Phishing Risk Calculator
Model phishing exposure from campaign volume, click and report rates, credential entry, MFA strength and expected compromises.
Inputs
After filtering — measure, do not guess
Industry simulations average 5–15%
Expected Account Compromises per Year
17.2accounts/year
Clicks per Year
1,200clicks/year
Credential Submissions per Year
420.0per year
Expected Annual Loss
$601,781
Report-to-Click Ratio
2.50×
Loss Avoided by Current MFA
$11,433,844
Priority Action
Well controlled — keep measuring with realistic simulations rather than easy ones
Step by step
Values used
Users targeted = 2,500 users; Phishing emails reaching the inbox per user per year = 6 emails/year; Click rate = 8 %; Of those who click, share entering credentials = 35 %; Report rate = 20 %; MFA on the phished application = Number matching with context — 0.05; Time to contain a reported phish = 45 minutes; Cost of one account compromise = 35,000 currency
Phishing Risk
expectedCompromises = users × emails × clickRate × credentialEntryRate × mfaBypassFactor × containmentFactor.
Expected Account Compromises per Year
= 17.2 accounts/year
Clicks per Year
= 1,200 clicks/year
Credential Submissions per Year
= 420.0 per year
Expected Annual Loss
= 601,781
Report-to-Click Ratio
= 2.50 ×
Loss Avoided by Current MFA
= 11,433,844
How it works
Compromise is a funnel: delivered mail, clicks, credential submissions, then whether the second factor survives the attack. The MFA factor is the dominant term — push-based MFA is fatigued and OTPs are relayed by any modern phishing kit, while FIDO2 is bound to the origin and simply does not phish. Containment reflects that a fast report lets you retract the mail and reset the account before the session is used. The report-to-click ratio is the awareness metric that predicts outcomes: an organisation where more people report than click detects campaigns in minutes, and one where clicks dominate finds out from the SOC.
Formula
Phishing Risk
expectedCompromises = users × emails × clickRate × credentialEntryRate × mfaBypassFactor × containmentFactor.
- clickRate
- Share of delivered phishing emails clicked
- credentialEntryRate
- Share of clickers who submit credentials
- mfaBypassFactor
- Probability the MFA in place fails to stop the attack — 1.0 for none, 0.01 for FIDO2
- containmentFactor
- Reduction from users reporting quickly enough to retract and reset
Frequently Asked Questions
How is Phishing Risk calculated?
expectedCompromises = users × emails × clickRate × credentialEntryRate × mfaBypassFactor × containmentFactor. Compromise is a funnel: delivered mail, clicks, credential submissions, then whether the second factor survives the attack. The MFA factor is the dominant term — push-based MFA is fatigued and OTPs are relayed by any modern phishing kit, while FIDO2 is bound to the origin and simply does not phish. Containment reflects that a fast report lets you retract the mail and reset the account before the session is used.
Why does Phishing Risk matter?
The report-to-click ratio is the awareness metric that predicts outcomes: an organisation where more people report than click detects campaigns in minutes, and one where clicks dominate finds out from the SOC.
What values do I need to enter?
This calculator takes 8 inputs: Users targeted, Phishing emails reaching the inbox per user per year, Click rate, Of those who click, share entering credentials, Report rate, MFA on the phished application, Time to contain a reported phish, Cost of one account compromise. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.
Why does phishing-resistant MFA score 0.01 rather than 0?
Because attackers still succeed through consent phishing, device-code flows, session-token theft from an already-compromised endpoint and help-desk social engineering to enrol a new key. FIDO2 removes credential relay, not every path to the account.
Are simulation click rates comparable to real ones?
Only loosely. Simulations are typically easier to spot than a targeted attack and harder than bulk spam, so treat the figure as a trend line for your own population rather than an absolute probability.
You might also need
- Insider Threat Risk CalculatorCommonly used together
- Deepfake Risk CalculatorCommonly used together
- Email Security Score CalculatorCommonly used together
- Security Awareness Coverage CalculatorCommonly used together
- LLM Prompt Injection Risk CalculatorAlso in Forensics & Emerging Threats
- Enterprise Cybersecurity Health Score CalculatorAlso in Forensics & Emerging Threats