KnowBe4 2026 Benchmark: One in Three Employees Click

Rachel Andersen··6 min read
Security manager reviewing phishing benchmark statistics on a dashboard

One in three untrained employees will engage with a malicious email. That is the headline finding of the KnowBe4 2026 Phishing by Industry Benchmarking Report, published on 7 July 2026, which puts the global baseline Phish-prone Percentage at 33.2 percent. The same dataset also delivers the good news: after twelve months of continuous security awareness training and simulated phishing, average susceptibility falls to just 4.2 percent.

For IT and security leaders, the report is less a warning than a measuring stick. It answers the two questions every board eventually asks: how bad is our human risk before we act, and how much does training actually move the needle?

The Largest Benchmark of Its Kind

The 2026 edition draws on 42 million phishing simulations sent to 14.8 million users across 64,000 organizations worldwide. The core metric, the Phish-prone Percentage (PPP), measures the share of users who interact with a simulated phishing email - by clicking a link, opening an attachment, or entering credentials on a landing page.

Across that entire population, the untrained baseline lands at 33.2 percent. In plain terms: send a convincing phishing email into a company that has never run a structured awareness program, and roughly one in three recipients will do something an attacker can exploit. The full breakdown by industry, region, and company size is in the KnowBe4 benchmarking report.

A one-in-three failure rate would be considered a catastrophic defect in any technical control. A firewall that let a third of attacks through would be replaced immediately. Yet many organizations still treat the human layer as an afterthought, tested once a year at best.

Which Industries and Company Sizes Start Most Exposed

The baseline is not evenly distributed. Three sectors stand out at the top of the risk table before any training takes place:

  • Healthcare and Pharmaceuticals: 42.7 percent baseline PPP
  • Insurance: 38.1 percent
  • Retail and Wholesale: 36 percent

Company size matters too. Large enterprises with 10,000 or more employees start at 39.5 percent, well above the global average, and large healthcare organizations peak at a startling 54 percent - meaning more than half of untrained staff in those environments engage with simulated attacks. The pattern is intuitive: scale creates exposure. More departments, more internal processes, and more legitimate-looking system email give attackers a richer set of templates to imitate, while individual employees have less chance of personally knowing the supposed sender.

Regional differences follow a similar logic. Africa records the highest untrained baseline at 35.9 percent, while North America demonstrates what a mature awareness market can achieve, reaching 4.0 percent PPP after a year of sustained training.

Training Moves the Needle - Dramatically

The most consequential number in the report is not the baseline but the trajectory. After twelve months of continuous training combined with regular simulated phishing, the average PPP falls from 33.2 percent to 4.2 percent. KnowBe4's accompanying press release headlines the result as a 79 percent global drop in phishing susceptibility after one year.

Two aspects of that finding deserve emphasis. First, the improvement is not produced by a single annual training video. The organizations that reach single-digit click rates run continuous programs: regular simulations, immediate feedback at the moment of a mistake, and short recurring lessons rather than one long compliance session. Second, the result is measured across tens of millions of real users in production environments, not in vendor lab conditions - which makes it one of the more defensible figures a security leader can put in front of a budget committee.

No firewall upgrade or email gateway replacement reliably removes four out of five successful compromise opportunities. Sustained awareness training does exactly that for the human attack surface.

What This Means for European Organizations

The report is global, but its message lands with particular weight in the EU and especially in Germany. Under NIS2, essential and important entities are required to implement basic cyber hygiene practices and security training, and management bodies are expected to oversee and approve those measures. GDPR adds a second lever: a phishing-initiated breach of personal data is a reportable incident, with all the notification duties and reputational cost that follow.

The benchmark gives European security leaders a defensible reference point for both conversations. If your untrained click rate is somewhere near a third, you are normal - not negligent. Staying there, however, is a choice, and it is becoming a hard one to justify to regulators, auditors, and cyber insurers alike. Organizations in regulated sectors should pay special attention to the healthcare figures: a 42.7 percent baseline in the industry that handles the most sensitive personal data is exactly the kind of gap supervisory authorities ask about after an incident.

How to Benchmark Your Own Organization

Industry averages are useful context, but the number that matters is your own. A credible internal benchmark takes four steps:

  1. Run an unannounced baseline simulation. Test a representative cross-section of the workforce with a realistic template before announcing any new training initiative. An announced test measures compliance, not risk.
  2. Segment the results. Break the click rate down by department, role, and location. A 30 percent average often hides a 50 percent hotspot in one team - typically the one with the most external email contact.
  3. Train continuously, not annually. Follow the baseline with short, regular training and monthly or quarterly simulations that vary in difficulty and theme.
  4. Re-measure and report the trend. Track the same metric quarterly and report the trajectory to leadership. A falling curve is the clearest evidence of program value a CISO can present.

Platforms like empowsec automate this loop end to end: phishing simulations establish the baseline, per-user risk scoring highlights who needs extra attention, and targeted training closes the gaps - so the benchmark becomes a management instrument rather than a one-off report.

Key Takeaways

  • The global untrained baseline is 33.2 percent - one in three employees engages with a malicious email, based on 42 million simulations across 64,000 organizations.
  • Healthcare (42.7 percent), insurance (38.1 percent), and retail (36 percent) start most exposed; large enterprises begin at 39.5 percent and large healthcare organizations peak at 54 percent.
  • Twelve months of continuous training and simulation cuts the average to 4.2 percent - reported as a 79 percent global drop in susceptibility.
  • For EU organizations, NIS2 training obligations and GDPR breach duties turn the benchmark into a compliance argument, not just a security one.
  • Benchmark yourself: run an unannounced baseline simulation, segment by department, train continuously, and report the quarterly trend to leadership.
Share: