Work out phishing click rate instantly with clear inputs, formula shown and shareable results.
Click rate alone is a poor programme metric because it can be driven down by making simulations obvious. The pair that matters is credential submission rate, which measures actual compromise, and report rate, which measures whether the workforce is generating the early-warning signal your security team depends on. A rising report-to-click ratio is the clearest sign a programme is working.
Phishing simulation metrics
click rate = clicks / sent; submission rate = credential submissions / sent; report rate = reports / sent; ratio = reports / clicks
Industry baselines commonly start near 25 to 30 percent for untrained populations and fall into single digits with sustained training, though results depend heavily on how convincing the lure is.
Detection speed depends on it. A workforce that reports a campaign within minutes lets you block the sender and reset credentials before an attacker gets far, regardless of how many clicked.