Measuring phishing simulations: the metrics that matter
The number everyone quotes — click-rate — is the least interesting one on its own. What tells you whether a programme is working is how it moves over time, and whether people are reporting.
The core metrics
- Click-rate — the share of recipients who clicked the link. A starting point, not the goal.
- Submission-rate — those who went further and entered credentials or data. Closer to real-world harm.
- Report-rate — the share who reported the email as suspicious. The metric that most reflects a healthy security culture.
- Reporting speed — how quickly the first (and most) reports arrive. Fast reporting shrinks an attacker’s window.
The resilience ratio
A useful single view is the ratio of people who reported to those who clicked. As a programme matures, this ratio should climb — more reporters, fewer clickers — showing that your workforce is turning into an active sensor network rather than a liability.
Read trends, not snapshots
A single campaign’s numbers are noisy — they depend on the lure’s difficulty, timing and audience. Judge the programme by the trend across many campaigns with varied scenarios, not by one score. Beware "teaching to the test": if you always send easy lures, click-rate looks great and means nothing.
What to report to leadership
- Trends over time (click, submit, report, speed), not individuals.
- The resilience ratio and how it’s moving.
- Coverage — who has been trained and how recently.
- How results map to risk and to obligations such as NIS2 awareness requirements.
FAQ
Related questions
What is a good phishing-simulation click-rate?
There’s no universal target — it depends on your baseline, audience and lure difficulty. Focus on the downward trend and on a rising report-rate rather than chasing a specific percentage.
Why is report-rate so important?
Because reporting is what lets your security team detect and stop a real campaign. A workforce that reports quickly turns every employee into an early-warning sensor.
How do we avoid gaming the metrics?
Vary scenarios and difficulty, and don’t always send easy lures. Judge the programme on trends across many realistic campaigns, not a single flattering score.
Keep reading
More guides
-
How to run a phishing simulation: a step-by-step programme
A practical, ethical way to plan, send, measure and follow up a phishing simulation — and turn it into a programme that changes behaviour.
Read guide -
Ethical phishing simulations: how to test without breaking trust
A phishing simulation can build a security culture — or destroy it. The difference is ethics: blame-free, fair lures, and coaching over shaming.
Read guide