Skip to content

Glossary

The vocabulary, without the marketing

Fourteen terms this category uses constantly, defined plainly enough to paste into a policy document or an explanation for a board.

A–Z

Definitions

Business email compromise (BEC)
Fraud carried out by impersonating a trusted party over email — a supplier changing bank details, an executive requesting an urgent payment — usually without malware or a malicious link, which is why gateways rarely stop it. Phishing simulation
Credential harvesting
Capturing usernames and passwords through a fake sign-in page. In a simulation the submission must be recorded as an event and the credentials discarded — a platform that stores them has created a new liability.
Human risk management (HRM)
Managing the likelihood that a person's action leads to a security incident, as a measured and reducible risk rather than an awareness campaign. The distinguishing feature is a behavioural metric that changes over time. Behavioral Risk Score
MFA fatigue (push bombing)
Repeatedly triggering multi-factor prompts until the target approves one to stop the noise. Defeated by number matching and by training people that an unexpected prompt is a report, not an annoyance.
Phish-prone rate
The share of simulated phishing recipients who took the unsafe action — usually clicking. Only comparable when the difficulty, the channel mix and the population are held constant, which is why baselines matter more than absolute numbers. The 2026 benchmark
Quishing (QR phishing)
Phishing that uses a QR code to move the target onto a personal device, outside managed browsers and URL protection. Effective in printed form — invoices, posters, parking notices — because physical media confers legitimacy. Beyond email
Repeat clicker
Someone who fails two or more simulations within a rolling window. A small share of any workforce and a large share of credential submissions; they respond to immediacy and specificity, not to more generic content.
Report rate
The share of simulations reported rather than ignored. The leading indicator in this category: it predicts future credential-submit rates better than click rate does, and it is the only metric that produces value on the day it moves. Phish reporting
Secure email gateway (SEG)
A filtering layer in front of a mail platform — Mimecast, Proofpoint and peers. Relevant to simulations because it will detonate URLs and strip lures unless a scoped bypass policy exists for the simulation sending domains. Deliverability
Smishing (SMS phishing)
Phishing delivered by text message. Carries no headers to inspect and no gateway in front of it, and is frequently the only channel frontline staff read within the hour — which makes it both high-risk and under-tested.
Spear-phishing
A lure written for a specific person using real context — their role, a live project, a genuine supplier. Distinguished from bulk phishing by research effort, and the reason difficulty tiers exist in simulation platforms.
Susceptibility rate
How often a person or group takes the unsafe action when tested. One of ten factors in a resilience score; on its own it penalises heavily-targeted roles for their job description.
Time-to-click
Latency between delivery and first interaction. Median is around 21 seconds, with data entry roughly 28 seconds later — which is why detection measured in minutes arrives after the incident.
Vishing (voice phishing)
Phishing by phone call, increasingly with synthesised or cloned voice. The defence is procedural rather than perceptual: a verification step that does not rely on recognising who is speaking.

See the terms in practice

A twenty-minute demo covers most of this glossary using your own people and your own mail platform.

See your human risk in 20 minutes

Book a demo and we’ll run a sample campaign against a test group.