TL;DR: A global pre-training Phish-prone Percentage of 33.2% is found in a 2026 benchmarking report, with continuous security awareness training reducing susceptibility by 87% to 4.2% over a year, according to Knowbe4. The governance lesson is that behavioural risk decays slowly, so identity and access programmes need sustained controls, not campaign-based awareness, and the report notes a 17.1% increase in phishing attacks since the second half of 2025.
At a glance
What this is: KnowBe4’s benchmarking report shows phishing susceptibility remains high before training, with a global average Phish-prone Percentage of 33.2% and a marked drop after continuous awareness programmes.
Why it matters: This matters because phishing still feeds credential theft, account takeover, and downstream access abuse, so IAM, PAM, and identity verification programmes need behavioural controls that reduce human and non-human trust failures together.
By the numbers:
- Before any security awareness training, the global average Phish-prone Percentage (PPP) stands at 33.2%.
- Organizations that commit to a full year of continuous security awareness training reduce their PPP by an average of 87%, bringing average susceptibility down to just 4.2%.
- The 2026 KnowBe4 report shows a 17.1% increase in phishing attacks since the second half of 2025.
👉 Read KnowBe4's 2026 Phishing by Industry Benchmarking Report
Context
Phishing remains a governance problem because human decision-making is still one of the most reliable entry paths into identity compromise. In the KnowBe4 benchmarking data, the issue is not whether people can be trained, but whether organisations are willing to treat behaviour change as a continuous control rather than a one-time intervention. That framing matters for IAM, PAM, and identity verification teams because a single successful phish can still expose passwords, MFA flows, help desk processes, and delegated access.
The report also points to an identity-adjacent reality that security teams often underweight: attackers do not need to defeat every control if they can influence one user, one workflow, or one reset path. AI-assisted phishing makes that easier by improving personalisation and timing. For identity programmes, the implication is straightforward. Human identity controls and non-human identity controls increasingly face the same trust-exploitation problem, just at different layers of the stack.
Key questions
Q: How should security teams reduce phishing risk without relying only on awareness training?
A: They should combine user training with behavioural detection, vendor verification, and tighter controls on high-risk identity actions. Awareness helps users spot obvious lures, but it does not stop impersonation that looks routine. The stronger model is to detect trust abuse across mail, identity, and workflow layers before approval or credential use occurs.
Q: When does phishing-resistant MFA still leave identity risk unresolved?
A: It leaves risk unresolved when recovery, reset, or session revocation paths remain weak. Attackers often target the easier path around the primary factor, especially help-desk or self-service recovery flows. Strong sign-in controls matter, but the broader control boundary has to include how credentials are reset and how sessions are terminated.
Q: What do security teams get wrong about phishing awareness training?
A: They often treat training as a replacement for technical containment. Awareness can reduce clicks, but it does not stop every mistake, especially under pressure or when attackers use convincing workflow-based lures. Training should be measured by lower incident impact, faster reporting, and fewer successful follow-on actions.
Q: Who is accountable when phishing leads to customer fraud and account takeover?
A: Accountability is shared across identity, fraud, and application owners because the attack crosses authentication, session handling, and transaction risk. The security programme should define who owns lookalike domain detection, who owns session abuse detection, and who decides when to step up or block access after suspicious login behaviour is detected.
Technical breakdown
Why phishing still bypasses identity controls
Phishing succeeds when attackers exploit trust before technical controls can intervene. A malicious message can capture credentials, coerce MFA approval, redirect a user to a convincing login page, or trigger a help desk reset path. In identity terms, the attack is not just email abuse. It is an attempt to insert a false authentication event into a legitimate access workflow. Once that event is accepted, downstream controls such as RBAC, session policies, and PAM are forced to operate on compromised identity signals rather than trusted ones.
Practical implication: teams should treat phishing resistance as part of identity assurance, not only as an awareness topic.
Why continuous training outperforms one-off campaigns
The report’s pattern shows that behaviour change accumulates over time. Early reductions are useful, but the real drop appears when training is sustained across months, not days. That fits how human error works in access risk. Users need repeated exposure to realistic scenarios, especially as attack language, lures, and impersonation tactics evolve. For identity programmes, this means measuring change in susceptibility, not just course completion. Completion rates tell you who attended; they do not tell you whether users are less likely to approve a malicious prompt or surrender a credential.
Practical implication: measure behaviour change over time, not training attendance alone.
How AI-powered phishing changes the trust model
AI-assisted phishing increases message quality, personalisation, and scale, which weakens the assumptions behind generic awareness programmes. The attacker no longer depends on obvious spelling mistakes or broad campaigns. Instead, the lure can match role, geography, business context, and timing, making human verification harder. That is relevant to NHI governance too, because the same social engineering patterns are increasingly used to steal tokens, reset privileged accounts, or manipulate support workflows that protect service identities. The trust boundary is becoming behavioural as much as technical.
Practical implication: align awareness, identity verification, and help desk controls around realistic impersonation scenarios.
Threat narrative
Attacker objective: The attacker wants to convert human trust into authenticated access that can be reused for account takeover, fraud, or deeper network intrusion.
- Entry begins with a phishing lure that impersonates a trusted sender, brand, or business process and reaches a user at a moment of routine decision-making.
