Resources

KnowBe4’s 2026 Phishing Industry Benchmarking Report: Key findings

Written by Ross Harris | Aug 17, 2026, 11:00:26 AM

Despite improvements in email security, a convincing message can still reach an employee’s inbox and persuade them to click a link, open an attachment or even share sensitive information.

KnowBe4’s 2026 Phishing by Industry Benchmarking Report examines millions of simulated phishing tests to measure how employees respond before and after receiving security awareness training.

The report covers 19 industries, four organisation sizes and seven global regions. Its findings show the scale of the risk organisations face, but also the impact that regular training and simulated phishing can have over time.

What is a phish-prone percentage?

KnowBe4 measures phishing susceptibility using a metric called the Phish-prone Percentage, or PPP.

This represents the percentage of employees who interact with a simulated phishing test. The higher an organisation’s PPP, the more likely its employees are to respond to a genuine phishing email.

Before any security awareness training takes place, the global average PPP is 33.2%. This means around one in three employees is likely to engage with a malicious email if it reaches their inbox.

For organisations, this provides a useful way to measure human risk rather than relying on assumptions about how employees might respond.

Larger organisations face greater phishing susceptibility

The report found a clear link between organisation size and phishing susceptibility.

Businesses with fewer than 250 employees recorded an average baseline PPP of 24.7%. This increased as organisations became larger, reaching 39.5% among enterprises with more than 10,000 employees.

Larger businesses often have more departments, locations, suppliers and communication channels. Employees may regularly receive messages from people they do not know personally, making unusual requests or impersonation attempts more difficult to recognise.

They also offer cybercriminals a wider choice of potential targets. A single phishing campaign can be sent to thousands of employees in the hope that just one person responds.

Smaller organisations should not assume they are safe, however. A baseline PPP of 24.7% still means almost one in four employees could interact with a phishing email before training.

Some industries remain more vulnerable than others

Industry also has a significant effect on phishing susceptibility.

For the second consecutive year, Healthcare and Pharmaceuticals, Insurance and Retail and Wholesale recorded the highest baseline PPPs.

Healthcare and Pharmaceuticals had an average baseline PPP of 42.7%, followed by Insurance at 38.1% and Retail and Wholesale at 36%.

These sectors often manage large volumes of valuable personal, medical or financial information. They may also have distributed workforces, busy customer-facing teams and employees who need to respond quickly to external communications.

However, phishing is not limited to a particular type of business. Every organisation has employees who receive emails, access systems and handle information that could be valuable to an attacker.

The industry benchmarks give organisations a way to compare their own results with businesses of a similar size and type. They can also help partners identify customers that may face greater exposure because of their sector, workforce structure or current approach to training.

Training makes a measurable difference

The baseline figures are concerning, but the report also shows that phishing susceptibility can be reduced significantly.

Within 90 days of introducing security awareness training and simulated phishing, the global average PPP fell from 33.2% to 20.1%. This represents a 40% reduction.

After 12 months of continuous training and testing, the average PPP fell to 4.2%, an 87% reduction from the original baseline. After 24 months, the average stabilised at 3.9%.

The timeline is important. Although organisations see progress during the first 90 days, the greatest reduction takes place between months three and 12.

A single training course or annual presentation may meet a basic compliance requirement, but it is unlikely to create the same lasting change in employee behaviour.

Regular training keeps security front of mind, while simulated phishing tests give employees an opportunity to practise recognising realistic threats. They also allow organisations to track progress and identify users who may need additional support.

AI is changing phishing attacks

KnowBe4 reports that phishing attacks have increased by 17.1% since the second half of 2025. It also highlights the growing effect of AI-powered phishing on the threat landscape.

Generative AI can help attackers create personalised, convincing phishing emails more quickly. Messages can be adapted to reflect a recipient’s role, industry, location or organisation, while avoiding some of the spelling mistakes and unusual wording traditionally associated with phishing.

This makes it harder for employees to rely on a simple checklist of warning signs.

Training must reflect the emails and social engineering techniques employees are likely to face now. More personalised programmes can also focus additional training on users, teams or roles with a higher level of risk.

Starting better conversations about human risk

For Brigantia partners, the report provides useful evidence for conversations with both prospects and existing customers.

Some businesses may have strong technical controls but no way to measure how their employees would respond if a phishing email bypassed them. Others may already provide security awareness training but treat it as a one-off annual task.

Partners can use the report’s benchmarks to raise questions such as:

  • Does the customer know its current phish-prone percentage?
  • How does its result compare with businesses of a similar size and industry?
  • Is training delivered regularly or only once a year?
  • Are simulated phishing tests used to measure changes in behaviour?
  • Can the customer identify which users or departments require more support?
  • Has its phishing susceptibility improved over the past 12 months?

These questions can help move the conversation away from whether training has been completed and towards whether it is reducing risk.

Help customers reduce their phishing susceptibility with KnowBe4

KnowBe4 combines security awareness training, simulated phishing exercises and detailed reporting to help organisations understand and reduce human risk.

Its library includes frequently updated and localised training content, real-world phishing simulations and email templates. Reporting gives organisations visibility of their risk levels and wider security culture.

Brigantia also offers KnowBe4 as a Managed Service, helping partners deliver ongoing training and phishing simulations while reducing the time and resources required to manage the platform.

To learn more about KnowBe4, arrange a demonstration or discuss an opportunity, contact the Brigantia team.