Source: Businesswire India
KnowBe4, the world-renowned cybersecurity platform that comprehensively addresses human risk management, today launched its “Phishing by Industry Benchmarking Report 2025” which measures an organization’s Phish-prone™ Percentage (PPP) — the percentage of employees likely to fall for social engineering or phishing attacks, indicating the organization’s overall susceptibility to phishing threats. This year’s report found a global average baseline PPP of 33.1%, meaning a third of employees interact with phishing simulations before taking part in best-practice security awareness training (SAT).
The data underscores the significant impact of SAT in mitigating risk. The rapid decline in the global PPP following the implementation of training — falling by 40% in just three months and by a total of 86% after 12 months — demonstrates that ongoing, effective training leads to lasting behavior change and a substantial reduction in vulnerability to cybersecurity threats. This highlights the critical role of continuous education in building a stronger security culture within organizations, even in as little as three months.
KnowBe4 analyzed 67.7 million phishing simulations globally, across 14.5 million users from 62.4 thousand organizations. The baseline PPP (33.1%) reflects an organization’s susceptibility to phishing before any KnowBe4 training. Employees then undergo KnowBe4’s SAT, and the PPP is recalculated after 90 days and again after one year-plus of ongoing training to quantify the program’s effectiveness.
Other Key Findings from the Phishing By Industry Benchmarking Report:
“The data speaks for itself — security awareness training truly makes a difference,” said Stu Sjouwerman, CEO of KnowBe4. “From 2024 to 2025, the general trend has remained fairly consistent — around one-third of employees click on a simulated phishing link before taking part in training. However, the data shows a slight improvement in 2025. Within a year, we’ve seen a 3.5% decrease in the global baseline PPP, highlighting a positive shift in overall security awareness worldwide. However, there is still significant progress to be made in fully addressing phishing risks. By consistently prioritizing relevant and engaging training, combined with simulated phishing, organizations can strengthen their human risk management strategies and better protect against phishing to improve overall security culture.”
To download a copy of the Phishing by Industry Benchmarking Report 2025, visit here.
About KnowBe4
KnowBe4 empowers workforces to make smarter security decisions every day. Trusted by over 70,000 organizations worldwide, KnowBe4 helps to strengthen security culture and manage human risk. KnowBe4 offers a comprehensive AI-driven ‘best-of-suite’ platform for Human Risk Management, creating an adaptive defense layer that fortifies user behavior against the latest cybersecurity threats. The HRM+ platform includes modules for awareness & compliance training, cloud email security, real-time coaching, crowdsourced anti-phishing, AI Defense Agents, and more. As the only global security platform of its kind, KnowBe4 utilizes personalized and relevant cybersecurity protection content, tools and techniques to mobilize workforces to transform from the largest attack surface to an organization’s biggest asset.
View source version on businesswire.com: https://www.businesswire.com/news/home/20250513295204/en/
DISCLAIMER
The content and services provided by Kalkine Consultancy India Private Limited (Research Analyst License No: INH000017727, hereinafter referred to as “Kalkine”) are for informational purposes only. The content, including but not limited to articles, news, quotes, information, data, text, reports, ratings, opinions, images, photos, graphics, charts, animations, and videos (collectively, “Content”), is a service of Kalkine Consultancy India Private Limited and is available for personal and non-commercial use only. Kalkine does not provide personalized financial advice and does not endorse or recommend any individuals, investment products, or services as suitable for specific financial situations. Investors are advised to consult a qualified financial planner or adviser to assess their risk tolerance and portfolio suitability before making any investment decisions. Kalkine accepts no liability for investment losses or any other financial detriment arising from reliance on the Content. Some of the Content on this website may be sourced from third-party providers. Kalkine does not claim ownership over such third-party content and does not guarantee its accuracy, completeness, or reliability. Kalkine shall not be held liable for any errors, omissions, or inaccuracies in third-party content or for any damages or losses resulting from its use. Any images, music, or videos used in the Content are either sourced from publicly available materials, paid subscriptions, or credited to their respective owners where applicable. Kalkine does not claim ownership of third-party media unless explicitly stated. This disclaimer is subject to change without notice. Users are advised to review it periodically for updates.