Phishing Simulation Click-Rate Benchmarks (2026) — What's Good, What's Not
PhishSim AI ·
When you run your first phishing simulation and a big chunk of the company clicks, the natural reaction is panic. Usually it shouldn't be — a high first-run rate is normal. What matters is where you start, how fast the number drops with training, and whether you're measuring it honestly. Here's how to read phishing click-rate benchmarks in 2026.
What's a "normal" click rate?
Treat these as broad ranges, not precise targets — the real number depends heavily on your industry, how convincing the lure is, and whether people have been trained before:
- First-ever simulation, no prior training: commonly 25–35%+. A large share of an untrained workforce will click a believable lure. This is a baseline, not a failure.
- After a few months of regular simulations plus training: often falls into roughly 10–15%.
- Mature program, running consistently for a year or more: frequently down toward 5% or lower.
The headline isn't the absolute number — it's the trajectory. A program that takes a workforce from 30% to 8% over two quarters is working, even though 8% isn't zero.
Why the lure difficulty changes everything
A benchmark is meaningless without context on the bait. A generic "your package is delayed" email and a targeted spear-phish impersonating your CEO will produce wildly different click rates from the same people. If you make your simulations trivially easy, you'll post a flattering low number and learn nothing. If you make them realistic, the rate is higher but the training is real.
Good programs gradually increase difficulty as the baseline improves, so the number stays honest rather than becoming a vanity metric.
The metric that matters more than click rate
Click rate tells you who's vulnerable. Report rate — the share of users who report the phish using the button in their email client — tells you who's actively defending. A mature security culture is one where the report rate climbs even as the click rate falls, because people aren't just avoiding the bait, they're flagging it.
If your tool only tracks clicks and not reports, you're seeing half the picture.
How to read your own number without fooling yourself
Three ways teams accidentally lie to themselves with this metric:
- Averaging away the risk. A 10% company-wide average can hide a department clicking at 40%. Always look at the distribution, not just the mean.
- Easy lures for a good number. If the rate looks great, check whether the simulation was actually convincing. A low rate on a weak lure proves nothing.
- Deliverability inflation. If simulations land in Junk, people never see them, and your "low" click rate is really a delivery failure. Make sure your simulations actually reach the inbox before you trust the number. (See our Microsoft 365 allowlisting guide.)
What to do with the benchmark
Don't chase a specific number. Set a baseline with a realistic first simulation, run monthly, pair every click with targeted training, and watch two lines: click rate trending down and report rate trending up. That's the program working — and it's exactly the evidence auditors and cyber insurers now expect to see documented.
PhishSim AI tracks both click and report rates per user over time, with the dated logs that turn your benchmark into a defensible record for compliance and insurance renewals.
Frequently asked questions
What is the average phishing click rate? For an untrained workforce's first simulation, 25–35%+ is common. With consistent training it typically falls to 10–15%, and mature programs often reach 5% or lower. Ranges vary by industry and lure difficulty.
Is a high click rate on the first test bad? No — it's expected and it's your baseline. What matters is how quickly the rate drops with regular simulations and follow-up training.
What's a good phishing report rate? There's no universal number, but the goal is a report rate that rises over time — ideally overtaking your click rate — which signals people are actively flagging suspicious mail, not just avoiding it.