Your Click Rate Is Lying to You
A year-long study by security awareness platform Pistachio sent 2.47 million simulated phishing emails to 123,000 employees across 1,200 organisations, and found that click rate — the metric most phishing training programmes are judged on — tells only part of the story, according to SecurityWeek.
What actually matters is what happens after the click: 30% of tech and IT workers clicked at least once, and nearly 20% of construction employees handed over credentials after clicking. A click with no credential submission creates no real breach.
What you should do: If your organisation runs phishing simulations, push for reporting that tracks credential submission and suspicious-email reporting rates alongside clicks. If you're an individual, the habit worth building is simple: before entering a password anywhere, check the URL bar first.
Sources

