Model phishing exposure from campaign volume, click and report rates, credential entry, MFA strength and expected compromises.
Compromise is a funnel: delivered mail, clicks, credential submissions, then whether the second factor survives the attack. The MFA factor is the dominant term — push-based MFA is fatigued and OTPs are relayed by any modern phishing kit, while FIDO2 is bound to the origin and simply does not phish. Containment reflects that a fast report lets you retract the mail and reset the account before the session is used. The report-to-click ratio is the awareness metric that predicts outcomes: an organisation where more people report than click detects campaigns in minutes, and one where clicks dominate finds out from the SOC.
Phishing Risk
expectedCompromises = users × emails × clickRate × credentialEntryRate × mfaBypassFactor × containmentFactor.
expectedCompromises = users × emails × clickRate × credentialEntryRate × mfaBypassFactor × containmentFactor. Compromise is a funnel: delivered mail, clicks, credential submissions, then whether the second factor survives the attack. The MFA factor is the dominant term — push-based MFA is fatigued and OTPs are relayed by any modern phishing kit, while FIDO2 is bound to the origin and simply does not phish. Containment reflects that a fast report lets you retract the mail and reset the account before the session is used.
The report-to-click ratio is the awareness metric that predicts outcomes: an organisation where more people report than click detects campaigns in minutes, and one where clicks dominate finds out from the SOC.
This calculator takes 8 inputs: Users targeted, Phishing emails reaching the inbox per user per year, Click rate, Of those who click, share entering credentials, Report rate, MFA on the phished application, Time to contain a reported phish, Cost of one account compromise. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.
Because attackers still succeed through consent phishing, device-code flows, session-token theft from an already-compromised endpoint and help-desk social engineering to enrol a new key. FIDO2 removes credential relay, not every path to the account.
Only loosely. Simulations are typically easier to spot than a targeted attack and harder than bulk spam, so treat the figure as a trend line for your own population rather than an absolute probability.