A good phishing report rate is one that climbs month after month and ends up far above your click rate — on a mature monthly programme, 50% or better, with click rates under 10% and falling. But the more useful answer is directional: your first month's number is a baseline, not a grade, and the trend over the following six months is the real verdict. Report rate is the single most predictive number in a phishing programme — it tells you how quickly your organisation spots and stops a real attack — and most businesses have never once looked at it. This guide defines it, benchmarks it, and shows how to move it.
What is a phishing report rate?
The report rate is the share of recipients who flagged a simulated phishing email as suspicious, using your report button or process:
Report rate = (number of people who reported the email ÷ number who received it) × 100
If 40 staff receive a campaign and 6 report it, the report rate is 15%. The same campaign's click rate might be 22% — 9 people clicked the link. Both numbers describe the same email, and they measure completely different things:
- Click rate measures how many people were fooled — after the fact, after the risk already passed through them.
- Report rate measures how many people acted — which is the behaviour that stops the real email from turning into a successful attack.
That asymmetry is why mature security programmes watch report rate first. A workforce with a 20% click rate and a 40% report rate is safer than one with a 10% click rate and a 2% report rate, because in the first organisation every attack gets flagged within minutes and neutralised, while in the second most attacks sail through unreported.
What is a good report rate? The trajectory to aim for
These are the ranges we see on healthy monthly programmes at Cyber Aware. Your first month will vary with template difficulty and how experienced your team is with simulations — that is expected.
| Programme stage | Click rate | Report rate | What it means |
|---|---|---|---|
| Month 1 — first-ever simulation | 15-30% | Under 10% | Baseline. Staff are seeing the exercise for the first time |
| Months 2-4 | 8-15% | 10-25% | Click rate trending down, reporting starting to form as a habit |
| Months 5-8 | Under 10% | 25-50% | Behaviours consolidating; repeat clickers shrinking |
| Mature programme (month 8+) | Under 5-10% | 50%+ | Cyber Aware's benchmark: ~80% average reduction in clicked links on monthly cadence |
Read the table as a direction, not a contract. A business that hits a 25% report rate in month three on genuinely difficult templates is ahead of one that hits 45% on laughably obvious ones — which is why template difficulty needs to escalate as your team improves. The honest pairing is: click rate falling, report rate rising, templates getting harder.
Why report rate matters more than click rate
A reported email protects everyone who has not opened it yet. When an employee reports a simulated (or real) phishing email, your security team or platform can pull the message from other inboxes before they read it. In a real incident, minutes matter: the difference between a report landing in five minutes versus five hours is often the difference between one exposed credential and forty.
Click rate can be gamed; report rate cannot. You can make your click rate look heroic by sending templates so obvious a child would spot them. That produces a nice quarterly slide and zero protection. Report rate resists this game — staff either recognise a message as suspicious and act, or they do not — which is why it is the number to put in front of leadership.
Report rate is a culture measurement. It moves when people feel safe reporting, know the one-step process, and believe it is worth doing. Those are exactly the traits that decide how your organisation handles a real attack.
The number that pairs with it: repeat clickers
Alongside report rate, track the small group of people who click more than once. In most organisations a handful of people account for a disproportionate share of clicks, and that concentration is good news: it means the risk is addressable. A programme is working when the repeat-clicker list shrinks month over month. Cyber Aware's phishing simulations report click rate, report rate and repeat clickers per person after every campaign, so the three numbers can be read together.
How to raise your report rate in 90 days
- Make reporting one click. If reporting an email means forwarding to an address, attaching as an attachment, then describing what happened, almost nobody will do it. A native report button in the mail client is the single biggest lever.
- Praise reporters by name after each campaign. A short shout-out in the company channel costs nothing and does more for next month's number than any memo. People repeat behaviour that gets noticed.
- Vary templates and escalate difficulty. Reusing the same three emails teaches staff to recognise your templates, not the tactics. Rotate through current scam patterns — invoice fraud, MFA fatigue, fake courier notifications — and get harder as report rate climbs.
- Auto-enrol clickers into short training the same week. When a click is followed within days by a five-minute course on exactly that tactic, the next campaign's numbers move. Cyber Aware's Auto Phish does the enrolment automatically.
- Run monthly. An annual campaign measures a moment. A monthly cadence builds and maintains a habit — the 80% click-rate reduction benchmark above is measured on monthly programmes, not annual ones.
- Have leadership participate and report too. When the managing director's own report rate appears in the same chart as everyone else's, the exercise stops being an IT chore.
Reporting your numbers without the spreadsheet pain
The five numbers worth reporting each month: click rate, report rate, time-to-report, repeat clickers, and remediation training completion. Cyber Aware's human risk reporting tracks all of them per person per month, so the trend reaches your leadership without anyone maintaining a spreadsheet.
FAQ
Is a 30% report rate bad?
On a first-ever simulation it is excellent. On a two-year-old programme it is mid-pack. Always read the number against the month it came from — the trend is the verdict, not the snapshot.
Should our simulation emails be easy to spot so report rate looks good?
No. Easy templates inflate both your report rate and your confidence. Escalate difficulty as the team improves; the goal is protecting against the scams actually in circulation, not a flattering chart.
Our report rate is high but clicks are not falling. What is wrong?
Usually one of two things: templates are easy enough that reporting is trivial, or clickers are not receiving remediation training. Check that the auto-enrolment loop is actually firing the same week as each click.
Can the report rate be too high?
Only in the benign sense that staff start reporting legitimate mail. That is a tuning problem, not a culture problem — and it is vastly preferable to silence. Adjust as needed; never discourage reporting.
Should we track who reports and who does not, individually?
Yes, per-person data is how coaching happens — but use it to celebrate and coach, never to discipline. The moment reporting feels risky, the number you most need stops telling the truth.