Report rate
The percentage of people who report a simulation or a real attack. It is the best early indicator of a security culture that works.
Full definition
Report rate is the percentage of recipients who report a phishing email, simulated or real, through the company's official channel. It measures the behavior that actually protects: an early report gives the security team the signal to block the attack before someone else falls.
It is harder to game than click rate, because reporting is a voluntary act that requires attention, judgment and confidence that speaking up brings no punishment. That is why it works as a thermometer of security culture: it rises when practice is frequent and mistakes are treated as data, not offenses.
In a mature program, a rising report rate while click rate falls against increasingly difficult lures is the best evidence that human risk is genuinely going down.
Related terms
Click rate
The percentage of people who click a phishing simulation. Useful as a signal, misleading as the only metric of a program.
Security culture
What employees do about security when nobody is watching: reporting, verifying, asking. It is built through practice, not posters.
Phishing simulation
A controlled phishing attack a company sends to its own employees to measure who falls, for which kind of lure, and how often.
From definition to data: measure your company's human risk
Fensivo detects leaked credentials, simulates real attacks and validates with retests that behavior changed.