Join our Newsletter — 33% off our NHI Course

Email Reporting Rate

Email reporting rate is the proportion of received suspicious messages that employees forward or flag for security review. It is a practical indicator of awareness and participation, showing whether users are noticing threats and choosing to escalate them. Higher reporting rates usually reflect stronger security culture and better frontline detection.

What Email Reporting Rate Measures

Email reporting rate shows how often people who receive suspicious messages choose to report them instead of ignoring, deleting, or interacting with them. It is a behavioural security measure, not a technical detection metric, and it reflects whether users recognise potential phishing and treat escalation as part of normal work.

Because it measures the human response to suspected threats, the term is most useful when read as a signal of awareness, trust in reporting channels, and the ease of frontline escalation. A strong rate usually means employees understand what looks suspicious and believe reporting will lead to action.

Why the Metric Matters for Security Culture

Reporting rate matters because the first person to spot a malicious message is often the recipient. When users report quickly, security teams gain earlier visibility into phishing campaigns, business email compromise attempts, and malicious links or attachments that may not yet be blocked by automated controls.

The metric also helps distinguish passive awareness from active participation. Training can improve recognition, but reporting behaviour shows whether that recognition becomes a real security habit. In that sense, the measure captures both user judgement and the organisation’s ability to turn awareness into an operational signal.

Low reporting rates often point to friction, confusion, or weak trust in the process. If people are unsure what should be reported, or if reporting feels slow and unrewarded, the metric can stall even when awareness content is sound.

How to Interpret the Number

Email reporting rate should be interpreted alongside volume, accuracy, and response speed. A rise in reporting can be positive even if it also increases false positives, because it often means more suspicious mail is reaching human attention before harm occurs.

The metric is most meaningful when paired with other outcomes such as click rate, simulation performance, mailbox protection, and analyst handling time. Reporting by itself does not prove resilience, but it can reveal whether users are contributing to early detection and whether the reporting path is actually usable.

It is also worth treating the metric as a trend rather than a one-off score. Campaign type, user population, recent incidents, and communication style can all shift reporting behaviour, so short-term changes should be read carefully.

Operational Use in Awareness and Detection Programs

Teams use email reporting rate to judge whether awareness initiatives are working as intended and whether suspicious mail is reaching the right escalation path. In mature programmes, reported messages become a detection feed that complements gateway filtering and threat intel, especially when attack patterns evolve faster than automated signatures.

The measure is also helpful for comparing departments, geographies, or roles where exposure and behaviour differ. That can reveal where further training, simpler reporting controls, or stronger messaging is needed. For a broader view of how user reporting fits into resilience and control design, NCSC UK Advice and Guidance is a useful reference point, and the NIST Cybersecurity Framework 2.0 provides the wider govern, detect, respond lens that gives the metric context.

At the control level, the metric aligns with practical detection and reporting capabilities in NIST SP 800-53 Rev 5 Security and Privacy Controls and the human-participation side of phishing defence described in NIST SP 800-63 Digital Identity Guidelines.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

CIS Controls v8, NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
CIS Controls v8 CIS-9 — Email and Web Browser Protections Email reporting rate reflects how well users help surface suspicious messages for defensive review.
Recommendation — Use CIS-9 to reinforce email reporting paths and reduce user exposure to malicious messages.
NIST CSF 2.0 DE.CM-01 — Monitoring for Unauthorized Personnel, Connections, Devices, and Software Reported phishing messages extend monitoring into user-reported suspicious communications.
RS.CO-02 — Incidents Are Reported Consistent With Established Criteria The metric measures whether users escalate suspicious email through defined reporting criteria.
Recommendation — Use DE.CM-01 to feed user-reported email into monitoring and triage workflows. Use RS.CO-02 to standardize when users should report suspicious email.
NIST SP 800-53 Rev 5 AT-2 — Awareness Training Reporting rate is a practical outcome of security awareness and phishing recognition.
IR-6 — Incident Reporting The metric directly measures the human reporting path that supports incident handling.
Recommendation — Use AT-2 to train users to recognize and report suspicious messages. Use IR-6 to define and test a clear path for suspicious-email reporting.