Click Rate Measures the Lure, Not the Organisation
When a phishing simulation report lands on the board table, the number everyone looks at first is click rate. It is the least useful number in the report. Click rate measures the quality of the lure and the timing of the send; it says very little about whether the organisation would survive a real campaign. The numbers that do are report rate, time to first report and credential submission rate, because a real phishing incident is decided by detection and response, not by the hope that nobody ever clicks.
The asymmetry is what makes this true. An attacker needs one recipient to act on the email. A defender needs one recipient to report it, and in a well-run environment the first report arrives while most people have not yet opened the message. If that report reaches someone who can purge the email from every other mailbox and block the sending domain, the campaign dies in minutes regardless of how many people would eventually have clicked. Click rate describes what would have happened with no response at all. Report rate describes the response.
The Perverse Incentives of a Click Rate KPI
Goodhart's law applies with full force: when a measure becomes a target, it stops being a good measure. If click rate is the KPI your program is judged on, whoever designs the campaigns is quietly incentivised to send lures soft enough to hit the target. Generic parcel-delivery phish with spelling errors produce a flattering quarterly trend line, and that trend line compares lures, not people. A genuinely good pretext (an MFA re-registration notice styled on your real Entra ID tenant, or a document-signing request from a supplier your finance team actually uses) will draw clicks from experienced staff, including security staff. That is not a training failure. It is what good pretexts are built to do.
Blame does worse damage. Organisations that name, shame or discipline clickers suppress the one behaviour they most need. A person who clicked and fears the consequences deletes the email and says nothing. In a simulation, that costs you a data point. In a real incident it costs you the early-warning window, and that window has regulatory weight in Australia: once you suspect an eligible data breach, the Notifiable Data Breaches scheme under the Privacy Act gives you up to 30 days to assess it, and if the assessment confirms the breach, notification to the OAIC and affected individuals must follow as soon as practicable. Every silent hour at the front of an incident makes that assessment slower and the outcome worse.
The Four Numbers That Belong on the Front Page
Four numbers deserve the front page of every simulation report. None of them is click rate.
- Report rate: the percentage of recipients who reported the message through the sanctioned channel, not just deleted it.
- Time to report: both time to first report, which drives containment, and the median, which describes the culture.
- Credential submission rate: tracked separately from clicks, because a click is reconnaissance and a submitted password is compromise.
- Reporter-to-clicker ratio: whether the people who fell for the lure also raised their hand afterwards.
Credential Submission Is the Compromise Line
Watch the direction of travel across campaigns rather than any single result. A maturing program shows report rate climbing, time to first report falling towards minutes, and credential submission falling even as pretext difficulty rises. Audit the reporting channel itself before trusting any of it: if reporting means forwarding the message to an unmonitored mailbox or raising a helpdesk ticket, friction is quietly suppressing your report rate. A one-click report button in the mail client moves behaviour more than another annual awareness module ever will.
On the credential line, be precise about what each event means. A click on a link tells the attacker the address is live and the recipient is curious. A password typed into the fake page is the compromise. Programs that conflate the two produce a single number that means neither thing. Then ask what the credential would actually have bought. Modern reverse-proxy phishing kits sit between the victim and the real sign-in page, relay the one-time code and capture the resulting session token, which means OTP-based multi-factor authentication does not end the conversation. This is exactly why the Essential Eight's multi-factor authentication strategy pushes phishing-resistant methods, such as FIDO2 passkeys, as maturity rises.
Where it is safe to do so, test the chain behind the human as well: whether conditional access flags a sign-in from unfamiliar infrastructure, and whether anyone is alerted when a new inbox rule appears or an OAuth consent grant lands, two of the most common post-compromise moves in Microsoft 365 estates. A simulation that ends at a training page the moment someone clicks is testing only the human layer. The failure modes that decide real incidents usually live in the layers behind it.
Measure the Response, Not Just the People
A phishing simulation is also a live-fire test of your security operation, and most programs never mark that half of the exam. Start the clock at the first report and measure the response: how long until a person triaged it, how long until the message was purged from every other mailbox, how long until the domain was blocked at the mail gateway. These are containment numbers, and containment is what separates a near miss from a notifiable breach. If the first report sat unactioned in a queue for half a day, that is the finding of the exercise, whatever the click rate says.
Run the same clock every campaign and fix the friction it exposes. Unmonitored abuse mailboxes. No runbook for a mass mailbox purge. Nobody with delegated authority to block a domain out of hours. Each of these is invisible in a click-rate report and decisive in an incident, and each is cheaper to fix than another round of awareness content.
Targeted Training Beats Blame
The results should drive training that is targeted, short and close to the event. Cohorts face different pretexts: finance teams see invoice fraud and bank-detail-change requests, HR sees resume attachments and complaint lures, executives and their assistants see payment-authority and MFA-fatigue plays. Train each group on the attacks aimed at them, within days of the campaign, in minutes rather than hours. Repeat clickers warrant a risk conversation and stronger controls around their accounts, phishing-resistant MFA first, not a warning letter. And reward reporting visibly, including from people who clicked first and reported second. Click-then-report is a success. It is the exact sequence you want on the day the email is real.
What good looks like is straightforward to state and rare to see. Campaigns run quarterly with escalating pretext difficulty. Report rate and median time to report as the headline metrics, credential submission tracked separately, response timings on the same page, click rate relegated to context. Run that way, a simulation stops being a compliance ritual and becomes a rehearsal, with the humans, the tooling and the responders all on stage at once. That is how Black Shard runs the phishing components of its offensive engagements, and it is the difference between a number that flatters and a program that protects.
