TL;DR: A global pre-training Phish-prone Percentage of 33.2% is found in a 2026 benchmarking report, with continuous security awareness training reducing susceptibility by 87% to 4.2% over a year, according to Knowbe4. The governance lesson is that behavioural risk decays slowly, so identity and access programmes need sustained controls, not campaign-based awareness, and the report notes a 17.1% increase in phishing attacks since the second half of 2025.
NHIMG editorial — based on content published by KnowBe4: 2026 Phishing by Industry Benchmarking Report
By the numbers:
- Before any security awareness training, the global average Phish-prone Percentage (PPP) stands at 33.2%.
- Organizations that commit to a full year of continuous security awareness training reduce their PPP by an average of 87%, bringing average susceptibility down to just 4.2%.
- The 2026 KnowBe4 report shows a 17.1% increase in phishing attacks since the second half of 2025.
Questions worth separating out
Q: How should security teams reduce phishing risk without relying only on awareness training?
A: They should combine user training with behavioural detection, vendor verification, and tighter controls on high-risk identity actions.
Q: When does phishing-resistant MFA still leave identity risk unresolved?
A: It leaves risk unresolved when recovery, reset, or session revocation paths remain weak.
Q: What do security teams get wrong about phishing awareness training?
A: They often treat training as a replacement for technical containment.
Practitioner guidance
- Instrument phishing as an identity-risk control Track phishing test outcomes alongside credential reset attempts, MFA approval events, and help desk escalation patterns so the programme measures identity risk, not just awareness completion.
- Extend training beyond annual campaigns Run repeated, scenario-based simulations across the full year and vary them by role, region, and privilege level so behaviour change is reinforced before attackers adapt.
- Harden recovery and support workflows Require stronger verification for password resets, MFA re-enrolment, and delegated access changes because phishing often succeeds by abusing the path around the login screen.
What's in the full report
KnowBe4's full report covers the operational detail this post intentionally leaves for the source:
- Industry-by-industry PPP benchmarks across 19 sectors, four organisation sizes, and seven regions.
- Regional breakdowns that let teams compare susceptibility against peers in Africa, Europe, North America, and other geographies.
- Guidance on building a continuous security awareness programme and tailoring training with AI.
- The underlying benchmarking context behind the 17.1% increase in phishing attacks since the second half of 2025.
👉 Read KnowBe4's 2026 Phishing by Industry Benchmarking Report →
Phishing susceptibility and continuous training: what changes for IAM teams?
Explore further
Phishing is now an identity assurance problem, not a communications problem. The report’s 33.2% pre-training susceptibility figure shows that a large share of users will still interact with malicious content before any remediation begins. That means identity programmes cannot rely on a single awareness layer to protect authentication, recovery, and delegation workflows. The governance gap is not lack of information, but lack of repeated verification at the point of human decision.
A question worth separating out:
Q: Who is accountable when phishing leads to customer fraud and account takeover?
A: Accountability is shared across identity, fraud, and application owners because the attack crosses authentication, session handling, and transaction risk. The security programme should define who owns lookalike domain detection, who owns session abuse detection, and who decides when to step up or block access after suspicious login behaviour is detected.
👉 Read our full editorial: Phishing susceptibility stays high until training becomes continuous