Phish-Prone Rate
The percentage of employees who fail a simulated phishing test by clicking a link, opening an attachment, or submitting credentials.
Definition
Phish-prone rate is a security awareness metric representing the percentage of employees within an organization who fail a simulated phishing test, typically by clicking a malicious link, opening an attachment, or entering credentials on a fake page. It is commonly tracked over time, per department, or per campaign to measure organizational susceptibility to phishing and the effect of training.
Phish-prone rate is calculated by dividing the number of employees who fail a given simulated phishing campaign by the total number who received it, expressed as a percentage. Failure is usually defined by the action taken, such as clicking a link, versus more severe actions like submitting credentials on a spoofed login page, so many organizations track multiple tiers of failure rather than a single number. Comparing phish-prone rate across departments, seniority levels, or attack types often reveals where targeted training investment will have the greatest impact.
This metric matters because it gives security leaders a concrete, trackable number to report to executives and boards, turning an abstract concern about human risk into a measurable trend that can justify training investment. A declining phish-prone rate over successive simulation campaigns is generally interpreted as evidence that awareness training and simulation are working, while a rising rate can flag emerging risks, such as new hires or increasingly sophisticated attack templates. Regulators and compliance frameworks in sectors like banking increasingly expect organizations to track and report on this kind of behavioral metric alongside technical controls.
Phish-prone rate should be interpreted carefully rather than used punitively, since fear of being publicly named for a failed simulation can discourage employees from reporting real phishing attempts. The metric is most useful when read alongside reporting rate, the percentage of employees who correctly identify and report a phishing attempt, since a low phish-prone rate combined with a low reporting rate may simply mean employees are unengaged rather than fully protected. Benchmarking against industry averages provides useful context, but the most meaningful comparison is an organization's own trend over time.
At a glance
- Type
- Security metric
- What it measures
- Share of employees who fail a simulated phishing test
- Healthy target
- Under 5%
- Better when
- Lower
How it works
- 1
Campaign run: a simulated phishing test is sent to a defined group of employees.
- 2
Failure tracking: the platform records who clicked a link, opened an attachment, or entered credentials.
- 3
Calculation: the number who failed is divided by the total number who received the campaign, expressed as a percentage.
- 4
Tiering: many organizations track multiple failure tiers, since clicking a link is less severe than submitting credentials.
- 5
Trend comparison: the rate is compared across departments, seniority levels, and successive campaigns.
Key points
- It represents the percentage of employees who fail a simulated phishing test
- Failure is usually tiered, from clicking a link to the more severe act of submitting credentials
- A declining rate over successive campaigns is generally read as training and simulation working
- It should be read alongside reporting rate, since a low phish-prone rate with low reporting may mean disengagement, not protection
- Comparing across departments and attack types reveals where targeted training will help most
Best practices
- Track phish-prone rate over time rather than as a single snapshot
- Break the metric down by department, seniority, and attack type
- Read it alongside reporting rate to avoid mistaking disengagement for safety
- Avoid using the metric punitively, since fear of public naming discourages real phishing reports
- Benchmark against industry averages for context, but prioritize the organization's own trend
Real-world example
A bank's phish-prone rate falls from 18 percent to 6 percent over four quarterly campaigns after introducing just-in-time training for anyone who clicks. The security team presents this downward trend to the board as evidence that the awareness program is working, alongside a rising reporting rate that confirms engagement, not just avoidance.
How Claro helps
Claro calculates phish-prone rate automatically from every simulation campaign, breaking it down by department and attack type so security teams can target training where it is needed most.
Frequently asked questions
How is phish-prone rate calculated?
By dividing the number of employees who failed a given simulated phishing campaign by the total number who received it, expressed as a percentage.
What counts as a failure in a phishing simulation?
Definitions vary, but clicking a link, opening an attachment, and entering credentials on a fake page are the most common tiers, with credential submission treated as more severe.
What is considered a healthy phish-prone rate?
Many organizations aim for a rate under 5 percent as a sign of a mature program, though the most meaningful benchmark is an organization's own trend over successive campaigns.
Why shouldn't phish-prone rate be used punitively?
Publicly naming employees who fail a simulation can discourage them from reporting real phishing attempts out of fear, which undermines the behavior the program is trying to build.
Related terms
Phishing Simulation
A controlled, authorized exercise that sends realistic but harmless fake phishing messages to employees to measure how they respond and to train safer behavior.
Security Awareness Training
Security awareness training is structured education that teaches employees to recognize and respond to cyber threats such as phishing, social engineering, and unsafe data handling.
Human Risk Management
A security discipline that identifies, measures, and reduces the risk that people introduce through their everyday behavior.
Security Culture
The shared attitudes, beliefs, and everyday behaviors around security that exist across an organization, beyond formal policy and training.
Reduce your human risk
Claro measures and lowers the risk these terms describe, in English and Bahasa Indonesia.
Request a demo