Most phishing assessments produce a single headline number: the click rate. But a click rate in isolation tells you very little about your actual risk. An organisation where 20% of people clicked but 80% reported the email is in a fundamentally different position from one where 20% clicked and nobody reported it.

Measuring phishing resilience properly means tracking the right metrics, understanding what they actually indicate, and using them to drive targeted improvement.

Beyond the click rate

The click rate — the percentage of recipients who clicked a link in a phishing email — is the most commonly reported metric. It is also the most commonly misunderstood.

A click is not a compromise. Clicking a link and immediately recognising the page as fraudulent is a very different outcome from clicking a link and entering credentials. Treating both as equivalent overstates the risk and produces misleading comparisons between campaigns.

Furthermore, click rates vary enormously depending on the sophistication of the pretext, the time of day, the day of the week, and even the subject line. A 5% click rate on a generic “your package is waiting” email and a 40% click rate on a tailored email referencing a real internal system are not comparable measurements — they test different things.

The click rate is useful as one data point among several. It should never be the only metric reported, and it should always be presented alongside context.

The metrics that matter

Credential submission rate

The percentage of recipients who entered credentials on the phishing page. This is the metric that most directly corresponds to real-world risk, because a submitted credential gives an attacker access.

Tracking the submission rate separately from the click rate reveals important information. If 30% click but only 5% submit credentials, most employees are catching themselves at the login page — a sign that awareness training is working at that stage. If 30% click and 25% submit, the problem is more serious.

Report rate

The percentage of recipients who reported the phishing email through the organisation’s designated reporting mechanism. This is arguably the single most important metric for organisational resilience.

An organisation with a high report rate can detect and respond to real phishing campaigns quickly. The first person to report a phishing email triggers a response that protects everyone else. Even if some employees click, a fast report rate limits the window of exposure.

Conversely, an organisation where nobody reports — even those who recognised the email as suspicious — has no early warning system. Real phishing emails will circulate unchecked until someone falls for them or the security team discovers them through other means.

Time to first report

How quickly the first report was received after the campaign email was sent. This measures the speed of the human detection layer.

In a real phishing campaign, time matters. A report received within five minutes of the email being sent allows the security team to block the phishing domain, quarantine remaining emails, and warn employees. A report received 24 hours later is too slow to prevent most damage.

Tracking this metric over successive campaigns shows whether the reporting culture is improving.

Repeat offenders

Individuals who click or submit credentials in multiple campaigns. This is not about blame — it identifies people who may need additional, targeted support.

Repeat offenders often fall into a few categories:

  • People in high-pressure roles who are conditioned to act quickly on email.
  • People with lower technical literacy who do not recognise phishing indicators.
  • People who missed previous training or were not engaged by it.

Identifying these individuals allows the organisation to provide targeted, one-to-one support rather than relying on generic training to reach everyone.

Campaign-specific performance

Not all phishing campaigns test the same thing, and results should not be aggregated without context. Track each campaign independently and note:

  • The pretext used (generic vs targeted vs spear-phishing).
  • The campaign type (link click, credential harvesting, attachment, QR code).
  • The target population (all staff, specific department, specific individuals).
  • The date and time of delivery.

This allows the organisation to understand which types of attack are most effective against which groups — and to target defences accordingly.

Segmenting results

Aggregate metrics hide important variation. Breaking results down by segment reveals where the real risk lies.

By department. Finance, HR, IT, and executive teams often show different resilience patterns. Finance teams may be well-trained on invoice fraud but vulnerable to credential harvesting. IT teams may be resilient to generic phishing but overconfident in their ability to spot targeted attacks.

By seniority. Senior leaders are common spear-phishing targets and may have less time for training. Understanding their resilience separately from the general population is critical.

By location or office. Multi-site organisations may find that awareness varies between locations, particularly if training has been delivered inconsistently.

By tenure. New employees may not yet have received training. Long-tenured employees may have attended training years ago and forgotten it.

Segmented data allows the organisation to allocate training resources where they will have the most impact.

Using data to drive improvement

Metrics are only useful if they lead to action. The data from phishing assessments should feed into a continuous improvement cycle.

Set targets. Based on baseline measurements, set realistic improvement targets for each metric. For example: reduce the credential submission rate from 15% to 8% over three campaigns, or increase the report rate from 10% to 30%.

Target training. Use segmented data to deliver training where it is needed most. A department with a 40% click rate needs different intervention from one with a 5% click rate.

Adjust campaign difficulty. As resilience improves, increase the sophistication of the campaigns. If the organisation consistently handles generic phishing well, move to targeted and spear-phishing scenarios to test the next level of defence.

Report to leadership. Present metrics in a format that senior leadership can act on. Trend lines over time are more useful than individual campaign results. Frame the data in terms of risk reduction rather than pass/fail.

Benchmark externally. Compare results against industry averages (available from phishing platform vendors and industry reports) to understand how the organisation compares to peers. External benchmarks provide context that internal metrics alone cannot.

A word on responsible measurement

Phishing metrics measure organisational resilience, not individual competence. Publishing league tables of who clicked, naming people in reports, or applying disciplinary consequences for clicking a test email are counterproductive. They create fear, suppress reporting, and undermine the goal of building a security-aware culture.

The most resilient organisations are those where employees feel safe reporting mistakes. Measurement should reinforce that culture, not erode it.