What a phishing resilience score measures, why click rate alone misleads, and how to move the number without gaming it.
A phishing resilience score is a single number describing how well an organisation withstands phishing — not just how often people fall for it, but how the workforce behaves as a whole when a suspicious message arrives.
Deep dive: for how the metric is calculated and acted on, see the complete guide to phishing resilience scoring.
Why one number, and why not click rate
Click rate is the obvious candidate and a poor one on its own, for a reason that catches almost everyone: it can be improved by making simulations easier. Send an obvious lure, watch clicks fall, report success. Nothing about the organisation changed.
A resilience score exists to resist that. By combining several behaviours, it becomes much harder to move the number without genuinely improving.
What goes into it
- Click rate — who followed the link, and separately, who went on to enter credentials. The second is the more serious failure.
- Reporting rate — who actively flagged the message to security.
- Time to report — how quickly the first warning arrived.
- Training engagement — whether people are completing what they are assigned.
- Repeat behaviour — whether the same individuals click campaign after campaign.
Why reporting carries so much weight
Picture two teams, both with a 10% click rate. Team A reports the message half the time; Team B reports it 5% of the time.
Team A is dramatically more resilient, and the reason is timing. A real phishing campaign hitting 200 inboxes is a race between the attacker and your security team. Reports are how that race is won — they let someone pull the message from every other inbox before the tenth person clicks. A high click rate with fast reporting is recoverable. A low click rate with no reporting means an attack runs unnoticed until something breaks.
This is also why low clicks and low reports is a warning sign rather than a good result. It usually means people are ignoring their email, not recognising threats.
How to improve it honestly
Run simulations consistently. One a year builds no habit — how often to run them sets out a sensible cadence. Vary the difficulty rather than settling on lures you know will pass.
Reward reporting, never punish clicking. Punishment reliably lowers reporting, because people hide mistakes rather than flag them. That trades a visible metric for an invisible risk.
Keep training short and immediate. A two-minute lesson at the moment of the click beats an hour-long module three weeks later.
Focus on repeat clickers. A small group usually accounts for a large share of the exposure. Targeted support for a handful of people moves the number more than retraining everyone.
What the score does not tell you
It measures behaviour under simulation, which is a proxy for behaviour under attack — a good one, but a proxy. It says nothing about your technical controls, and a strong score does not mean an attacker cannot get in another way. Treat it as one instrument on the dashboard rather than the dashboard itself.
Improvement does carry financial weight: organisations with stronger resilience consistently report better training ROI benchmarks.
Related Learning
More Learning Resources
View all learning resourcesBusiness Email Compromise (BEC) Explained
Learn what Business Email Compromise (BEC) is, how these sophisticated financial scams work, and the strategies organizations can use to defend against them.
Quick Guide: Phishing Statistics
What the headline phishing numbers mean, how to read a benchmark without fooling yourself, and which of your own metrics actually predict risk.
What Is a Phishing Simulation?
What a phishing simulation is, how one runs end to end, what the results actually tell you, and the ethics of testing your own colleagues.
Ready to stop phishing attacks?
Run realistic phishing simulations and high-impact security awareness training with PhishSkill's automated platform.