Skip to main content

The Reporting Race: Why Your Click Rate Isn't the Number That Matters

, CEO
Chart showing the odds that the first action on a phishing email is a report rise from 33% to 89% as reporting rate increases

Somebody in your company will click the next phishing email. No training program changes that. What decides whether that click becomes an incident is whether someone reports the email before enough people click it. That's a race, and you can build your security awareness program to win it. Here's the short version of a working paper I just published on it.

The full paper, with every citation, is on psysec.io. This post covers what an awareness program leader or MSP needs to act on.

Why won't training get clicks to zero?

Three large studies published between 2022 and 2026 covered more than 45,000 employees between them. All three found that standard awareness training made little or no measurable difference to how often people clicked. The one thing that did predict clicking was how hard the email was to spot.

Even if training worked perfectly, the math is against you. A program with an excellent 1% click rate, sending to 200 people, still gets at least one click 87% of the time. At 4%, a click is close to certain. Attackers only need one person.

So the question isn't how to get clicks to zero. It's what happens after the first click.

What is the reporting race?

Picture a phishing email landing in 200 inboxes. Over the next hour, some people click and some people report. If a report comes in before the clicks pile up, your team pulls the email and warns everyone else. If the clicks come first, you're cleaning up an incident.

If clicks and reports arrive at roughly the same speed, the odds that the first action is a report are your report rate divided by your report rate plus your click rate:

  • 10% click rate, 5% report rate: the report comes first 33% of the time
  • 10% click rate, 20% report rate: 67%
  • 2.5% click rate, 5% report rate: 67%
  • 5% click rate, 40% report rate: 89%

Look at the second and third lines. Raising reporting from 5% to 20% buys the same head start as cutting clicks by three-quarters. Most programs spend nearly everything on the click side. The reporting side is at least as powerful, and attackers can't easily push it down. In interviews, people who report phishing said they were more likely to flag convincing emails, because those looked more dangerous.

The field data fit. In one 2026 study of 12,511 employees, the first report beat the first click in 36% to 55% of simulations. A 15-month study of 14,000 employees found reporting worked as a fast early-warning system, and reporters kept at it for the long haul.

How do you win the reporting race?

Stop grading your program on click rate

A click rate mixes two things: how alert your people are and how hard the email was. Easy emails in the 2026 study drew 7% clicks and hard ones drew 15%, with no measurable effect from training. Attackers control difficulty, and AI has made hard emails cheap. Fully automated AI spear phishing got 54% of people to click in one study, the same as emails written by human experts. Keep click rate as a diagnostic, always shown next to difficulty. Lead with reporting.

Keep it top of mind, and keep changing it

The research points to phishing as an attention problem more than a knowledge problem. Annual training showed no meaningful link to how people handled simulations. A one-time awareness push held for four months and was gone by six. Periodic reminders brought the gains back. Repetition wears out, though. Warnings that changed their look each time held attention far better than the same warning repeated.

Tell everyone how they did

Email almost never tells people whether they judged right. Someone who ignores a phishing email rarely finds out it was phishing. A simulation is one of the few chances to close that loop, and most programs waste it by sending feedback only to the people who clicked. When feedback went to everyone after a simulation, three field experiments found better results. Do the same with real reports: tell the reporter what the email was and what happened next.

Why does punishing clicks slow you down?

The person who just clicked knows something nobody else knows yet: an attack got through, what it looked like, and what they typed in. If they speak up right away, that's the earliest warning you'll ever get.

Punishment puts a price on speaking up. The research behind consequences studied people choosing to break rules. Nobody chooses to be fooled. People admit mistakes when it feels safe to, and most reporters report because they want to protect their coworkers, not for a reward. So split the two problems. Someone who knowingly skips a security step has a compliance problem. Someone who got fooled is part of your warning system. Punish them and they learn to stay quiet.

What should you measure instead?

  • Share of simulations where a report came before the first click
  • Time from delivery to first report
  • Reporting rate, grouped by how hard the email was
  • Number of people who report their own click
  • How fast reporters hear back

Click rate and training completion still belong on the report. They just aren't the headline. If you run programs for clients, our 15-minute QBR template shows how to present these numbers. Want to see where your own program stands? The free PsySec Program Audit checks your reporting setup in about ten minutes.

Read the full paper

The working paper, The Reporting Race: Why Phishing Defense Depends on Who Speaks Up First, has the math, the sources, the objections I hear most, and a list of results that would prove me wrong. I'd rather be tested than agreed with.

Frequently asked questions

What is a good phishing reporting rate?

There isn't one universal benchmark, because reporting rate depends on how hard the simulated email is. Track it by difficulty level and watch the trend. The number that matters most is how often a report arrives before the first click.

Should click rate still be tracked?

Yes, as a diagnostic. Show it next to the difficulty of each simulation. On its own, a click rate mostly tells you how hard the email was.

Does security awareness training work?

Recent large studies found standard training formats barely changed click rates. That doesn't mean people can't improve. It means programs should aim at reporting speed, frequent varied reminders, and feedback for everyone, instead of a lower click rate.

Should employees who click be punished?

Being fooled isn't breaking a rule. Punishing it teaches people to hide their click, which delays the earliest warning you can get. Save consequences for people who knowingly skip a security step.

Ready to Strengthen Your Security Culture?

See how Hook Security can help protect your organization.