The 2026 human risk benchmark: what 4.6 million simulations show
Phish-prone rates fall from 33.2% to 4.2% over twelve months — but two-thirds of that lands in the first ninety days.
By SafeLoop Research · Updated
Every vendor in this category publishes a curve that goes down. Fewer publish the shape of it, and almost none publish what happens to the people the curve leaves behind. This is our attempt at the second thing.
The dataset behind this piece is 4.6 million simulations delivered across 1,200 organisations between January 2025 and April 2026, spanning email, SMS, voice and QR. Where we cite an industry figure rather than our own, it is attributed inline.
The headline curve
Baseline phish-prone rate across the dataset was 33.2%. Ninety days into a continuous programme it was 20.1%. At twelve months it was 4.2% — an 87% relative reduction, consistent with the published KnowBe4 2026 benchmark.
The shape matters more than the endpoints: most of the movement is early.
The interesting part is the distribution of that improvement over time. Roughly two-thirds of the total reduction lands in the first ninety days. That early drop is dominated by people who had simply never been tested before — a first simulation teaches a large number of people something genuinely new, and it does so cheaply.
The ninety-day trap
Because that first drop is so large, it is also the point at which programmes are most likely to be declared finished. In our dataset, organisations that reduced campaign frequency after the ninety-day win regressed toward their baseline within two quarters.
The reason is straightforward: the remaining population is not the same population. What is left after ninety days is disproportionately made up of repeat clickers, and repeat clickers do not respond to the intervention that worked on everybody else.
Repeat clickers are a different problem
Across the dataset, the cohort that failed two or more simulations in a rolling six-month window accounted for a small share of people and a large share of credential submissions. Generic awareness content moved them very little. What moved them was three things.
- Immediacy — training that arrived within minutes of the failure rather than at the next scheduled cycle.
- Specificity — a module matched to the failure type, not a general course reassigned.
- Channel change — testing the same person over SMS or voice after repeated email failures, which frequently revealed that the problem was not email literacy at all.
Report rate is the metric that predicts
Click rate tells you what went wrong. Report rate tells you whether the workforce has become useful. Organisations in the top quartile for report rate at six months had materially lower credential-submit rates at twelve, even where their click rates were comparable at baseline.
The moment our report rate passed our click rate, the SOC started treating the workforce as a sensor rather than a liability.
Head of Security Awareness, 12,000-person health system
Channels change the answer
Email-only programmes systematically over-report their own maturity, because they never measure the channels where a large part of the workforce is actually reachable. In mixed-channel deployments, SMS failure rates for frontline and field staff ran well above the same organisation's email figures.
If a third of your people have no corporate mailbox, an email-only phish-prone rate is not a measure of your organisation. It is a measure of your office workers.
What we would do with twelve months
- Baseline honestly, at tier one, across every channel you can reach — accept the uncomfortable number.
- Run monthly per person with cool-down windows, not quarterly for everybody at once.
- Enrol on failure automatically, matched to the failure, within minutes.
- Track the repeat cohort separately from month three and treat it as its own programme.
- Report the graded score and report rate to the board; keep completion in the appendix.
None of this is difficult. Almost all of it is automatable. The programmes that plateau are rarely short of effort — they are usually short of the second half of the year.
Keep reading
Related articles
Beyond email: why smishing, vishing and quishing belong in every programme
Attackers moved channels years ago. An email-only programme measures your office workers and calls it an organisation.
Read article →Why quarterly phishing tests fail, and what monthly-per-person fixes
Sending one campaign to everybody every three months optimises for administrative convenience. Here is what changes when you pace per person instead.
Read article →Deliverability is the hard part nobody advertises
A simulation sitting in quarantine produces a flattering number and teaches nobody. What actually has to be configured, and why.
Read article →