- Escalation follows when the target submits credentials, approves MFA, or opens a path into a reset or delegation workflow, giving the attacker a trusted identity signal.
- Impact occurs when the attacker uses that trust to access email, internal systems, or privileged workflows, often opening the door to broader credential theft and account takeover.
NHI Mgmt Group analysis
Phishing is now an identity assurance problem, not a communications problem. The report’s 33.2% pre-training susceptibility figure shows that a large share of users will still interact with malicious content before any remediation begins. That means identity programmes cannot rely on a single awareness layer to protect authentication, recovery, and delegation workflows. The governance gap is not lack of information, but lack of repeated verification at the point of human decision.
Continuous training only works when it is treated like a control loop. The 87% reduction reported after a year of training is meaningful because it reflects sustained reinforcement, not a one-off campaign. Security teams should read that as a signal that behavioural controls need measurement, feedback, and repeat exposure. For identity governance, the practical conclusion is that awareness content must be tied to risk signals from phishing tests, account takeover attempts, and support desk abuse.
AI-powered phishing widens the trust-exploitation surface across human and non-human identity workflows. As lures become more personalised, attackers can target not only users but also recovery channels, delegated approvals, and service access processes that depend on human intervention. Trust exploitation drift: the attack pattern where users and operators become the weakest validation layer because the message, request, or reset step looks legitimate. That is why identity governance now has to include behavioural verification, not only policy enforcement.
Organisations should stop treating phishing outcomes as an endpoint metric. A falling click rate is useful, but it does not automatically mean reduced identity risk if attackers are now using consent grants, MFA fatigue, or help desk manipulation instead. The more important question is whether identity assurance improves across login, reset, and escalation paths. For practitioners, the lesson is to govern the entire trust chain, not just the inbox.
What this signals
Phishing programmes now need to be measured like identity controls because the operational failure mode is trust, not simply user error. A team that only tracks completion rates will miss the point. The real signal is whether users, service desks, and delegated approval paths become harder to manipulate over time.
Trust exploitation drift: as phishing becomes more personalised, the control boundary moves from inbox filtering to identity verification, recovery workflow hardening, and behavioural monitoring. That is where IAM, PAM, and fraud-prevention teams converge. The organisations that prepare for that convergence will be better placed to absorb AI-assisted lures without turning every message into a potential compromise.
For practitioners
- Instrument phishing as an identity-risk control Track phishing test outcomes alongside credential reset attempts, MFA approval events, and help desk escalation patterns so the programme measures identity risk, not just awareness completion.
- Extend training beyond annual campaigns Run repeated, scenario-based simulations across the full year and vary them by role, region, and privilege level so behaviour change is reinforced before attackers adapt.
- Harden recovery and support workflows Require stronger verification for password resets, MFA re-enrolment, and delegated access changes because phishing often succeeds by abusing the path around the login screen.
- Use identity signals to target intervention Prioritise coaching, monitoring, and stepped-up verification for users, teams, or regions with persistent susceptibility so the programme focuses on the highest-risk populations first.
Key takeaways
- Phishing remains a live identity threat because attackers exploit human trust to reach credentials, resets, and approval paths.
- Continuous training is more effective than one-off campaigns because behaviour change accumulates over months, not days.
- Identity teams should measure phishing as an assurance problem and harden the workflows attackers abuse after the first click.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AT-1 | The report is about awareness and training as a preventive control. |
| NIST SP 800-53 Rev 5 | AT-2 | AT-2 covers security awareness training directly relevant to phishing resistance. |
Use PR.AT-1 to assess whether phishing education is sustained and role-based, not a one-time exercise.
Key terms
- Phish-prone percentage: Phish-prone percentage measures the share of users who click or otherwise respond incorrectly during simulated phishing tests. It is a behavioural metric that helps security teams baseline susceptibility, target training, and track whether awareness efforts are improving real-world judgment over time.
- Security Awareness: A programme that teaches people how to recognise and respond to common security risks. In identity security, awareness is only useful when it changes behaviour around authentication, verification, reporting, and safe handling of access requests. Message repetition alone does not create measurable risk reduction.
- Identity Assurance: The confidence an organisation has that a person or system is truly who it claims to be before access or action is granted. In modern IAM, assurance depends on evidence quality, channel trust, and the strength of verification around high-risk decisions.
- Trust Exploitation: Trust exploitation is the abuse of legitimate-looking communication, process, or authority to make a user or operator take an unsafe action. It is central to phishing, and it often succeeds when technical controls are sound but the human or procedural validation step is weak.
What's in the full report
KnowBe4's full report covers the operational detail this post intentionally leaves for the source:
- Industry-by-industry PPP benchmarks across 19 sectors, four organisation sizes, and seven regions.
- Regional breakdowns that let teams compare susceptibility against peers in Africa, Europe, North America, and other geographies.
- Guidance on building a continuous security awareness programme and tailoring training with AI.
- The underlying benchmarking context behind the 17.1% increase in phishing attacks since the second half of 2025.
Deepen your knowledge
NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, identity lifecycle, and secrets management. It helps security practitioners connect identity controls to the broader access risks that affect their programmes.
Published by the NHIMG editorial team on August 1, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org