KnowBe4’s latest phishing benchmark shows that sustained security awareness training can dramatically reduce employee susceptibility, even as AI-powered phishing grows more sophisticated.
The vendor said organisations that maintained continuous training for one year cut phishing risk by 79%, bringing the average Phish-prone Percentage down from 33.2% to 4.2%.
The findings come from the 2026 Phishing by Industry Benchmarking Report, which analysed 42 million phishing simulations across 14.8 million users at 64,000 organisations worldwide.
KnowBe4 said the research reinforces a simple message for CISOs: one-off compliance exercises are not enough, and ongoing behavioural training remains one of the most effective controls against phishing.
The report also found that risk drops quickly in the early months of training, with susceptibility falling 40% within 90 days. However, KnowBe4 said the biggest improvement comes over time, as consistent reinforcement drives lasting behaviour change rather than temporary caution.
Threat levels remain uneven across sectors and geographies. Before any training, large enterprises with more than 10,000 employees had a baseline PPP of 39.5%, compared with 24.7% for small businesses. Healthcare and pharmaceuticals remained the most vulnerable industry at 42.7%, followed by insurance at 38.1% and retail and wholesale at 36%.
Javvad Malik, lead CISO advisor at KnowBe4, said the expanding use of autonomous AI agents is enlarging the attack surface in ways traditional controls were not built to handle.
He said the 17% spike in phishing attacks since late 2025 shows how adversaries are exploiting the complexity, but added that continuous personalised training can reduce employee susceptibility to 4.2% over 12 months.
The report also points to regional differences. Africa had the highest baseline risk at 35.9%, followed by North America at 34.5% and South America at 31.5%, while Asia entered with the lowest baseline at 24.9%.
The broader industry trend is that phishing defence is moving beyond static awareness modules towards sustained, role-based and AI-aware programmes.
As cybercriminals use more personalised lures, deepfake-enabled social engineering and business email compromise, organisations are being pushed to treat human risk as a continuously managed exposure, not a yearly training exercise.











