Best overall for reducing click rates: Cyber Aware. Best email-layer filter: Cisco Secure Email Threat Defense. Best endpoint backstop: CrowdStrike Falcon. The number that matters comes from KnowBe4's 2025 benchmark of 67.7 million simulations across 14.5 million users: 33.1% of employees interact with a phishing simulation before any training, and 4.1% after twelve months of ongoing simulation-based training — an 86% reduction. The software that moves your number closest to that 4.1% is what this page ranks.
Key takeaways
- The measurable target is the KnowBe4 benchmark curve: 33.1% phish-prone before training, roughly 5% after 90 days, 4.1% after 12 months of ongoing training.
- Cisco Secure Email Threat Defense earned a AAA rating with close to 100% detection and zero false positives in SE Labs' email security testing (test window March to April 2026) — it reduces clicks by reducing what lands in the inbox.
- CrowdStrike Falcon scored 100% detection and protection with zero false positives in SE Labs' 2025 endpoint test, catching the payloads that get past both the filter and the user.
- Simulation-based training is the only layer with published evidence of changing click behaviour — KnowBe4's data spans 62,400 organisations and shows results only hold with ongoing training, not one-off campaigns.
Why click rates are the metric that matters
Click rate is the share of staff who interact with a phishing email — clicking a link, opening an attachment or entering credentials. It is the human-layer number insurers, auditors and boards now ask for, because it predicts real incidents better than any filter statistic: an email that gets filtered costs nothing, and an email that gets clicked can cost a breach.
Two layers move it. Filters reduce volume — fewer malicious emails reach anyone, so fewer clicks happen by arithmetic. Training and simulation change behaviour — the people who do receive a malicious email stop clicking it. The KnowBe4 2025 data shows the second layer is where the durable reduction lives, and its Q4 2025 trends report shows why filters alone cannot finish the job: nearly 90% of top-clicked phishing attempts involved domain spoofing that looks legitimate enough to survive scrutiny.
What makes the best click-rate software
- Measured behaviour change — published evidence that click rates fall, not vendor claims about engagement.
- Realistic simulations — templates matching current attack patterns, including the domain spoofing and personalised lures that dominate clicks.
- Cadence that holds results — the benchmark curve depends on ongoing training, so automation matters.
- Reporting you can act on — per-user and per-department click, report and repeat-click data.
Best software to reduce phishing click rates at a glance
| Software | Best for | Published evidence | Main limitation |
|---|---|---|---|
| Cyber Aware | Behaviour change for Australian teams | Category benchmark: 33.1% to 4.1% over 12 months of simulation training (KnowBe4 2025) | Does not filter email itself |
| Cisco Secure Email Threat Defense | Reducing phishing volume in inboxes | AAA rating, close to 100% detection, zero false positives (SE Labs 2026) | No staff training component |
| CrowdStrike Falcon | Catching payloads post-click | 100% detection and protection, zero false positives (SE Labs 2025 EPS) | Acts after the email is opened |
| KnowBe4 | Enterprises wanting benchmark data | 67.7M simulations, 14.5M users, 62,400 organisations (2025) | Heavier platform and cost |
1. Cyber Aware: best for changing click behaviour
Cyber Aware is a security awareness and phishing simulation platform built for Australian teams. Its simulation library tracks scam patterns in Australian Cyber Security Centre threat reporting — AI-generated lures, QR code phishing and deepfake voice pretexting — so the emails staff face in simulations match what actually lands in Australian inboxes in 2026. Clickers get short training immediately, which is the mechanism behind the benchmark's fall from one in three staff clicking to roughly one in twenty.
Cyber Aware pros:
- Attacks the layer with published evidence of behaviour change: ongoing simulation-based training.
- Australian scam content means simulations feel real rather than generic.
- Human risk reporting tracks click, report and repeat-click trends per user and department.
Cyber Aware cons:
- It complements a filter, it does not replace one — malicious volume still needs a gateway.
