Glossary
The vocabulary, without the marketing
Fourteen terms this category uses constantly, defined plainly enough to paste into a policy document or an explanation for a board.
A–Z
Definitions
- Business email compromise (BEC)
- Fraud carried out by impersonating a trusted party over email — a supplier changing bank details, an executive requesting an urgent payment — usually without malware or a malicious link, which is why gateways rarely stop it. Phishing simulation →
- Credential harvesting
- Capturing usernames and passwords through a fake sign-in page. In a simulation the submission must be recorded as an event and the credentials discarded — a platform that stores them has created a new liability.
- Human risk management (HRM)
- Managing the likelihood that a person's action leads to a security incident, as a measured and reducible risk rather than an awareness campaign. The distinguishing feature is a behavioural metric that changes over time. Behavioral Risk Score →
- MFA fatigue (push bombing)
- Repeatedly triggering multi-factor prompts until the target approves one to stop the noise. Defeated by number matching and by training people that an unexpected prompt is a report, not an annoyance.
- Phish-prone rate
- The share of simulated phishing recipients who took the unsafe action — usually clicking. Only comparable when the difficulty, the channel mix and the population are held constant, which is why baselines matter more than absolute numbers. The 2026 benchmark →
- Quishing (QR phishing)
- Phishing that uses a QR code to move the target onto a personal device, outside managed browsers and URL protection. Effective in printed form — invoices, posters, parking notices — because physical media confers legitimacy. Beyond email →
- Repeat clicker
- Someone who fails two or more simulations within a rolling window. A small share of any workforce and a large share of credential submissions; they respond to immediacy and specificity, not to more generic content.
- Report rate
- The share of simulations reported rather than ignored. The leading indicator in this category: it predicts future credential-submit rates better than click rate does, and it is the only metric that produces value on the day it moves. Phish reporting →
- Secure email gateway (SEG)
- A filtering layer in front of a mail platform — Mimecast, Proofpoint and peers. Relevant to simulations because it will detonate URLs and strip lures unless a scoped bypass policy exists for the simulation sending domains. Deliverability →
- Smishing (SMS phishing)
- Phishing delivered by text message. Carries no headers to inspect and no gateway in front of it, and is frequently the only channel frontline staff read within the hour — which makes it both high-risk and under-tested.
- Spear-phishing
- A lure written for a specific person using real context — their role, a live project, a genuine supplier. Distinguished from bulk phishing by research effort, and the reason difficulty tiers exist in simulation platforms.
- Susceptibility rate
- How often a person or group takes the unsafe action when tested. One of ten factors in a resilience score; on its own it penalises heavily-targeted roles for their job description.
- Time-to-click
- Latency between delivery and first interaction. Median is around 21 seconds, with data entry roughly 28 seconds later — which is why detection measured in minutes arrives after the incident.
- Vishing (voice phishing)
- Phishing by phone call, increasingly with synthesised or cloned voice. The defence is procedural rather than perceptual: a verification step that does not rely on recognising who is speaking.
See the terms in practice
A twenty-minute demo covers most of this glossary using your own people and your own mail platform.