惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

GbyAI
GbyAI
Google DeepMind News
Google DeepMind News
爱范儿
爱范儿
Cloudbric
Cloudbric
TaoSecurity Blog
TaoSecurity Blog
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
V2EX - 技术
V2EX - 技术
云风的 BLOG
云风的 BLOG
O
OpenAI News
Recent Commits to openclaw:main
Recent Commits to openclaw:main
博客园_首页
A
Arctic Wolf
PCI Perspectives
PCI Perspectives
Hacker News: Ask HN
Hacker News: Ask HN
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
人人都是产品经理
人人都是产品经理
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
Engineering at Meta
Engineering at Meta
Scott Helme
Scott Helme
Blog — PlanetScale
Blog — PlanetScale
T
Tailwind CSS Blog
罗磊的独立博客
量子位
SecWiki News
SecWiki News
Recent Announcements
Recent Announcements
阮一峰的网络日志
阮一峰的网络日志
H
Hacker News: Front Page
G
Google Developers Blog
K
Kaspersky official blog
Recorded Future
Recorded Future
Project Zero
Project Zero
Webroot Blog
Webroot Blog
W
WeLiveSecurity
D
Docker
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
C
CERT Recently Published Vulnerability Notes
C
Cybersecurity and Infrastructure Security Agency CISA
Google DeepMind News
Google DeepMind News
T
Troy Hunt's Blog
V
Visual Studio Blog
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
T
Tor Project blog
I
InfoQ
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
L
Lohrmann on Cybersecurity
C
CXSECURITY Database RSS Feed - CXSecurity.com
Cyberwarzone
Cyberwarzone
www.infosecurity-magazine.com
www.infosecurity-magazine.com
The Register - Security
The Register - Security
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC

