The Phishing Behaviour Report 2026
A year of phishing behaviour across SMB and mid-market organsiations, showing why click rate alone can't tell you whether your workforce is getting safer. The data tracks how click, leak and report rates move together over a 12-month programme: where risk peaks, which sectors and departments carry the most, and what genuine resilience looks like in the numbers.
Five findings that challenge conventional security awareness programmes
1. More users report than click on their first simulation, but 1.57% still leak credentials.
There is a baseline of security awareness, but in an organisation of 500, that still means up to eight people could hand over their login details to a convincing attack.
2. Click rates peak at six months, when users are tested hardest.
It looks like regression, but the 6-month stage contains more simulations and the highest share of Hard tests. The increase reveals risk that simpler tests don’t expose.
3. Technical teams are not automatically low risk.
Over a year, 30.27% of Tech Development users and 28.53% of IT users clicked at least once. Knowledge does not guarantee behaviour.
4. The same test produces very different results across teams.
With a similar difficulty mix across all 18 departments, cumulative click rates ranged from 26.35% in Design to 41.31% in Construction. A one-size-fits-all approach cannot account for that variation.
5. Click rate is only part of the picture.
Resilience means fewer clicks, fewer credential leaks and more reports. By 12 months, users reported suspicious emails nearly twice as often as they clicked them, showing that effective programmes build vigilance, not just fewer clicks.
Download the report
Submit your details to receive the full report.
You'll receive an automated email shortly.