Join our Newsletter — 33% off our NHI Course

Reporting Rate

Reporting rate is the share of employees who correctly identify and report a simulated or real phishing attempt. It is a stronger maturity signal than click rate because it reflects active detection behaviour. Higher reporting rates usually indicate better awareness, stronger security culture, and faster containment potential.

Expanded Definition

Reporting rate measures how consistently people escalate suspected phishing, whether the message is simulated or genuinely malicious. It is a behavioural metric, so it reflects detection and response habits rather than simple exposure to a lure. That makes it more informative than click rate in many awareness programmes, because a low click rate can still hide weak incident reporting discipline. In practice, security teams use reporting rate to understand whether staff recognise suspicious content, trust the reporting channel, and act quickly enough to support containment.

The metric sits close to operational security because it connects human judgement to incident response, but it is not a formal control by itself. Definitions vary across vendors and programme owners: some count only correct reports, others count timely reports, and some require a simulated phish to be fully analysed by a SOC workflow before it is counted. The most useful interpretation is one that links behaviour to response outcomes, not vanity averages. The most common misapplication is treating a high reporting rate as proof of resilience, which occurs when organisations measure submissions without verifying whether the reports are accurate, timely, and actionable.

For broader cyber governance context, the NIST Cybersecurity Framework 2.0 emphasizes the need to detect and respond to events through coordinated practices, which is where reporting behaviour becomes meaningful.

Examples and Use Cases

Implementing reporting rate rigorously often introduces measurement overhead, requiring organisations to balance simple awareness dashboards against the cost of validating each report for quality and timeliness.

  • A simulated phishing campaign includes a “report phish” button, and the security team measures how many recipients submit the message within the defined window.
  • A help desk records employee escalations of suspicious login prompts, then correlates those reports with mailbox telemetry to see whether the reports were accurate.
  • A finance team reports a fake invoice email before any link is opened, showing that the reporting path works as an early-warning channel.
  • A SOC uses reporting rate alongside time-to-report to identify departments that may need more targeted awareness coaching.
  • An organisation with remote and hybrid staff tracks reporting by business unit to see whether awareness is consistent across locations and onboarding cohorts.

Where phishing simulations are part of the programme, guidance from sources such as the CISA phishing guidance helps teams frame reporting as a detection behaviour, not just an awareness score.

Why It Matters for Security Teams

Reporting rate matters because phishing defence depends on speed as much as on prevention. If people report suspicious messages quickly, defenders can hunt for mailbox rules, token theft, credential use, and lateral spread before the event becomes an incident. A strong reporting rate also signals that employees understand the reporting path and trust that action will follow, which is essential for security culture. From a governance perspective, it gives leaders a behavioural indicator that complements technical telemetry from email security, SIEM, and incident response workflows.

This term also intersects with identity and access security. When a report leads to a verified compromise, teams often need to revoke sessions, reset credentials, and review privileged access, so reporting behaviour directly affects containment of credential abuse. For programme design, the OWASP guidance on AI-related misuse patterns is also relevant where phishing is augmented by AI-generated content, because more persuasive messages can make timely reporting harder. Organisations typically encounter the true value of reporting rate only after a phishing event spreads beyond the first inbox, at which point fast reporting becomes operationally unavoidable to contain it.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10 address the attack and risk surface, while NIST CSF 2.0 and NIST SP 800-63 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
NIST CSF 2.0 RS.AN-1 Reporting rate reflects how quickly people detect and communicate suspicious events.
NIST SP 800-63 Identity compromise often follows phishing, making reporting rate relevant to credential protection.
OWASP Agentic AI Top 10 AI-generated phishing can increase message realism and affect human reporting behaviour.

Use rapid reporting to trigger credential resets and session revocation after suspected phishing.