Human Risk Management Blog

Beyond the Checkbox: How a Proactive Partnership Led to Turnkey Hazing Compliance Trust, Verify, Protect: Modernizing Email Security for the Cloud Report: Social Engineering Remains a Central Part of AI-assisted Attacks ClickFix Social Engineering is Now the Leading Malware Delivery Method CyberheistNews Vol 16 #28 Your 2026 Phishing by Industry Benchmarks: The Findings on Human Risk Scammers Can Use AI Tools to Pinpoint Your Location Based on a Photo Report: Attackers Are Using AI to Automate Social Engineering Your KnowBe4 Fresh Compliance Plus Content Updates from June 2026 From Awareness to Digital Workforce Security Your KnowBe4 Fresh Content Updates from June 2026 Threat Actor Uses Phishing to Breach Orgs for Ransomware Gangs Invoice Phishing Attacks Are Abusing the Shop App Phishing Campaign Impersonates Interpol to Deliver Ransomware Prompt Injection and the Rise of Agentic Risk Hyper-Targeted Social Engineering Needs Real-Time Video Response Your Email is Protected. Is Your Teams Chat? CyberheistNews Vol 16 #27 [HOW TO] Your Cybersecurity Starts at Home on World Social Media Day Static DLP Is Leaving You in the Dark: Why It’s Time for Intelligent, Self-Serve Outbound DLP and Misdirected Content Analysis INC Ransomware Gang Targets the Legal Sector 5 Essential Cybersecurity Defenses for Cloud Email Security Cybercriminals Are Targeting the FIFA World Cup 2026 Why Bite-Sized Security Awareness Training Matters in an Age of TikTok and Digital Distraction Happy 3rd Birthday to Our KnowBe4 Community! Phishing Exposes Employee Data at 86% of Fortune 100 Companies Shadow AI Is Not Shadow IT With a Better Marketing Budget CyberheistNews Vol 16 #26 A New Extortion Scam Uses IT Impersonation to Breach Organizations Cybersecurity Starts At Home This World Social Media Day FTC Report: Americans Lost $3.5 Billion to Imposter Scams Last Year Report: Device Code Phishing is Surging Report: Online Shoppers Increasingly Ignore Scam Warning Signs Security Training Needs Google Maps, Not Christopher Columbus Turn Account Takeover Into Real-Time Security Coaching Extortion Gang Sends In-Person Attackers to Exfiltrate Data Attackers aren’t loyal to any collaboration channel CyberheistNews Vol 16 #25 [The AI Tell] How To Expose Machine-Written Phishing Fast Social Engineering Attacks Abuse Workplace Collaboration Tools New Extortion Brand Uses IT Impersonation to Breach Organizations APWG Report: Social Media Phishing is Surging Cybersecurity Awareness Training for AI: Key Focus Areas Americans Lost $900 Million to AI-Powered Scams Last Year What AI Can’t Hide When It Writes a Phishing Email Your AI Agents Are Eager to Please And Easy to Exploit From 1% to 26%: How AIDA Orchestration Fixes the Remedial Training Gap Best AI Agent Security Tools for SMB and Enterprise in 2026 4 Hot Summer Travel Tips To Avoid Scams CyberheistNews Vol 16 #24 [FBI Alert] Lock Down Your Microsoft 365 Device Code Flows Now The Role of Agentic AI in Phishing Security Training A Credit Score for Cyber Behavior Agentic AI Security in 2026: What to Know How to Secure AI Agents: 4 Best Practices An Overview of Email Compliance Regulations and Reporting Report: AI-Assisted Fraud is Surging Attackers Use Spoofed ChatGPT Site to Deliver Malware I Love Device-Bound Session Credentials, But They Are Still Phishable and Hackable Nearly Two-Thirds of CEOs Cite Cyberattacks as Their Top Concern A Look at Spam vs. Phishing: 4 Key Differences KnowBe4 Wins Multiple 2026 TrustRadius Top Rated Awards Cyber Insurance for Mid‑Market Organizations in Southeast Asia KnowBe4 Earns Multiple 2026 Buyer's Choice Awards from TrustRadius The New Frontier: Securing Japan’s Hybrid Digital Workforce (2026 & Beyond) CyberheistNews Vol 16 #23 Now Phishing Attacks Use Real Hotel Reservations to Target Travelers Report: AI-Enabled Social Engineering Attacks Are on the Rise Your KnowBe4 Fresh Compliance Plus Content Updates from May 2026 FBI: Kali365 Phishing Kit is Targeting Microsoft 365 Accounts KB4-CON - AI Is Everything How to Secure AI Adoption In Your Organization Your KnowBe4 Fresh Content Updates from May 2026 The Silent Invitation: A Deep Dive into Calendar Invite Phishing Cyber Insurance for Mid‑Market Organizations in Southeast Asia Chinese-Language Phishing Kits Are Growing More Advanced Phishing Attacks Are Using Real Hotel Reservation Info to Target Travelers Warning: Scammers are Exploiting Geopolitical Unrest Athletes Are Increasingly Targeted by Social Engineering Attacks AI Agent Governance Part 3 - Runtime Governance: The Hidden Performance Cost of Agentic AI AI Agent Governance Part 2 - What Good Looks Like: Governing AI Agents in Practice 8 Ways to Reduce False Positives in Email Security Ransomware Attacks Drive a Surge in Cyber Insurance Claims My Favorite 5 KnowBe4 Agents Perry Carpenter KB4-CON 2026 Q&A: Deepfakes & Deception Free Gift Fallacy: How Attackers Harvest Credit Cards via Fake Surveys When Global Conflict Becomes a Cyber Weapon: How Iran Tensions and Other Stressful Events Fuel Social Engineering Attacks CyberheistNews Vol 16 #21 [Heads Up] GitHub Breach Shows Developer Tools Are Social Engineering Targets Alert: Extortion Groups Are Using Phishing Kits to Automate Their Attacks Beyond the Chatbot: Why Your AI Agents are Your Newest (and Most Vulnerable) Colleagues Report: Adversarial Use of AI is Evolving
2026 Phishing by Industry Benchmarking Report: Findings on Human Risk
KnowBe4 Team · 2026-07-07 · via Human Risk Management Blog

Every year, KnowBe4 analyzes millions of simulated phishing tests to measure one thing: how likely is your workforce to fall for a phishing attack? The results, published in the 2026 Phishing by Industry Benchmarking Report, paint a clear picture of where human risk concentrates — and what organizations can do about it.

