# Redefining Phishing Resilience: What Millions of Simulated Attacks Reveal About Modern Cybersecurity
**Published: July 2025**
—
A comprehensive study spanning twelve months and involving over two million simulated phishing attempts has delivered a sobering message to organizations worldwide: the way most companies measure phishing resistance is fundamentally flawed. The research, which targeted more than 123,000 employees across over 1,200 organizations, reveals that click rates alone are a dangerously incomplete metric for evaluating how well a workforce can withstand real-world phishing threats.
## The Scale of the Study
The research was conducted by a cybersecurity firm specializing in human risk management, employee awareness training, and phishing simulation. Based originally in Norway and now operating across multiple international offices, the organization deployed its AI-driven platform to deliver simulated phishing campaigns through email and collaboration tools like Microsoft Teams. Every simulation was tailored to the recipient’s specific role and previous responses, creating a dynamic and evolving testing environment.
What makes this research particularly notable is its sheer volume and duration. The study ran continuously between June 2025 and May 2026, generating a dataset that would have been impossible to compile through manual effort. The platform’s artificial intelligence condensed a process that would have taken over two decades into just one year, showcasing how automation transforms the scope and speed of cybersecurity research.
## Sector Performance: Surprises and Expectations
The results revealed significant disparities across industries, with some findings challenging long-held assumptions about who is most vulnerable to phishing attacks.
**Financial Services** emerged as the most resilient sector across every measured category — including click rates, credential submission, and reporting behavior. While this may not come as a complete shock given the industry’s heavy regulatory requirements and security investments, it underscores the importance of continuous, structured training programs.
**Technology and IT departments**, however, produced the most unexpected results. Despite possessing deep technical knowledge, approximately 30% of tech development employees and nearly 29% of IT users clicked on at least one simulated phishing attempt. This finding challenges the assumption that technical expertise naturally translates to phishing resistance.
**Construction and Real Estate** sectors showed concerning vulnerability patterns, with nearly 20% of employees who fell for a phishing attempt going on to submit their credentials. Meanwhile, the range of first-click rates across departments varied dramatically — from just over 26% in design teams to more than 41% in construction crews — illustrating that risk profiles differ significantly even within a single organization.
## Why Click Rate Is Not Enough
Perhaps the most important insight from this research is the call to move beyond click rate as the primary indicator of phishing resilience. The study emphasizes that clicking a phishing link is merely the first step in a longer chain of behavior. What happens afterward — whether the user submits credentials, recognizes the deception, or reports the attempt — is what truly determines the level of risk.
The data supports this argument powerfully. By the end of the twelve-month testing period, users reported suspicious emails at nearly twice the rate at which they clicked on them. This shift demonstrates that sustained training programs can build genuine vigilance over time. However, the study also found that click and leak rates actually **increase** during the first six months of a simulation program before they begin to decline, suggesting that early-stage training may initially surface latent vulnerabilities before meaningful improvement takes hold.
## The Critical Role of Reporting
The research highlights that a strong phishing resilience program should cultivate three distinct behaviors: fewer clicks, fewer credential leaks, and more reports. Reporting suspicious emails emerged as the most valuable long-term indicator of a security-conscious workforce. When employees report rather than simply avoid or ignore phishing attempts, the entire organization benefits — security teams can investigate, block related campaigns, and strengthen defenses proactively.
## AI-Driven Personalization and Its Implications
The use of artificial intelligence to customize phishing simulations based on individual roles and historical responses represents a significant advancement in how organizations approach security awareness. This personalization ensures that simulations remain realistic and relevant, avoiding the “one-size-fits-all” approach that can render training exercises ineffective or easily dismissed by employees.
The platform’s ability to adapt content and difficulty in real time means that each employee faces challenges appropriate to their level of exposure and prior performance, creating a far more accurate picture of genuine vulnerability than static, generic tests ever could.
## A Gap in Geographic Analysis
One notable limitation of the research is the absence of geographic or regional analysis. While the study examined differences across industries and teams, it did not break down results by country or region. This is a missed opportunity, as geographic factors — such as language barriers, regional threat landscapes, and local cybersecurity regulations — could significantly influence phishing susceptibility. Future iterations of such research would benefit greatly from incorporating location-based comparisons, potentially helping multinational organizations identify which regional offices may need additional focus.
