Phishing Click Rate Benchmarks 2026: KnowBe4 Data by Industry

Phishing Click Rate Benchmarks 2026: KnowBe4 Data by Industry

One in three. That is how many untrained employees click a simulated phish, according to KnowBe4’s 2026 Phishing by Industry Benchmarking Report — a 33.2% global baseline Phish-prone Percentage drawn from 42 million simulations across 14.8 million users at roughly 64,000 organizations. If your board asks whether the security awareness line item is working, this is the dataset you benchmark against. This brief gives you the 2026 numbers by industry and organization size, the thresholds that separate a healthy program from a stalled one, and the honest caveats about what simulation click rates do and do not tell you.

The 2026 benchmarks

The headline numbers first. KnowBe4 measures Phish-prone Percentage (PPP) — the share of users who click a link, open an attachment, or otherwise fail a simulated phishing test. The 2026 report covers 19 industries, four organization sizes and seven global regions.

Phish-prone Percentage (2026)
Global baseline, untrained (all industries)33.2%
Healthcare & Pharmaceuticals, untrained42.7%
Insurance, untrained38.1%
Retail & Wholesale, untrained36.0%
Large enterprise (10,000+ employees), untrained39.5%
After 12 months of sustained training (all industries)~4.2%

Two things stand out. First, size hurts: large enterprises of 10,000-plus employees start at 39.5%, meaningfully worse than the global average, because scale brings more turnover, more contractors and more inboxes nobody owns. Second, the trained number is the story. Organizations that run continuous simulated phishing and training for a full year land around 4.2% — a reduction of roughly 87% from baseline. That delta is the strongest ROI evidence anywhere in the security awareness category.

How to read your own click rate

Benchmarks only matter if they change a decision. Here is how I read a phishing click rate benchmark by industry when a team brings me their numbers:

  • Above 30% on your first baseline test: normal. Do not panic and do not punish anyone — you are simply average, and the fix is a program, not a memo.
  • Still above 15% after six months of training: your program is broken. Either the cadence is too slow (quarterly is not a cadence), the templates are too easy to game, or training is a once-a-year compliance video.
  • Between 5% and 10% after a year: respectable but unfinished. The residual clickers are usually concentrated — new hires, specific departments, shared mailboxes. Segment the data before spending more.
  • Under 5% sustained: mature. Shift budget from volume of simulations to depth — harder spear-phish templates, callback phishing, QR codes and MFA-fatigue scenarios.

The takeaway for the meeting: a good phishing click rate in 2026 is under 5%, and anything above 15% a year into a funded program is a program failure, not a people failure.

Why healthcare, insurance and retail keep losing

Healthcare & Pharmaceuticals tops the vulnerability table again at 42.7%, and in large healthcare organizations the untrained rate climbs even higher. The reasons are structural, not cultural. Clinical staff work under time pressure on shared workstations, email is a life-or-death coordination channel that people process fast, and turnover keeps the untrained population permanently refreshed. Insurance (38.1%) and Retail & Wholesale (36%) share a related profile: large distributed workforces, heavy seasonal hiring, and daily legitimate email that looks exactly like phishing bait — invoices, claims, shipping notices, password resets.

If you run security in one of these three industries, the benchmark is your budget argument. You are starting from a measurably worse position than the cross-industry average, and breach economics compound the problem — as our 2026 data breach cost benchmarks show, healthcare remains the most expensive industry in which to get breached. A higher click rate feeding a higher cost-per-breach is exactly the kind of multiplication a CFO understands.

What the training curve actually looks like

The 87% reduction is real, but it is not fast. KnowBe4’s longitudinal data shows the biggest gains arrive between month three and month twelve — not in the first 90 days. That has two practical implications. First, a pilot program judged at 90 days will look mediocre and may get cut exactly when it is about to start working. Set expectations with leadership for a 12-month evaluation window. Second, one-off annual campaigns do not bend the curve at all. The organizations hitting 4.2% run continuous simulations — typically at least monthly — with immediate, short remedial training at the moment of failure.

Worth noting: the year-over-year trend is favorable. The equivalent 2025 report showed an 86% reduction from training; 2026 shows roughly 87%. The methodology is consistent enough across years that the direction is credible, and it means the intervention keeps working even as attackers adopt AI-generated lures.

KnowBe4’s role — and where the data has limits

KnowBe4 owns this benchmark for a simple reason: nobody else has the sample size. With tens of thousands of customer organizations feeding the dataset, its annual report is the closest thing the industry has to a census of simulated phishing behavior. The company has also moved decisively beyond the awareness-training label — its HRM+ platform bundles simulated phishing and training with real-time coaching (SecurityCoach), cloud email security, and a growing suite of AI agents under the AIDA banner, eight of them as of early 2026. That repositioning mirrors the broader market shift we covered in the move from security awareness to human risk management: the product category is no longer annual training, it is continuous measurement and intervention on human risk.

Where KnowBe4 is strong: breadth of template and content library, mature automation for continuous campaigns, and benchmark data that makes board reporting easy — you can put your PPP next to your industry’s line and be done. Where it is weaker: per-seat pricing adds up at large-enterprise scale, the sheer content volume can overwhelm smaller teams without a program owner, and a simulation-centric metric invites gaming — run easy templates and your numbers look great while your real risk does not move.

And treat the dataset itself with analyst discipline. It is drawn from KnowBe4’s own customer base, which skews toward organizations that already bought awareness tooling. PPP measures clicks on simulations, not real-world compromise — a useful proxy, not a ground truth. And the 33.2% baseline is measured before training by definition, so the dramatic headline delta is partly a property of how the cohort is constructed. None of that invalidates the numbers. It does mean you should benchmark against the trend and your industry line, not treat 4.2% as a guarantee.

What to do about it

  • Baseline before budget season. Run an unannounced simulation across the full employee population and put your number next to the 33.2% global line and your industry’s line. That one slide anchors the whole funding conversation.
  • Commit to twelve months, not a pilot. The curve bends between months three and twelve. Fund a year of at least monthly simulations with in-the-moment remedial training, and report quarterly against the 87% reduction trajectory.
  • Segment the stragglers. Once you are under 10%, stop treating the workforce as one population. New hires, finance, executive assistants and shared mailboxes deserve targeted, harder scenarios.
  • Audit template difficulty annually. If your click rate dropped but your reported-phish rate did not rise, you are probably measuring easier templates, not better behavior.

Frequently asked questions

What is a good phishing click rate?

Under 5% on realistic simulations, sustained over multiple campaigns, is a mature result in 2026. Between 5% and 10% is acceptable for a program in its first year. Above 15% after a year of funded training signals a broken program cadence.

What is the average phishing simulation click rate in 2026?

KnowBe4’s 2026 benchmarking data puts the untrained global average at 33.2%, falling to roughly 4.2% after twelve months of continuous simulation and training. Healthcare (42.7%), insurance (38.1%) and retail (36%) start above the average.

What does Phish-prone Percentage mean?

Phish-prone Percentage (PPP) is KnowBe4’s metric for the share of users who fail a simulated phishing test — clicking a link, opening an attachment, or submitting data. It measures simulation behavior, which is a proxy for real-world susceptibility rather than a direct measure of compromise.

How much does security awareness training reduce phishing clicks?

Across KnowBe4’s 2026 dataset, organizations running sustained programs cut susceptibility by about 87% within a year — from a 33.2% baseline to around 4.2%. Most of the improvement lands between month three and month twelve, which is why one-off campaigns underperform.

Enterprise Techie publishes vendor-honest analysis like this daily — get the brief by email, free.