Click rate
The percentage of people who click a phishing simulation. Useful as a signal, misleading as the only metric of a program.
Full definition
Click rate is the percentage of recipients who click the link in a phishing simulation. It is the oldest and most quoted metric in awareness programs, and also the easiest to misread.
Its problem is that it depends on lure difficulty: an easy campaign produces low rates that look good in the report while saying nothing about real risk, and comparing rates across campaigns of different difficulty is comparing apples and oranges. A falling click rate can mean better behavior, or simply more obvious simulations.
Read together with report rate and retest results, click rate regains value: it shows which deception categories work against which teams and how vulnerability evolves after training. Alone, it is a vanity metric.
Related terms
Report rate
The percentage of people who report a simulation or a real attack. It is the best early indicator of a security culture that works.
Phishing simulation
A controlled phishing attack a company sends to its own employees to measure who falls, for which kind of lure, and how often.
Retest
A new simulation of the same attack category, weeks after a failure and with a different template, to verify the person actually changed their behavior.
From definition to data: measure your company's human risk
Fensivo detects leaked credentials, simulates real attacks and validates with retests that behavior changed.