and push notifications remain phishable, because an adversary-in-the-middle proxy captures the session cookie after a perfectly successful login.

Why layer three matters even when training is going well: half the ransomware victims in DBIR 2026 had had a credential compromise event or an infostealer infection in the preceding 95 days. Stolen credentials do not cause damage on the day they are stolen. They cause damage three months later, when nobody connects the two events any more.

There is one more limitation training vendors rarely mention, ourselves included when we sell a package that simulates over email. Per DBIR 2026, 41% of social engineering breaches use a channel other than email, and around a quarter come through social media or the phone; vishing simulations succeed roughly 40% more often than email ones (median click rate 2% against 1.4%, on simulation data rather than real breaches). In Romania the gap is starker still: in the first half of 2026, 42% of incidents reported to DNSC were vishing, 14% classic phishing and 13% smishing. An email simulation tests a vector that is declining in relative terms. The rest is covered in the live session and in procedure, not in the simulation.

How to build a programme that moves the risk, not just the report

  1. 1Fix a set of reference lures. Two or three templates identical in every round, plus the rest on rotation. Only the fixed ones may be used to compare progress over time.
  2. 2Put a report button one click away, inside the email client people actually use. If reporting means sending IT an email with the suspicious message attached, the reporting rate will stay near zero no matter how much training you do.
  3. 3Measure the reporting rate and the median time to first report, round by round. Those are the numbers you push up; the click rate is only their context.
  4. 4Make reporting a cost-free event for the employee. No lists of names, no jokes in the team meeting. Someone who fears being laughed at hides the click, and a hidden click costs more than ten reported ones.
  5. 5Connect reporting to someone who genuinely looks at it, within a defined window — otherwise the button becomes a black box. We wrote separately about what happens after the alarm goes off.
  6. 6Invest in completion, not in volume of content. A live session with examples from your own industry, followed by short e-learning, has a far better chance of being finished than a module emailed out and forgotten in an inbox.
  7. 7Write the out-of-band verification procedure for any payment request, bank-details change or invoice amendment: a phone call to a number known in advance, never the one in the email. The exact mechanism used at Tohan SA stops here, not in the simulation.
  8. 8Move email and administrator accounts to phishing-resistant MFA before adding another training round. It is a control that does not depend on anyone staying alert.
  9. 9Drop “look for spelling mistakes” from the curriculum. DNSC warns that fraudulent messages in Romania are now written in correct Romanian and replicate the visual identity of legitimate institutions.

What to ask for in a training and simulation quote

A serious provider answers the list below without hesitating. If the answers are vague, what you are buying is a report, not a programme.

  • Which lures stay constant between rounds and which rotate — with the reasoning behind the choice.
  • Whether the report includes the reporting rate and the median time to first report, not just the click rate.
  • Which channels the simulation actually covers. If it is email only, ask them to say so explicitly, and discuss the phone and SMS procedure separately.
  • How training completion is tracked, not just training delivery.
  • What happens to the employee who clicks in every round: a conversation and a process change, not a sanction.
  • Cadence: a one-off intervention before an audit, or a recurring programme with a monthly simulation.

As a cost reference, in our packages a two-hour live session with industry-adapted materials, plus a simulation against your mailing list, starts at 2,800 RON for up to 25 employees and 4,500 RON for 26–75. The recurring option, four sessions a year plus one simulation a month, is 1,900 RON a month for up to 50 employees and 3,500 RON a month for 50–150. We deliver the click-rate report too, because everyone asks for it; this article is about what else you need to read in it for it to mean anything. And in our cyber security service we state a measurable click-rate reduction as an expected outcome, from 25–30% to under 5% in six months — that is our target, in line with what the large behavioural-programme vendors report on their own customers, and it is only honest to add that the randomised study above does not support effects of that size at general-population level.

If your company falls under NIS2, the conversation has a compliance side as well. Article 20(2) of the directive applies across the EU: the management bodies of essential and important entities must follow training, and those entities must regularly offer similar training to their staff. In Romania this is transposed by Law no. 124 of 7 July 2025, which approves GEO no. 155/2024 (Official Gazette no. 638 of 07.07.2025), and sets it out in article 14(2). If you are not sure which category you fall into, we covered separately how to check your classification and your obligations towards DNSC.

Conclusion

The click rate is easy to measure, easy to put on a slide and almost impossible to read correctly: the same team produces 1.8% or 30.8% depending on what the subject line says. What is worth tracking is how fast somebody raises their hand, and how well authentication holds when the hand does not go up in time. If you would like us to look together at your last simulation report, or your first, let us talk for 30 minutes.

Frequently asked questions

What is a normal click rate for a phishing simulation in a company?+

There is no normal figure detached from the lure. In the randomised experiment at UC San Diego Health, the same population of more than 19,500 employees produced a 1.82% click rate on a “password update” lure and 30.8% on a “change to the vacation policy” lure, in the same period. Training vendors publish benchmarks of 25–35% without a programme and 5–10% for a mature one, but those are vendor data, measured on their own customers and without a control group. In practice, a click rate is only useful compared with itself, on the same lures, from one round to the next.

Does anti-phishing training actually work, or is it just a compliance tick-box?+

It works, but far less than it is sold. The only large randomised experiment on the subject, presented at the IEEE Symposium on Security and Privacy 2025, measured a reduction of roughly 1.7 percentage points in the average failure rate, and found no significant relationship between mandatory annual training and the odds of falling for phishing. The likely explanation is that 75% of users spend at most a minute on the material and a third close it without interacting. Only interactive training that was actually completed was associated with a real drop, of around 19% in relative terms.

How much does a phishing simulation cost for 25 employees?+

With us, the package that combines a two-hour live session with industry-adapted materials and a phishing simulation against your mailing list starts at 2,800 RON for up to 25 employees, as a one-off. For 26–75 employees, 4,500 RON. If you want a monthly simulation and four sessions a year, the recurring option is 1,900 RON a month for up to 50 employees. A one-off is useful as a starting point or ahead of an audit, but the figures that matter, the reporting rate and the time to report, only become visible after several rounds.

Is cyber security training mandatory under NIS2?+

For entities in scope, yes. Article 20(2) of the NIS2 directive requires the management bodies of essential and important entities to follow training, and requires those entities to offer similar training to their employees on a regular basis. In Romania it is transposed by Law no. 124 of 7 July 2025, approving GEO no. 155/2024 (Official Gazette no. 638 of 07.07.2025), in article 14(2). Neither the directive nor the Romanian text fixes a target click rate or a specific platform, so how you demonstrate “on a regular basis” remains an internal documentation decision.

Have a concrete question?

30 minutes, free. We discuss exactly your situation.

Book a consultation