Security leaders are encouraged to implement department-specific training to address the unique risk profiles and behavioral disparities found across different corporate sectors. Modern enterprises often miscalculate their vulnerability to cyberattacks by focusing on a single, narrow metric: the click rate. According to the Pistachio Phishing Behaviour Report, true phishing resilience is a complex, multifaceted concept that requires looking at a chain of behaviors rather than just the initial interaction. To accurately assess an organization’s defensive posture, security leaders must evaluate link engagement, credential disclosure, and proactive threat reporting. This comprehensive analysis moves beyond surface-level data to reveal how employees actually respond to sophisticated threats over time. Based on a 12-month study of over 120,000 users across 648 organizations, the research tracks a journey analysis rather than a snapshot in time. By monitoring nearly 355,000 simulations, the report demonstrates that employee performance does not follow a simple, upward path. Instead, the data shows that progress is often non-linear, influenced heavily by the increasing difficulty and frequency of the simulations. This longitudinal approach provides a realistic view of how a workforce evolves from being potential victims to becoming active participants in a company’s security infrastructure.
Challenging Traditional Metrics and the Six-Month Hump
The Hidden Reality: Understanding Non-Linear Progress
Many organizations become discouraged when they see a spike in click rates mid-way through a training program, but this six-month hump is often a sign of progress rather than failure. As training matures, the difficulty of simulations typically increases, with over half of the tests reaching a Hard classification by the six-month mark. These sophisticated exercises expose underlying vulnerabilities that easy tests miss, meaning a temporary rise in clicks indicates more rigorous preparation for real-world attacks. Low click rates can be deceptive if the tests are too simple, creating a false sense of security that leaves the company wide open to high-level social engineering. By the six-month mark, users typically receive an average of 3.5 simulations per person, exposing them to varied tactics. Therefore, a temporary spike in engagement is often an indicator of more rigorous testing rather than a decrease in employee vigilance or training efficacy.
True resilience is built upon three distinct but interconnected behaviors: clicking, credential submission, and reporting. The data shows that while clicks might decline by 27% between the six-month and 12-month marks, credential leaks drop even more significantly—by 41%. This suggests that even if employees are still occasionally tricked into clicking a link, they are becoming much better at recognizing the danger before they provide sensitive data. A low click rate can be deceptive; if the tests are too easy or use familiar templates, they create a false sense of security without actually preparing the workforce for real-world, high-sophistication attacks. Security leaders must therefore prioritize credential protection as a more critical KPI than initial link engagement. This behavioral shift represents the core of modern defensive maturity, where the objective is to mitigate the impact of a click rather than obsessing over the click itself.
The Reporting Revolution: Turning Targets into Defenders
A vital trend identified in recent research is the rise of the report-to-click ratio, which serves as a primary indicator of a healthy security culture. Over the course of a year, this ratio increased from 1.3 to 1.8, meaning that by the end of a mature training program, suspicious emails were being reported nearly twice as often as they were being clicked. When an employee reports a phishing attempt, they transition from a potential victim to an active part of the company’s detection infrastructure. This provides the security team with early visibility into an attack, allowing them to purge similar messages from the entire network before other users have a chance to interact with them. Making the reporting process frictionless—such as using one-click reporting tools—is essential for turning a passive workforce into a human firewall. Proactive reporting effectively turns the workforce into a distributed sensor network, providing a strategic advantage that goes far beyond individual caution.
In the final analysis, organizations that shifted their focus from avoidance to active defense saw the most significant gains in cybersecurity maturity. Security teams moved away from generic modules and instead prioritized the report-to-click ratio as their primary indicator of success. By the end of the observation period, the most resilient firms had integrated automated reporting tools that allowed users to flag suspicious content with a single click. These entities successfully transformed their workforce into a distributed sensor network, effectively closing the gap between detection and remediation. The transition to department-specific simulations proved that technical knowledge was not a substitute for behavioral habit, as even IT departments required specialized training to counter sophisticated social engineering. Ultimately, the industry moved toward a more nuanced understanding of risk, where a successful simulation was defined by the speed of the reporting response rather than the absence of user interaction with the malicious link.






