Security awareness training vendor benchmarks in 2026 converge on one story: roughly one in three employees fails a baseline phishing test before training, that figure falls to around 4-5% after twelve months of a real programme, and the reporting rate — not the click rate — is the metric that separates mature programmes from checkbox training. The numbers below come from the industry's large-scale benchmark studies: KnowBe4's Phishing by Industry Benchmarking Report (67.7 million simulations, 62,460 organisations), Hoxhunt's Phishing Trends Report (50+ million data points from four million users) and the Verizon DBIR.
Phishing susceptibility benchmarks, at a glance
| Benchmark | 2026 figure | Source |
|---|---|---|
| Baseline phishing click rate, untrained | 33.1-33.2% globally | KnowBe4 2025 & 2026 benchmark reports |
| After 90 days of training | 18.5-20.1% | KnowBe4 benchmark data |
| After 12 months of training | 4.1-4.2% | KnowBe4 benchmark data |
| Improvement over the year | 79-86% reduction | KnowBe4 press releases |
| Baseline, businesses under 250 staff | ~24.7% | KnowBe4 2026 report |
| Baseline, enterprises 10,000+ staff | 39.5% | KnowBe4 2026 report |
| Failure rate after 12 months (engaged programmes) | below 2% | Hoxhunt Phishing Trends Report |
| Reporting rate, trained users | ~21% vs 5% base rate | Verizon DBIR 2025 |
What the big three report cards say
KnowBe4 runs the most-cited benchmark: its Phishing by Industry Benchmarking Report measures the Phish-prone Percentage (PPP) — the share of employees likely to engage with a phishing attempt — across tens of millions of simulations. The 2025 edition put the global baseline at 33.1% and the twelve-month figure at 4.1%, an 86% reduction. The 2026 edition repeated the pattern with a 33.2% baseline falling to 4.2%, a 79% drop, across 14.5 million users in 62,400 organisations.
Hoxhunt reports on a different axis — failure and success rates on gamified simulations. Its 2026 trends data shows failure rates falling 5.5x, from 11% to below 2%, after twelve months, with success rates more than doubling from 34% to 74% by the twelfth simulation. Its headline for laggards: engagement above 60% and failure rates under 2% are achievable in behaviour-focused programmes.
Verizon's DBIR supplies the external yardstick: trained users report phishing at roughly 21%, against a base rate near 5% — a 4x lift. A click rate alone never captures this; a programme where nobody clicks but nobody reports either has learned nothing.
Benchmarks by company size
Baseline susceptibility rises with organisational size in KnowBe4's 2026 data: small businesses under 250 staff start at roughly 24.7%, mid-market climbs through the twenties and thirties, and enterprises with 10,000+ employees open at 39.5%. The reasons are structural — smaller firms know each other, larger ones have departments that never met — but the implication for an SMB buyer is counterintuitive: small businesses start with an advantage and reach the sub-5% band faster, while enterprise programmes need more months and more simulation volume to get there.
Benchmarks by industry
The 2026 report's most vulnerable industries at baseline were Healthcare & Pharmaceuticals (42.7%), Insurance (38.1%) and Retail & Wholesale (36%). Technology firms start lower — around 12% in Proofpoint's State of the Phish data — and reach roughly 1.5% after training, the excellence benchmark. Education and healthcare consistently carry the highest initial click rates, which tracks with staff who handle high-pressure inboxes and unfamiliar senders daily.
The metric that matters more than click rate
Every benchmark publisher now makes the same point: click rate is a lagging indicator, reporting rate is the leading one. A workforce that clicks less but reports more is genuinely maturing; a workforce that clicks less because users have simply learned to ignore everything is not. The established targets:
- Click/failure rate: below 5% is solid, below 2% is excellence, above 10% signals unaddressed human risk.
- Report rate: roughly 20%+ on simulations is the global benchmark; mature programmes push far higher, and every point of report rate shortens real incident response.
- Time-to-remediation: the interval between a failed simulation and the corrective training — automated platforms close it to minutes, manual programmes leave it at weeks.
That third benchmark is where platforms genuinely differ: auto-enrolment on phishing failure turns a click into a lesson the same day, which is the mechanism behind the twelve-month numbers above. A platform that only measures the click without closing the loop tends to plateau around 8-10%.
What a twelve-month programme costs against these numbers
The training that produces a 4-5% click rate costs $10-$72 per employee per year across the paid market, with most platforms in the $20-$40 band once phishing simulations are included — the full cost breakdown is here. Set against the reported average cost of a data breach for an Australian small business in 2024-25 (about $56,600), a 50-seat programme at $900-$1,800 a year is one of the cheapest controls in the stack — and the only one aimed at the human element involved in the majority of breaches.
How to benchmark your own programme
- Run a baseline simulation before training begins. The 33% global baseline is the comparison point; without a baseline, none of your later numbers mean anything.
- Measure at 90 days and 12 months. Those are the intervals the benchmark data uses, so your curve can be compared like for like.
- Track report rate from day one, and treat a rising report rate alongside a falling click rate as the real success signal.
- Segment by department. Finance and operations typically click most; IT and security least. Whole-company averages hide the concentration.
- Benchmark against your size band, not the global average. A 40-person firm should compare against the ~25% small-business baseline, not the 39.5% enterprise figure.
Where Cyber Aware sits against these benchmarks
Cyber Aware's platform is built around the same loop the benchmarks reward: 120+ story-driven modules on a monthly cadence, continuous phishing campaigns, automatic enrolment of clickers into remedial training, and a human risk score that trends click rate, report rate and completion together. For MSPs the same numbers deliver white-labelled per client — which is the segment most benchmark reports under-serve because their data skews enterprise.
FAQ
What is a good phishing click rate in 2026? Below 5% is a solid, mature programme; below 2% is excellence. The global twelve-month benchmark is 4.1-4.2%, so anything under 5% after a year of training is on benchmark.
What percentage of employees fail a phishing test without training? About one in three: 33.1-33.2% in KnowBe4's 2025 and 2026 global benchmarks, with small businesses lower (~24.7%) and large enterprises higher (39.5%).
How much does click rate improve after a year of training? By 79-86% in KnowBe4's data — from roughly 33% to 4-5% after twelve months of ongoing training and simulations.
Is report rate or click rate the better metric? Report rate. The Verizon DBIR puts trained-user reporting at about 21% versus a 5% base rate, and a rising report rate is the earliest signal of genuine behaviour change.
Do small businesses get better results than enterprises? They start better (24.7% vs 39.5% baseline) and reach the sub-5% band faster, largely because smaller workforces are easier to reach consistently.
Which industries are most phish-prone? Healthcare & Pharmaceuticals (42.7%), Insurance (38.1%) and Retail & Wholesale (36%) top the 2026 baseline rankings.
One last thing
A 4% click rate on easy simulations is not better than a 12% rate on hard ones — benchmark publishers consistently warn that difficulty is the variable that breaks comparisons. When you benchmark against these numbers, hold simulation difficulty constant first, or you will benchmark the campaign design instead of the workforce.
Related guides
- How much does security awareness training cost in 2026?
- Phishing simulations
- Human risk reporting
- Compare platforms