Skip to content
Calcrivo

Phishing Risk Calculator

Model phishing exposure from campaign volume, click and report rates, credential entry, MFA strength and expected compromises.

Inputs

users
emails/year

After filtering — measure, do not guess

%

Industry simulations average 5–15%

%
%
minutes
currency

Expected Account Compromises per Year

17.2accounts/year

Clicks per Year

1,200clicks/year

Credential Submissions per Year

420.0per year

Expected Annual Loss

$601,781

Report-to-Click Ratio

2.50×

Loss Avoided by Current MFA

$11,433,844

Priority Action

Well controlled — keep measuring with realistic simulations rather than easy ones

Step by step

  1. Values used

    Users targeted = 2,500 users; Phishing emails reaching the inbox per user per year = 6 emails/year; Click rate = 8 %; Of those who click, share entering credentials = 35 %; Report rate = 20 %; MFA on the phished application = Number matching with context — 0.05; Time to contain a reported phish = 45 minutes; Cost of one account compromise = 35,000 currency

  2. Phishing Risk

    expectedCompromises = users × emails × clickRate × credentialEntryRate × mfaBypassFactor × containmentFactor.

  3. Expected Account Compromises per Year

    = 17.2 accounts/year

  4. Clicks per Year

    = 1,200 clicks/year

  5. Credential Submissions per Year

    = 420.0 per year

  6. Expected Annual Loss

    = 601,781

  7. Report-to-Click Ratio

    = 2.50 ×

  8. Loss Avoided by Current MFA

    = 11,433,844

How it works

Compromise is a funnel: delivered mail, clicks, credential submissions, then whether the second factor survives the attack. The MFA factor is the dominant term — push-based MFA is fatigued and OTPs are relayed by any modern phishing kit, while FIDO2 is bound to the origin and simply does not phish. Containment reflects that a fast report lets you retract the mail and reset the account before the session is used. The report-to-click ratio is the awareness metric that predicts outcomes: an organisation where more people report than click detects campaigns in minutes, and one where clicks dominate finds out from the SOC.

Formula

Phishing Risk

expectedCompromises = users × emails × clickRate × credentialEntryRate × mfaBypassFactor × containmentFactor.

clickRate
Share of delivered phishing emails clicked
credentialEntryRate
Share of clickers who submit credentials
mfaBypassFactor
Probability the MFA in place fails to stop the attack — 1.0 for none, 0.01 for FIDO2
containmentFactor
Reduction from users reporting quickly enough to retract and reset

Frequently Asked Questions

How is Phishing Risk calculated?

expectedCompromises = users × emails × clickRate × credentialEntryRate × mfaBypassFactor × containmentFactor. Compromise is a funnel: delivered mail, clicks, credential submissions, then whether the second factor survives the attack. The MFA factor is the dominant term — push-based MFA is fatigued and OTPs are relayed by any modern phishing kit, while FIDO2 is bound to the origin and simply does not phish. Containment reflects that a fast report lets you retract the mail and reset the account before the session is used.

Why does Phishing Risk matter?

The report-to-click ratio is the awareness metric that predicts outcomes: an organisation where more people report than click detects campaigns in minutes, and one where clicks dominate finds out from the SOC.

What values do I need to enter?

This calculator takes 8 inputs: Users targeted, Phishing emails reaching the inbox per user per year, Click rate, Of those who click, share entering credentials, Report rate, MFA on the phished application, Time to contain a reported phish, Cost of one account compromise. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.

Why does phishing-resistant MFA score 0.01 rather than 0?

Because attackers still succeed through consent phishing, device-code flows, session-token theft from an already-compromised endpoint and help-desk social engineering to enrol a new key. FIDO2 removes credential relay, not every path to the account.

Are simulation click rates comparable to real ones?

Only loosely. Simulations are typically easier to spot than a targeted attack and harder than bulk spam, so treat the figure as a trend line for your own population rather than an absolute probability.

You might also need