Send a fake email to 100 of your staff today and 30 will click it.
That is not a guess. Somebody actually ran the test. They sent 42 million fake phishing emails to 14 million people across 64,000 organisations, then watched who clicked. This is what happened, what it means, and why the most interesting number in the whole report is one that almost nobody is talking about.
First, what actually happened here
A security training company ran the same experiment on a huge scale. They picked an organisation, wrote a convincing fake email, and sent it to everyone who works there. Nothing bad was hidden inside. The only thing the email did was quietly record who clicked the link.
Then they taught those same staff how to spot a dodgy message, waited, and sent another fake email. Then they kept teaching, waited a full year, and sent a third. Three tests, same people, spread over a year.
It is a fire drill, except instead of finding out how fast everyone leaves the building, you find out how many people would open the door to a stranger.
The words they use, translated
Security reports are full of terms that sound technical and mean something very simple. Tap each one.
Meet the 100 person office
Forget percentages for a second. Picture a room with 100 people in it. Every square below is one of them. A fake email lands in all 100 inboxes at once. The red squares are the people who clicked.
Step through the three moments in time and watch the room change.
That is the headline finding. Across every organisation tested in the UK and Ireland, roughly 30 people in every 100 clicked at the start. After a year of regular practice, that dropped to around 5. It is a reduction of just under 82%, and it was achieved without buying a single new piece of technology.
Now here is the number nobody is talking about
The report splits results by how many staff an organisation has. Most people skim past this table. They should not, because it contains something genuinely awkward.
Look at what happens in the first 90 days. Press each phase.
staff
staff
9,999 staff
staff
At day one, the biggest organisations look worst. A third of their people click. That makes sense: more staff means more inboxes to aim at, and a name everyone recognises makes a convincing target.
Then look at the 90 day column. The 10,000 person companies drop from 33.1% all the way to 14%. They more than halve their risk in three months. The organisations under 250 staff go from 24.8% to 22.9%. That is a change of under two percentage points. In a room of 100 people, they went from 25 clickers to 23.
Businesses without a dedicated security team get almost no visible payoff in the first three months. Which means the 90 day mark is exactly the point where most of them look at the results, decide it is not working, and stop.
Why the slow start? The report does not say, but the pattern is not mysterious to anyone who has run this work. The large organisations have someone whose actual job is to chase the people who did not complete their training. They have automatic reminders, a named owner, and a manager who notices. Everywhere else, the training goes out, a few people do it, the rest get busy, and nothing follows up.
It is the difference between a gym membership and a personal trainer who texts you when you miss a session. Same equipment. Very different outcome.
And then, a year later, everybody arrives in the same place
This is the part that should change how you think about it. Tap the third phase in the chart above and watch the bars collapse together. Every size band, from a 40 person firm to a 40,000 person bank, lands between 4.5% and 6.1%.
The gap does not narrow. It essentially disappears.
A business with no security team and no budget line for this ends up with the same click rate as an organisation with an entire department. What separated them was never headcount or money. It was whether anyone kept going after the first three months.
Some industries start in a much deeper hole
The report also breaks results down by sector. The spread is wide. Tap any row to see what it means.
Red bar: how many clicked before training. Green bar: how many still clicked after a year.
Two sectors stand out for the wrong reason. Healthcare and pharmaceuticals finishes the year at 8.7%, and financial services at 7.5%. Both improved a lot, but both remain well above everyone else. These are the sectors holding the most valuable data, so they get the most attention from attackers and the most carefully written fakes. They need the practice to keep running permanently, not to be switched off once the numbers look respectable.
The attack that proves the point
In April and May 2025, Marks and Spencer, Co-op and Harrods were hit one after another. The disruption at M&S alone was put at around £300 million.
Nobody broke through a firewall. Nobody cracked a password. The attackers phoned the IT help desk, said they were a member of staff who was locked out, and asked for a password reset. The help desk, trying to be helpful, reset it.
Press play and watch how short the conversation is.
No malware. No clever code. Just a confident voice and a helpful person on the other end. Afterwards, the National Cyber Security Centre told organisations to rethink how their help desks confirm that a caller is who they claim to be.
Here is the useful part: fixing that costs nothing. You write down a rule about how a caller proves their identity before anyone resets a password, and you make sure every person who answers the phone knows the rule and is allowed to say no. That is it. It is one of the highest value things you can do this month, and it has no invoice attached.
What this means for your business
Percentages are easy to read past. So here is the same data as people.
Move the slider to your team size. These are the numbers for a business like yours on the UK and Ireland averages.
Now the thing worth sitting with. It only takes one. One person clicking one link is how nearly every serious incident starts. So the real question is not how many people click. It is how far a single click travels once it happens, and whether anyone notices.
Three things that follow from this data
One. Your first 90 days will look disappointing, and that is normal. If you start awareness training and the second round of results barely moves, you have not failed. You are exactly where the benchmark says a business your size should be. Judge it at month twelve, not month three. Put a date in the calendar now for that review so the decision does not get made in a moment of frustration.
Two. Somebody has to own the follow up. Not the training itself, the chasing. The thing that separated fast improvers from slow ones is that somebody noticed who had not done it and went and asked them. If nobody in your business owns that, the training will not work no matter who supplies it. Pick a name before you pick a provider.
Three. Reporting matters more than not clicking. Someone will click eventually. What decides whether that becomes an incident is how quickly they tell you. If your staff are worried they will be blamed, they will stay quiet, and you lose the hours that matter most. Make reporting a single obvious button, thank people publicly for using it, and never make an example of anyone.
How exposed are you right now?
Tick everything that is already true in your business. The ring fills as you go.
- ✓Staff have practised on a fake phishing email in the last 3 months
- ✓There is one obvious way to report a suspicious email, and people use it
- ✓A named person owns chasing anyone who has not done the training
- ✓Anyone resetting a password has to prove who they are first, by a written rule
- ✓Two-factor login is on for email, finance and admin accounts
- ✓Nobody gets in trouble for reporting something that turns out to be fine
- ✓A payment or bank detail change always gets verified by a second channel
- ✓Someone would notice if a stolen login was used out of hours
A fair word about where this data comes from
This report is published by KnowBe4, who sell security awareness training. The data comes from their own customers, and it shows that their own product works. That is worth saying out loud.
Two things to hold in mind. First, the score measures clicks on a practice email, not real breaches, so it is a proxy rather than a direct count of harm. Second, the organisations in the sample had already decided to invest in training, which makes them more motivated than average.
None of that makes the numbers useless. The sample is enormous, the method is consistent across all three rounds, and the size pattern, where large organisations improve fast and everyone converges by year one, is not a shape a vendor would choose to publish about itself. Read it as a strong directional signal from a source with an interest in the conclusion, which is how most industry data should be read anyway.
The businesses that win this are the ones who keep going.
GHOSTLINE runs the part that gets dropped. INBOX screens the messages before anyone has to make a judgement call. VEIL sets quiet tripwires so a stolen login gives itself away. SIGNAL watches for your credentials appearing where they should not. WATCH gives you a monthly picture in language you can hand to your board or your insurer, so the improvement is visible long before month twelve.
Figures from the KnowBe4 Phishing by Industry Benchmarking Report, United Kingdom and Ireland 2026, and the UK Government Cyber Security Breaches Survey 2025/2026.