Source: KnowBe4 Phishing by Industry Benchmark, UK and Ireland 2026

Send a fake email to 100 of your staff today and 30 will click it.

DataInteractivePhishingSep 202611 min read

That is not a guess. Somebody actually ran the test. They sent 42 million fake phishing emails to 14 million people across 64,000 organisations, then watched who clicked. This is what happened, what it means, and why the most interesting number in the whole report is one that almost nobody is talking about.

30.3%
Clicked before training
19.8%
Clicked after 90 days
5.5%
Clicked after a year
93%
Of UK cyber crime is phishing

First, what actually happened here

A security training company ran the same experiment on a huge scale. They picked an organisation, wrote a convincing fake email, and sent it to everyone who works there. Nothing bad was hidden inside. The only thing the email did was quietly record who clicked the link.

Then they taught those same staff how to spot a dodgy message, waited, and sent another fake email. Then they kept teaching, waited a full year, and sent a third. Three tests, same people, spread over a year.

It is a fire drill, except instead of finding out how fast everyone leaves the building, you find out how many people would open the door to a stranger.

The words they use, translated

Security reports are full of terms that sound technical and mean something very simple. Tap each one.

Phish-prone Percentage
How many people out of every 100 clicked the fake email. If your score is 30%, then 30 of your 100 staff fell for it. Lower is better. That is the entire idea.
tap to translate
Phishing
A fake message pretending to be someone you trust, designed to get you to click a link, open a file, or type in your password. Like a stranger in a stolen uniform knocking on the door and asking to be let in.
tap to translate
Baseline
Your score before anybody has been taught anything. The honest starting photo, taken before you tidy up.
tap to translate
Simulation
A practice attack. It looks real to the person receiving it but is completely harmless. A fire drill for the inbox.
tap to translate
Social engineering
Tricking a person instead of hacking a computer. The attacker does not break the lock, they talk someone into opening it.
tap to translate
Security awareness training
Short, regular practice at spotting fakes. Not a lecture. More like learning to recognise a counterfeit note by handling a lot of them.
tap to translate
Credential
A username and password. Attackers want these because a stolen login lets them walk in through the front door, and nothing sets off an alarm.
tap to translate
Help desk pretexting
Phoning your IT support, pretending to be a member of staff who is locked out, and asking for a password reset. It is the oldest trick there is, and it is still working.
tap to translate

Meet the 100 person office

Forget percentages for a second. Picture a room with 100 people in it. Every square below is one of them. A fake email lands in all 100 inboxes at once. The red squares are the people who clicked.

Step through the three moments in time and watch the room change.

ghostline://who-clicked
30
out of 100 clicked
before any training
This is a normal, well-run business on an ordinary Tuesday. Nobody here is careless. The email simply looked like something they were expecting.
clicked the fake email ignored, deleted or reported it

That is the headline finding. Across every organisation tested in the UK and Ireland, roughly 30 people in every 100 clicked at the start. After a year of regular practice, that dropped to around 5. It is a reduction of just under 82%, and it was achieved without buying a single new piece of technology.

Now here is the number nobody is talking about

The report splits results by how many staff an organisation has. Most people skim past this table. They should not, because it contains something genuinely awkward.

Look at what happens in the first 90 days. Press each phase.

ghostline://by-headcount
Day one After 90 days After a year
Up to 249
staff
0%
250 to 999
staff
0%
1,000 to
9,999 staff
0%
10,000+
staff
0%

At day one, the biggest organisations look worst. A third of their people click. That makes sense: more staff means more inboxes to aim at, and a name everyone recognises makes a convincing target.

Then look at the 90 day column. The 10,000 person companies drop from 33.1% all the way to 14%. They more than halve their risk in three months. The organisations under 250 staff go from 24.8% to 22.9%. That is a change of under two percentage points. In a room of 100 people, they went from 25 clickers to 23.

// The uncomfortable bit

Businesses without a dedicated security team get almost no visible payoff in the first three months. Which means the 90 day mark is exactly the point where most of them look at the results, decide it is not working, and stop.

Why the slow start? The report does not say, but the pattern is not mysterious to anyone who has run this work. The large organisations have someone whose actual job is to chase the people who did not complete their training. They have automatic reminders, a named owner, and a manager who notices. Everywhere else, the training goes out, a few people do it, the rest get busy, and nothing follows up.

It is the difference between a gym membership and a personal trainer who texts you when you miss a session. Same equipment. Very different outcome.

And then, a year later, everybody arrives in the same place

This is the part that should change how you think about it. Tap the third phase in the chart above and watch the bars collapse together. Every size band, from a 40 person firm to a 40,000 person bank, lands between 4.5% and 6.1%.

