What the phish-prone rate actually measures
Your phish-prone rate is the percentage of employees who take the unsafe action in a phishing simulation, usually clicking a link or submitting credentials, over a defined period. If you send a simulation to 1,000 people and 90 click the link, your phish-prone rate is 9 percent. It is the single most quoted number in any security awareness program, and also the most misused.
The number only means something when the denominator and the difficulty are consistent. A 4 percent rate against an obvious, badly written lure tells you almost nothing. The same 4 percent against a well-crafted, contextual lure that mimics a real OJK notice or a payroll update is a genuinely strong result. Before you celebrate or panic, ask what was sent, to whom, and how hard it was to spot.
Treat the rate as a trend, not a verdict. A program that drops from 22 percent to 8 percent over four quarters of steady, escalating simulations is working. A flat 3 percent achieved by sending the same easy template every month is a vanity metric that will collapse the moment a real attacker raises the difficulty.
Lever one: realistic, escalating simulation
Behavior change starts with realistic practice. Begin with a baseline simulation that nobody on staff has been warned about, so you capture an honest starting number. From there, escalate difficulty deliberately: vary the pretext (IT helpdesk, HR, finance, courier delivery, government notice), the channel (email, and where appropriate WhatsApp or voice), and the urgency cues. Localized lures matter in Indonesia, a fake notification styled after a bank or a tax office will outperform a generic English template every time, which is exactly why you should test against it.
Segment your audience. Finance and executive assistants handle payment requests and are worth targeting with business email compromise scenarios. Frontline and branch staff face different pressures. Tracking the phish-prone rate per department, role, and tenure surfaces where the real risk concentrates, so you can direct training where it pays off instead of spraying everyone equally.
Keep simulations ethical and proportionate. Avoid lures that exploit genuinely distressing themes such as layoffs, bonus cuts, or personal emergencies, they damage trust and rarely teach anything useful. The goal is to build recognition and reporting reflexes, not to humiliate people.
Lever two: just-in-time training that actually sticks
The most teachable moment in a security program is the few seconds after someone clicks a simulated lure. Just-in-time training delivers a short, specific lesson at that exact moment, showing the person the red flags they missed in the email they just clicked. This beats an annual one-hour course because it is contextual, immediate, and tied to a real mistake the learner just made.
Keep the follow-up training micro and focused. A two-minute module that explains the three signals in that specific lure, a mismatched sender domain, an artificial deadline, a link that does not go where it claims, builds durable pattern recognition. Long, generic compliance videos check a box but move the phish-prone rate very little.
Make remediation supportive, not punitive. Frame the moment as coaching. People who fear being shamed will hide their mistakes, which is the opposite of what you need. Training should ship bilingually so Bahasa Indonesia speakers get first-class content, not an afterthought translation, comprehension is part of the security control.
Lever three: a reporting culture that turns staff into sensors
A low click rate is good. A high report rate is better. When an employee recognizes a suspicious email and reports it, they convert a potential incident into early-warning intelligence for your security team. The report rate, the percentage of recipients who flag a simulation, is the metric that best predicts resilience against novel, never-before-seen attacks.
Make reporting effortless. A one-click report button inside the email client removes friction so reporting becomes a reflex, not a chore. Acknowledge every report quickly, even an automated thank-you, so people know the action mattered. Recognize and reward consistent reporters; positive reinforcement builds the behavior far faster than warnings ever will.
Close the loop publicly when you can. When a reported email turns out to be a real threat that your team blocked because someone spoke up, share that story, anonymized. Nothing builds a reporting culture faster than proof that reporting prevents harm.
The Indonesian regulatory context
For regulated organizations in Indonesia, a measurable awareness program is not just good hygiene, it supports compliance obligations. OJK regulations on the implementation of information technology and cyber resilience for financial services institutions expect ongoing security awareness as part of a managed risk program, and a documented phish-prone rate trend is concrete evidence that the program exists and works.
Indonesia's Personal Data Protection Law, UU No. 27 of 2022 (UU PDP), holds organizations accountable for protecting personal data, and phishing is a leading cause of the breaches that expose it. Demonstrating that you actively train and test staff strengthens your position on organizational and technical safeguards. BSSN guidance on national cyber security similarly emphasizes human-factor readiness alongside technical controls.
Keep claims conservative and evidence-based. Regulations set expectations for security governance and risk management rather than mandating a specific phish-prone rate target. The value of your program is the documented, improving trend and the audit trail behind it, not a single headline number. Always confirm current requirements against the latest official text, as regulations and implementing rules evolve.
Putting it together: a 90-day starting plan
Days 1 to 30: run a no-warning baseline simulation across the whole organization, segment the results by department and role, and deploy the one-click report button. Record your baseline phish-prone rate and report rate so every later number has a reference point.
Days 31 to 60: launch monthly simulations with rising difficulty, wire up just-in-time micro-training for anyone who clicks, and begin acknowledging reports within the same day. Brief leadership on the trend, not raw incident counts, so they understand direction rather than reacting to single events.
Days 61 to 90: review the per-segment data, concentrate extra training on the highest-risk groups, and set realistic quarterly targets, for example a steady reduction in click rate paired with a steady rise in report rate. Sustained, modest improvement quarter over quarter beats a one-time drop every time.
Key takeaways
- The phish-prone rate is only meaningful as a trend over consistent, escalating difficulty, not as a single number against easy lures.
- Three levers move the rate: realistic segmented simulation, just-in-time micro-training at the moment of the click, and a frictionless reporting culture.
- Report rate predicts resilience against novel attacks better than click rate does, so reward and acknowledge every report.
- Keep remediation supportive rather than punitive, and ship training bilingually so Bahasa Indonesia speakers get first-class content.
- A documented, improving phish-prone rate trend supports OJK, UU PDP, and BSSN expectations as evidence of a managed awareness program.