Here are the key findings security leaders need to know.

One in Three Employees Is Vulnerable Before Training

Before any security awareness training is introduced, the global average Phish-prone Percentage (PPP) stands at 33.2%. That means if a real phishing email bypasses your technical filters today, roughly one in three of your employees is likely to engage with it. For large enterprises with 10,000 or more employees, that figure rises to 39.5% — and in large healthcare environments, it peaks at a staggering 54%.

The Same Industries Keep Appearing at the Top of the Risk Table

For the second consecutive year, Healthcare & Pharmaceuticals (42.7%), Insurance (38.1%), and Retail & Wholesale (36%) are the three most vulnerable industries at baseline. The consistency of this finding is itself significant. These sectors are not struggling because of a bad year — they face systemic targeting and structural vulnerabilities that require long-term, sustained intervention rather than a one-time fix.

Size Amplifies Risk

The data reveals a direct correlation between workforce size and phishing susceptibility. Small organizations with fewer than 250 employees start at a 24.7% baseline PPP. That figure climbs steadily through mid-sized organizations and reaches 39.5% for enterprises with more than 10,000 employees. Larger organizations present a wider attack surface, more complex communication environments and a weaker shared sense of security responsibility — all factors that make the human layer harder to protect without a formal, ongoing training program.

Security Training Works — But the Timeline Matters

The most compelling story in this year's data is not how bad the baseline numbers are. It is how dramatically they improve with consistent training.

Within 90 days of introducing security awareness training, the global average PPP drops 40%, falling from 33.2% to 20.1%. That is a meaningful early win — but it is only the beginning. After 12 months of continuous testing and training, the average PPP falls to just 4.2%, representing an 87% reduction from baseline. After 24 months, it stabilizes at 3.9%.

The practical implication is clear: the 90-day mark is not the finish line. The most significant behavioral change happens between month three and month twelve. Organizations that treat their first training campaign as a complete program are leaving the majority of the risk reduction on the table.

The Regional Picture

The 2026 report extends beyond global averages to benchmark phishing risk across seven regions. Africa records the highest baseline PPP at 35.9% and the highest residual risk after a year of training at 7.4% — roughly 70% above the global average at the one-year mark. South America, by contrast, achieves the lowest one-year regional PPP at 3.3%, while North America sits at 4.0%.

The regional data reinforces a finding that holds everywhere: sustained training closes the gap regardless of starting point. But organizations in higher-risk regions need more reinforcement cycles, not just more volume, to reach the residual risk levels that the best-performing regions achieve.

The AI Factor

This year's report introduces an important forward-looking dimension. Generative AI is lowering the cost and increasing the sophistication of phishing attacks globally, enabling threat actors to produce highly personalized, culturally convincing lures at scale. Generic awareness training is no longer sufficient. The organizations showing the strongest results are those using AI-powered training platforms that adapt to individual employee risk profiles, synchronize with emerging threat tactics in real time and move beyond annual compliance exercises toward continuous behavioral conditioning.

What This Means for Security Leaders

The data makes a straightforward case. Human risk is measurable, and it responds predictably to consistent investment. An 87% reduction in phishing susceptibility over 12 months is not an outlier — it is the average. The organizations that achieve it are not doing anything extraordinary. They are running structured, continuous awareness programs and measuring the results.

Additionally, as organizations expand beyond human employees to include AI agents, the attacks surface grows in ways that traditional controls were not designed to address. Security awareness training is not only the most effective lever for reducing human risk, it is the foundation for building the security culture and organizational vigilance required to manage the risk introduced by an AI-augmented workforce. 

The 2026 Phishing by Industry Benchmarking Report gives security leaders the industry-specific benchmarks, regional context and organizational size data needed to assess where they stand and build the case for sustained action.

Download the full report to see where your industry ranks.