THE CRUNCH
A new analysis of 2.47 million simulated phishing attacks suggests that organizations should shift their security awareness testing focus from simple clicks to reporting and credential leaks. The study, conducted by SecurityWeek, argues that current testing methods may not accurately reflect an organisation's true security posture. By analysing a vast dataset, the research highlights the limitations of relying solely
on click rates as a primary metric for success. Instead, the research proposes that measuring how many users report suspicious emails and how many credentials are actually compromised provides a clearer picture of an organisation's resilience. This approach could help security teams identify and address gaps in their awareness training more effectively. The findings challenge the conventional wisdom that a high click rate is a definitive sign of poor security awareness. Instead, a high click rate might indicate that users are engaged and actively testing the system, whereas a low click rate could mask a more dangerous complacency where users do not recognise threats at all. The research emphasises the need for a more nuanced approach to security awareness testing that accounts for these behavioural nuances.


