Pistachio Phishing Behaviour Report 2026 shown as an open report booklet with phishing simulation data, including click, credential leak, and reporting rates across 123,692 users.

How Exposed Is Your Business to Phishing?

Published on 24.09.20263 min read

There are two common ways SMB and mid-market organisations approach phishing risk. Some assume their people are aware enough to spot an obvious scam. Others run training once a year, tick the box, and move on.

Both approaches miss the same thing: phishing risk is always there, and the attacks keep changing.

We analysed a year of phishing behaviour across 123,692 employees. One finding stood out: people are vulnerable before any training has taken place.

Your phishing risk exists today

You can see it on the very first simulation a person receives, before training has influenced how they respond.

On that first test, 4.14% clicked the link and 1.57% entered their credentials. In a 500-person business, that is up to eight people handing over their login details to a single phishing email.

Chart showing journey curve over 12 months.

That is the baseline. It is not a sign of a weak training programme, because there is no programme yet. It shows what can happen when a convincing email reaches people who are not expecting it.

If you do nothing, that exposure stays unmanaged until a real attack arrives.

Why once-a-year training doesn't manage the risk

A single training session can feel like the problem has been solved. People join and leave, so a session held in January never reaches someone who starts in March. Attacks change, so what people learned to spot last year may not help when a different type of attack lands this year. And skills fade when they are not used.

An annual programme sets a baseline, then leaves it to erode for eleven months. It creates the impression that the risk is being managed, while the exposure underneath keeps changing.

Why managing phishing risk means regular training

Most people already know that phishing exists. The challenge is recognising and resisting an attack when it arrives.

That takes practice.

In our data, organisations whose people became harder to phish over the year were those running continual, realistic simulations rather than relying on a single annual session. Regular simulations give employees repeated opportunities to recognise suspicious emails in context.

The risk is present every day, so the response needs to be continuous too.

The aim is not to overload people. Testing often enough, and realistically enough, is what turns spotting a suspicious email into a habit rather than something they were told about once.

Start by knowing your exposure

Phishing risk is not something you remove with a one-off training session. It is something you manage because it is always there.

The first step is understanding your starting point. The next is running a programme that keeps pace with the risk.

Download the full Phishing Behaviour Report 2026 to see how behaviour changes across a 12-month programme, and what separates organisations building lasting resilience.

Want to see how continuous, adaptive simulations keep your people sharp as threats change? Email contact@pistachioapp.com to book a 15-minute demo.

Anyone can fall for a phishing scam.

That’s the point of Pistachio’s approach to hands-on learning over snooze-worthy training videos.

Activity overview of user