Insights

    ai-security

    Click rate stopped measuring what phishing tests think it measures

    Devence Lab

    · 2 min read

    Share
    Illustration · Devence Lab

    SecurityWeek reports new research across 2.47 million simulated phishing attacks arguing that click rate no longer predicts compromise. Once AI writes the emails, click rate mostly measures how good the email was, not how alert your staff are.

    On 11 September, SecurityWeek reported new research analysing 2.47 million simulated phishing attacks, arguing that click rate is the wrong number for organisations to measure. The study recommends tracking credential entry and employee reporting behaviour instead.

    Why click rate was ever the metric

    Click rate became the standard because it was the easiest signal to capture from a simulated phishing campaign: a link, a tracking pixel, a percentage. It stood in for a harder question, whether an employee's behaviour actually exposed the organisation, on the assumption that clicking correlated closely enough with getting compromised to serve as a proxy. That assumption held reasonably well when phishing emails were generic enough that clicking one signalled poor judgement rather than bad luck.

    What breaks the proxy

    Personalised, AI-generated phishing narrows the gap between what a careful employee and a careless one will click, because the message is built to defeat exactly the heuristics careful employees use. A click rate that used to separate the trained from the untrained now increasingly measures how good the email was, not how alert the recipient was. The 2.47 million-attack dataset backs this: the research found credential entry and reporting behaviour tracked security outcomes far more closely than whether someone clicked, because clicking alone no longer predicts what happens next.

    Click rate used to measure judgement. Now it mostly measures how convincing the email was, which is not a variable your staff control.

    What changes for security awareness programmes

    Retire click rate as the headline metric in phishing simulations and awareness reporting to leadership. Replace it with credential-entry rate, which reflects actual compromise risk, and reporting rate, which reflects whether your detection depends on employees noticing at all. Redesign the simulation programme around teaching people what to do after they click, since a click has stopped being preventable at the rate it once was, rather than continuing to train for a mistake that is no longer the one that matters.

    Sources

    1. Phishing Research Challenges Conventional Security Awareness TestingSecurityWeek

    Written by the Devence Lab research team.

    Share

    Collaborate

    We share findings with partners operating in the same constraint space.

    Get in touch