## What This Means for Your Organization
The overarching takeaway from this extensive research is clear: organizations should redesign their phishing simulation programs to look at the full spectrum of employee behavior, not just whether someone clicked a link. A comprehensive approach should measure reporting rates alongside clicking and credential-leaking behaviors, and it should be sustained over long periods to capture genuine behavioral change rather than temporary improvements.
Before developing or commissioning any phishing simulation test — whether internally or through external providers — organizations are encouraged to review the broader findings of this research to inform their strategy.
—
## Frequently Asked Questions (FAQ)
**Q1: What is a phishing simulation test?**
A phishing simulation test is a controlled, ethical exercise in which organizations send fake phishing emails or messages to their employees to gauge how well they can recognize and respond to malicious attempts. These tests are designed to train employees and identify weaknesses in an organization’s human security layer.
**Q2: Why is click rate alone an insufficient metric for phishing resilience?**
Click rate only measures whether someone interacted with a phishing link. It does not reveal whether that person went further and submitted credentials, reported the attempt, or simply closed the email without taking any action. A low click rate can create a false sense of security while credential leaks — the actual source of risk — go undetected.
**Q3: How does AI improve phishing simulation testing?**
AI enables the customization of phishing simulations based on each employee’s role, department, and previous responses. This personalization makes the tests more realistic and relevant, ensuring that the results accurately reflect real-world risk rather than providing generic data that may not apply to specific teams or individuals.
**Q4: Why did technology and IT employees perform worse than expected?**
Technical professionals are often assumed to be naturally resistant to phishing due to their deep knowledge of cybersecurity. However, the research found that over 30% of tech development employees and nearly 29% of IT users clicked on simulated phishing attempts. This may be due to overconfidence, familiarity with tech jargon in phishing messages, or simply the volume and sophistication of modern phishing attacks that can deceive even experienced professionals.
**Q5: How long does it take for phishing simulation training to show results?**
According to the research, click and leak rates tend to rise during the first six months of a simulation program before beginning to decline. This suggests that early-stage training may reveal hidden vulnerabilities before employees fully internalize best practices. Sustained, long-term programs are essential for building genuine, lasting resilience.
**Q6: What is the ideal ratio of clicks to reports in a healthy organization?**
The research found that by the end of a sustained twelve-month program, users reported suspicious emails at nearly twice the rate they clicked on them. A healthy program should aim for high reporting rates relative to clicks, as reporting enables security teams to respond proactively and strengthen organizational defenses.
**Q7: Can phishing simulation tests be conducted manually instead of through AI platforms?**
While manual testing is possible, it is extraordinarily time-consuming. The scale of the research discussed here involved over two million simulations — a task that would take approximately 23 years to complete manually but was accomplished within 12 months using an AI-driven platform. Automation is essential for organizations seeking comprehensive, ongoing testing at scale.
**Q8: Should organizations hire external providers or build phishing simulations in-house?**
Both approaches have merit. External providers often bring specialized platforms, AI-driven personalization, and extensive datasets that can benchmark performance against industry norms. In-house programs offer greater control and customization but require significant investment in tools, content creation, and ongoing maintenance. The key is ensuring that whichever approach is chosen, it measures the full spectrum of behaviors — clicks, leaks, and reports — rather than relying solely on click rates.
—
## Conclusion
The findings of this large-scale phishing simulation research mark a turning point in how organizations should approach human cybersecurity risk. The era of judging phishing resistance purely by click rates is over. Instead, a holistic view — encompassing clicking behavior, credential submission, and the willingness to report suspicious communications — is necessary to understand and improve an organization’s true resilience.
The data makes one thing abundantly clear: phishing attacks are evolving in sophistication, and so must the strategies used to defend against them. Organizations that invest in sustained, AI-enhanced simulation programs and measure success across multiple behavioral indicators will be far better positioned to protect themselves against the ever-present threat of real-world phishing campaigns.
Cybersecurity is not just a technical challenge — it is fundamentally a human one. The companies that recognize this and adapt their training accordingly will be the ones that stand strongest when the next wave of attacks arrives.
Thank you for reading