The gap does not narrow. It essentially disappears.

A business with no security team and no budget line for this ends up with the same click rate as an organisation with an entire department. What separated them was never headcount or money. It was whether anyone kept going after the first three months.

What does not decide it
Your size, your budget, how clever your staff are, or which product you bought.
What does decide it
Whether the practice is still happening in month nine, when the novelty has worn off entirely.
Where it goes wrong
Month three. Early results look flat, the effort feels wasted, and it quietly gets dropped.

Some industries start in a much deeper hole

The report also breaks results down by sector. The spread is wide. Tap any row to see what it means.

SectorDay 1Year 1

Red bar: how many clicked before training. Green bar: how many still clicked after a year.

Two sectors stand out for the wrong reason. Healthcare and pharmaceuticals finishes the year at 8.7%, and financial services at 7.5%. Both improved a lot, but both remain well above everyone else. These are the sectors holding the most valuable data, so they get the most attention from attackers and the most carefully written fakes. They need the practice to keep running permanently, not to be switched off once the numbers look respectable.

The attack that proves the point

In April and May 2025, Marks and Spencer, Co-op and Harrods were hit one after another. The disruption at M&S alone was put at around £300 million.

Nobody broke through a firewall. Nobody cracked a password. The attackers phoned the IT help desk, said they were a member of staff who was locked out, and asked for a password reset. The help desk, trying to be helpful, reset it.

Press play and watch how short the conversation is.

ghostline://help-desk-replay

No malware. No clever code. Just a confident voice and a helpful person on the other end. Afterwards, the National Cyber Security Centre told organisations to rethink how their help desks confirm that a caller is who they claim to be.

Here is the useful part: fixing that costs nothing. You write down a rule about how a caller proves their identity before anyone resets a password, and you make sure every person who answers the phone knows the rule and is allowed to say no. That is it. It is one of the highest value things you can do this month, and it has no invoice attached.

What this means for your business

Percentages are easy to read past. So here is the same data as people.

Move the slider to your team size. These are the numbers for a business like yours on the UK and Ireland averages.

ghostline://your-numbers
People who use email at work 25
3250
8
Would click today, with no practice
5
Would still click after 90 days
1
Would still click after a year

Now the thing worth sitting with. It only takes one. One person clicking one link is how nearly every serious incident starts. So the real question is not how many people click. It is how far a single click travels once it happens, and whether anyone notices.

Three things that follow from this data

One. Your first 90 days will look disappointing, and that is normal. If you start awareness training and the second round of results barely moves, you have not failed. You are exactly where the benchmark says a business your size should be. Judge it at month twelve, not month three. Put a date in the calendar now for that review so the decision does not get made in a moment of frustration.

Two. Somebody has to own the follow up. Not the training itself, the chasing. The thing that separated fast improvers from slow ones is that somebody noticed who had not done it and went and asked them. If nobody in your business owns that, the training will not work no matter who supplies it. Pick a name before you pick a provider.

Three. Reporting matters more than not clicking. Someone will click eventually. What decides whether that becomes an incident is how quickly they tell you. If your staff are worried they will be blamed, they will stay quiet, and you lose the hours that matter most. Make reporting a single obvious button, thank people publicly for using it, and never make an example of anyone.

How exposed are you right now?

Tick everything that is already true in your business. The ring fills as you go.

0%
in place
Tick what you already have

A fair word about where this data comes from

This report is published by KnowBe4, who sell security awareness training. The data comes from their own customers, and it shows that their own product works. That is worth saying out loud.

Two things to hold in mind. First, the score measures clicks on a practice email, not real breaches, so it is a proxy rather than a direct count of harm. Second, the organisations in the sample had already decided to invest in training, which makes them more motivated than average.

None of that makes the numbers useless. The sample is enormous, the method is consistent across all three rounds, and the size pattern, where large organisations improve fast and everyone converges by year one, is not a shape a vendor would choose to publish about itself. Read it as a strong directional signal from a source with an interest in the conclusion, which is how most industry data should be read anyway.

The businesses that win this are the ones who keep going.

GHOSTLINE runs the part that gets dropped. INBOX screens the messages before anyone has to make a judgement call. VEIL sets quiet tripwires so a stolen login gives itself away. SIGNAL watches for your credentials appearing where they should not. WATCH gives you a monthly picture in language you can hand to your board or your insurer, so the improvement is visible long before month twelve.

Start a conversationTry the free phishing analyser

Figures from the KnowBe4 Phishing by Industry Benchmarking Report, United Kingdom and Ireland 2026, and the UK Government Cyber Security Breaches Survey 2025/2026.