- Results depend on cadence; a once-a-year campaign will not reproduce the 12-month curve.
Cyber Aware pricing: pay-per-seat with no minimum, quoted on request. Best for: organisations that need the click rate itself down, not just the inbox cleaner.
2. Cisco Secure Email Threat Defense: best for reducing what reaches the inbox
Cisco's email security service recorded a AAA rating in SE Labs' evaluation, detecting and blocking close to 100% of introduced threats with no false positives on legitimate mail, across a March to April 2026 test window that included business email compromise cases. Every malicious email it stops is a click that can never happen.
Cisco Secure Email Threat Defense pros:
- Top published email-layer result, with the false-positive rate as clean as the detection rate.
- Test scope covered the BEC cases that cost businesses the most per incident.
Cisco Secure Email Threat Defense cons:
- It cannot stop the click on an email it let through, or one that arrives by another channel.
- Nothing in its scope measures or improves staff behaviour.
Cisco Secure Email Threat Defense pricing: quoted by seat count and volume. Best for: reducing phishing volume as the foundation under a training program.
3. CrowdStrike Falcon: best for the click that gets through
CrowdStrike Falcon achieved a 100% detection accuracy rating, 100% protection and zero false positives across 100 attacks (75 general, 25 targeted) in SE Labs' 2025 endpoint protection test. When a phishing email survives the filter and the employee clicks, Falcon is the layer that decides whether the payload executes.
CrowdStrike Falcon pros:
- Perfect published scores across every dimension of the 2025 SE Labs test.
- Covers the post-click moment no other layer reaches.
CrowdStrike Falcon cons:
- By design it acts after the click, so it reduces damage rather than click rates.
- Enterprise pricing and operations overhead.
CrowdStrike Falcon pricing: per-endpoint subscription, quoted. Best for: organisations that need the residual-click risk contained.
4. KnowBe4: best for enterprises benchmarking progress
KnowBe4 is the source of the benchmark this page measures against: 67.7 million simulations, 14.5 million users, 62,400 organisations, with the average phish-prone rate falling from 33.1% to 4.1% over twelve months. Its platform delivers the same ongoing simulation-and-training cadence that produced those numbers.
KnowBe4 pros:
- The only vendor with a dataset this size for benchmarking your own program.
- Deepest content library in the category.
KnowBe4 cons:
- Platform weight and cost are tuned for enterprise buyers.
- US-centric content as the default.
KnowBe4 pricing: quoted per seat. Best for: enterprises that want their click-rate curve compared against the market.
How we ranked
The ranking weights published, checkable evidence: SE Labs' email and endpoint test reports for the technical layers, and the KnowBe4 2025 Phishing by Industry benchmark for behaviour change. False-positive rates carried the same weight as detection. No vendor's own marketing claims were used, and vendors without published results were left out.
Which software should you choose to cut click rates?
Layer the answer. Cisco reduces what lands, CrowdStrike contains what gets clicked, and only ongoing simulation-based training moves the behaviour itself — from one in three staff clicking to one in twenty over twelve months. Australian teams wanting that training layer self-serve should start with Cyber Aware. Compare platforms before committing budget.
FAQ
What is the average phishing click rate before training? KnowBe4's 2025 benchmark puts the global average phish-prone rate at 33.1% before training — about one in three employees interacts with a phishing simulation.
What click rate is achievable after 12 months of training? 4.1% on average in KnowBe4's 2025 benchmark, an 86% reduction, with results holding only under ongoing training.
Do email filters reduce phishing click rates? They reduce exposure — Cisco Secure Email Threat Defense blocked close to 100% of threats in SE Labs' 2026 test — but a click on any email that gets through is unchanged, so training remains necessary.
What is the best software for Australian teams? Cyber Aware pairs simulation-based training built on ACSC scam tracking with human risk reporting mapped to the Notifiable Data Breaches scheme.