• About
  • Subscribe
  • Contact
Tuesday, May 20, 2025
    Login
FutureCISO
  • People
  • Process
  • Technology
  • Resources
    • White Papers
    • PodChats
No Result
View All Result
  • People
  • Process
  • Technology
  • Resources
    • White Papers
    • PodChats
No Result
View All Result
FutureCISO
No Result
View All Result
Home Technology Data Protection

Security training reduces global phishing click rates by 86%

FutureCISO Editors by FutureCISO Editors
May 20, 2025
Security training reduces global phishing click rates by 86%

Photo by Anton Belitskiy: https://www.pexels.com/photo/two-men-practicing-aikido-3629181/

Share on FacebookShare on Twitter

The KnowBe4 report “Phishing by Industry Benchmarking Report 2025.” - US market - reveals that comprehensive security awareness training (SAT) significantly reduces the likelihood of employees falling victim to phishing attacks. The report indicates a dramatic drop in the global Phish-prone Percentage (PPP) to just 4.1% after 12 months of effective training.

The study analysed 67.7 million phishing simulations across 14.5 million users from 62,400 organisations, establishing a baseline PPP of 33.1%. This figure indicates that one-third of employees interacted with phishing simulations prior to receiving training. The data highlights the profound impact of ongoing SAT on mitigating risks associated with phishing threats.

Following the implementation of training, the global PPP decreased by 40% within just three months, and by an impressive 86% after one year.

These results underscore the effectiveness of continuous education in fostering a stronger security culture within organisations, demonstrating that even short-term training can lead to significant behavioural changes.

Key findings

  1. At-Risk Industries: The report identified Healthcare & Pharmaceuticals as the most vulnerable sector, with a baseline PPP of 41.9%, followed closely by Insurance at 39.2% and Retail & Wholesale at 36.5%.
  2. Organisational Size and Risk: Larger organisations, particularly those with over 10,000 employees, exhibited a higher initial phishing risk, with a PPP of 40.5%. In contrast, smaller organisations with 1-250 employees had a significantly lower PPP of 24.6%.
  3. Improvement Rates: Among organisations with 1,000-9,999 employees, sectors like Healthcare & Pharmaceuticals, Hospitality, and Legal achieved remarkable PPP improvement rates of 91% following 12 months of ongoing training.
  4. Regional Variations: The highest baseline PPPs were recorded in South America (39.1%), North America (37.1%), and Australia and New Zealand (36.8%).
Stu Sjouwerman

“The data speaks for itself — security awareness training truly makes a difference,” said Stu Sjouwerman, CEO of KnowBe4. He noted a slight improvement in 2025, with the global baseline PPP decreasing by 3.5% compared to the previous year.

Related:  Time to revisit your cyber insurance strategy in 2025

This indicates a positive shift in security awareness worldwide, yet there remains significant progress to be made in fully addressing phishing risks.

By prioritising engaging and relevant training, combined with simulated phishing exercises, organisations can strengthen their human risk management strategies and enhance their overall security culture. The findings highlight the essential role of continuous education in combating the ever-evolving threat landscape of phishing attacks.

Tags: KnowBe4phishing attacks
FutureCISO Editors

FutureCISO Editors

No Result
View All Result

Recent Posts

  • Security training reduces global phishing click rates by 86%
  • Partnership to strengthen automotive security and support EU Chips Act sovereignty goals
  • Multimodal AI powers next gen threat detection
  • API security incidents cost APAC enterprises over US$580,000 on average in 2024
  • Security leaders go all in on AI Agents to address surging identity attacks

Categories

  • Blogs
  • Compliance and Governance
  • Culture and Behaviour
  • Cybersecurity careers
  • Data Protection
  • Endpoint Security
  • Incident Response
  • Network Security
  • People
  • Process
  • Resources
  • Risk Management
  • Technology
  • Training and awarenes
  • Videos
  • Webinars and PodChats
  • White Papers

Strategic Insights for Chief Information Officers

FutureCISO serves the interests of the Chief Information Security Officer (CISO) and the information security profession. Its purpose is to provide relevant and timely industry insights around all things important to security professionals and organisations that recognize and value the importance of protecting the organisation’s data and its customers’ privacy.

Cxociety Media Brands

  • FutureIoT
  • FutureCFO
  • FutureCIO

Categories

  • Privacy Policy
  • Terms of Use
  • Cookie Policy

Copyright © 2024 Cxociety Pte Ltd | Designed by Pixl

Login to your account below

or

Not a member yet? Register here

Forgotten Password?

Fill the forms bellow to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • People
  • Process
  • Technology
  • Resources
    • White Papers
    • PodChats
Login

Copyright © 2024 Cxociety Pte Ltd | Designed by Pixl