For years, phishing simulations have been judged primarily by one metric: click rate.
The appeal is obvious. Clicks are straightforward to measure, easy to benchmark, and serve as an intuitive indicator of user susceptibility. A declining click rate is often taken as evidence that a security awareness program is succeeding.
Yet click rates tell only part of the story.
Fortra’s 2025 Phishing Simulation Benchmark Report found that only 5.42% of users clicked simulated phishing links, and just 10.5% reported the phishing emails they received. In other words, nearly nine out of ten phishing simulations generated no actionable signal for security teams.
This finding reframes an important question. Rather than asking whether employees recognize phishing attempts, CISOs should ask whether their organizations possess sufficient visibility to detect and respond when phishing campaigns inevitably evade technical controls.
Visibility Is a Security Capability
Modern email security assumes imperfect prevention.
Secure email gateways, URL analysis, reputation services, and browser protections eliminate a substantial volume of malicious email, but they cannot eliminate uncertainty. Attackers continually adapt their infrastructure, delivery mechanisms, and lures to remain one step ahead of technical interventions.
Consequently, some phishing emails will reach end users.
When that occurs, employees become an extension of the organization’s detection architecture. Every reported email provides security teams with an opportunity to identify an active campaign, locate additional recipients, refine detection logic, and initiate containment before a broader compromise occurs.
Conversely, every suspicious email that is deleted without being reported represents lost telemetry.
The benchmark therefore highlights a frequently overlooked distinction: user susceptibility and organizational visibility are related but not synonymous. An employee who ignores a phishing email without interacting with it has avoided personal compromise, but the organization has gained no intelligence from the encounter.
Reporting Rates as an Operational Metric
Click rates measure individual behavior.
Reporting rates measure organizational capability.
This distinction deserves greater attention from executive leadership because phishing reports initiate operational processes that extend well beyond awareness training. A single report can trigger threat hunting, mailbox searches, indicator extraction, detection updates, and enterprise-wide remediation.
More importantly, reporting compresses response time.
A phishing campaign identified within minutes can often be contained before users begin interacting with it. The same campaign identified hours later may require credential resets, forensic investigation, and incident response.
Viewed through this lens, reporting rates are not merely awareness statistics. They are indicators of detection maturity.
Culture Matters More Than Technology
Many organizations have deployed phishing-reporting buttons in Outlook or Gmail, lowering the technical barrier to reporting suspicious messages. The relative ease or difficulty of reporting a suspected phishing message rarely explains low reporting rates.
Employees may assume someone else has already reported the message. Others believe security teams are already aware of the campaign. Some delete suspicious emails because doing so feels efficient. Others hesitate because they fear reporting a legitimate message.
These are not technical deficiencies. They are cultural ones.
Organizations with mature reporting cultures reinforce a simple principle: uncertainty is sufficient justification for reporting. False positives represent a manageable operational cost; undetected phishing campaigns do not.
This cultural distinction is subtle but consequential. Employees should view reporting not as escalating a problem, but as contributing to collective defense.
Click Rates Alone Can Create False Confidence
Executive dashboards frequently emphasize declining click rates as evidence of progress.
That emphasis is understandable but incomplete.
A reduction in clicks demonstrates that users are becoming more cautious. It does not necessarily indicate that the organization is becoming more observant.
Indeed, an organization could reduce click rates while simultaneously failing to improve reporting behavior. In such an environment, individual risk declines while organizational awareness remains stagnant.
The phishing benchmark report reinforces this point by demonstrating meaningful variation across geography, language, company size, and industry. These differences suggest that phishing resilience cannot be reduced to a single enterprise-wide metric. Risk behaviors and reporting behaviors vary considerably across different populations.
For CISOs, this argues for a broader set of performance indicators.
Click rates remain valuable.
Reporting rates, reporting velocity, departmental participation, and repeat reporting behavior may provide equally meaningful insight into organizational resilience.
Human Intelligence Remains an Essential Detection Layer
Organizations routinely invest in endpoint detection, network telemetry, SIEM platforms, and threat intelligence to improve visibility across their environments.
Human reporting should be viewed through the same lens.
Unlike automated systems, employees possess contextual awareness. They recognize unusual requests from executives, subtle deviations in vendor communications, and business-specific anomalies that detection algorithms may overlook.
This does not make employees a replacement for technical controls.
Rather, it recognizes them as another source of high-value telemetry within a layered detection strategy.
Security programs often describe defense in depth as a combination of overlapping technical safeguards. Human reporting deserves recognition as one of those layers.
A More Useful Question
Perhaps the most significant implication of the phishing benchmark is not the reporting rate itself, but the question it invites.
If nearly ninety percent of phishing simulations generate no report, what level of visibility should organizations expect during genuine phishing campaigns?
No benchmark can answer that question definitively.
It can, however, encourage security leaders to reconsider how success is measured.
Reducing click rates will always remain an important objective. But resilient organizations do more than prevent users from interacting with malicious emails. They cultivate a workforce that contributes meaningful intelligence to the detection and response process.
Ultimately, the value of a phishing simulation extends beyond identifying who clicked.
Its greater value may lie in revealing whether employees help the organization see the attack at all.