Employees are simultaneously a business’s biggest security vulnerability and, with the right training, one of its strongest defenses. The data on which one they end up being comes down almost entirely to whether training is a sustained program or a once-a-year checkbox.
The Baseline Nobody Wants to Hear
Industry benchmarking of over 67 million phishing simulations found a global baseline click rate of roughly 33% before any training — about one in three employees, on average, will click a simulated phishing link with no prior awareness training in place. That’s the exposure most businesses are carrying today without realizing it.
What Actually Moves the Number
The same benchmarking shows the effect compounds with sustained training. After just 90 days of ongoing training and simulation, click rates dropped by roughly 40%. After a full 12 months of continued training, organizations achieved an 86% reduction, bringing the average click rate down to around 4%. This is a program effect, not a one-time event effect — the improvement comes from sustained, repeated exposure, not a single training session that gets forgotten within weeks.
Why the Annual Video Doesn’t Work
An annual compliance video creates a brief awareness spike that decays quickly. Ongoing simulated phishing with regular, varied scenarios keeps the skill sharp because employees are tested against realistic attempts continuously, not quizzed on a video once a year. The dramatic reduction in click rates in the data above only shows up in programs measured over 12 months of continuous engagement — not annual events.
Beyond Click Rate: The Reporting Rate Matters More
A mature program tracks more than whether someone clicked — it tracks the reporting rate, how many employees proactively flag a suspicious email to IT or security rather than just quietly not clicking it. Strong programs achieve a 60% or higher reporting rate, and that matters because an employee who reports a real phishing attempt gives the business a chance to block it company-wide before anyone else falls for it.
It’s Not Just Email Anymore
Phone and text-based phishing (vishing and smishing) are measurably more effective than email on average. Benchmarking data found phone-based phishing simulations had a median click/response rate around 2%, compared to about 1.4% for email — roughly 40% higher for voice and text-based lures. A training program focused only on email misses a real and growing attack surface, particularly as attackers increasingly use AI-generated voice cloning for phone-based social engineering.
Who Needs the Most Targeted Training
Employees handling financial transactions, client communications, or sensitive data — finance, legal, real estate, and healthcare roles specifically — are frequently targeted with more sophisticated, context-specific attacks, like the wire fraud patterns covered in our real estate and legal guides, rather than generic mass phishing. Training for these roles should include scenarios specific to their actual workflow, not just generic phishing examples that don’t resemble what they’ll actually see.
How to Roll This Out Without Overwhelming Anyone
Start with a baseline simulation to measure where the business actually stands before training begins, then introduce regular — commonly monthly — simulated phishing tests alongside short, frequent training content rather than long infrequent sessions. Employees who click a simulation should get brief, immediate, non-punitive feedback explaining what they missed. The goal is behavior change, not shaming anyone into disengagement.
How CelereTech Helps
CelereTech runs an ongoing simulated phishing and training program for Chicagoland businesses — starting with a baseline assessment, then regular simulations tailored to your actual industry and role-specific risks, paired with brief training content and reporting-rate tracking. The goal is the sustained, 12-month-style improvement the data shows, not a single annual event that satisfies a checkbox but doesn’t change behavior.
Get a baseline phishing assessment to see where your team actually stands.