
Key Takeaways
- A phishing simulation sends a fake attack to your own staff and records who clicks. Most agencies then spend the debrief on the least useful number it produces.
- Report rate tells you whether your agency would spot a real attack, while click rate tells you very little on its own.
- The minutes between the first click and the first warning are your containment window, and a gap measured in hours points to a problem in the reporting process.
- A click rate is not a breach probability, and it has to stay out of performance records, because reporting stops the moment staff think a click might appear there.
- The useful meeting after a simulation includes whoever owns the affected workflow, and it ends with a change to a process.
On a Tuesday morning, your security team sends a fake phishing email to everyone in the agency. The exercise is a controlled test, run with approval, and nothing in the message is real. By Thursday, the results are on a director's desk: 37% of staff clicked.
What happens next is predictable. The first conversation is about blame. It is conducted politely, with words like "awareness" and "accountability" doing the work. The second is about training completion, and it ends with a course assigned to everyone, most of whom did nothing wrong.
Both conversations treat that 37% as a verdict on the people who work there. In a government agency, that reading is especially unfair, because a click rate has more to do with how the organization is set up than with how careful anyone happened to be that morning.
Read the same report as a diagnosis instead, and it will tell you 4 things about how your agency works, each of which you can do something about.
Why the Click Rate Misleads in Government
Agency inboxes are built to receive official-looking mail from senders nobody recognizes. Interdepartmental notices, procurement portals, grant systems, and shared-service providers all send that kind of mail. As a result, the usual instinct to ask whether a message looks legitimate has stopped being useful.
Some teams have it harder still. Procurement, HR, records requests, and benefits intake exist precisely to open documents from strangers, so the behavior a simulation appears to punish is the behavior the job requires.
The workforce adds to the difficulty. People stay far longer in public service than elsewhere. According to the US Bureau of Labor Statistics, median tenure in the public sector was 6.2 years in January 2024, compared with 3.5 years in the private sector. Long service builds deep familiarity with how things are normally done, and familiarity is exactly what a convincing message imitates. Someone who has approved the same kind of request for years is unlikely to look twice at a fake one built to match.
The mix of people compounds the problem. Contractors and seasonal staff arrive with partial onboarding and training done elsewhere to a different standard, yet they have the same network access as everyone around them. Field and shift workers may reach their email only once a week, often on a shared terminal, so a suspicious message can sit there unreported for days.
Put those together, and an agency-wide click rate turns out to describe the operating model more than the people inside the agency. That is why the headline number is close to useless on its own, and why the rest of the report deserves more attention than it usually gets.
The 4 Findings About Your Agency
What the report tells you | What you measure | Where the answer lives |
|---|---|---|
Whether you would spot a real attack | Report rate | Your detection capability |
How quickly you could contain it | Time to first report | The reporting path |
Which part of the organization is exposed | Concentration by team, shift, or location | Whoever designed the affected workflow |
How many people you are losing to friction | Staff who noticed and said nothing | Friction in the reporting step |
- Whether you would spot a real attack: Report rate is the share of tested staff who flagged the message to security, and it deserves to lead the debrief. A click is 1 person's bad few seconds, whereas a report is the organization noticing an attack that is still in progress. To see why that matters, picture an agency with a 20% click rate and a 45% report rate, and then picture another sitting at 8% and 3%. The second looks healthier on paper, but it is the one that sees no attack coming, because nothing reaches its security team until something has already broken. Put report rate first, and you stop keeping score of mistakes and start measuring the capability you can build.
- How quickly you could contain it: Time to first report is the gap between the first click and the moment a warning reaches security. Measure it in minutes, because nothing is contained until somebody speaks up. When that gap stretches into hours, what you have learned concerns the reporting path more than the workforce. The causes are usually mundane: the report button is buried, the process demands a form, or people are unsure whether raising a false alarm wastes someone's time. Each of those is cheaper to fix than a training push across the whole organization, and each will do more to move the number.
- Which part of the organization is exposed: Clicks rarely spread evenly across an agency. They gather in 1 department, 1 shift, 1 job family, or 1 location, and every pattern points somewhere specific. A cluster in records requests or benefits intake is the public-facing problem described earlier, now arriving as a number you can act on. A cluster on the night shift is worth reading alongside the support and verification actually available at 2 a.m. A cluster in a single region suggests that local practice has drifted from the standard. In each case, the concentration raises a question about workflow, and the answer sits with whoever designed the process rather than with the people following it.
- How many people you are losing to friction: Some staff open the message, avoid the link, and then say nothing at all. Almost nobody counts them, and they are the quiet waste in most programs. They notice something is wrong and decide it is not worth the trouble of reporting. If reporting means forwarding an email to a mailbox that never replies, that is a reasonable judgment rather than apathy. This is the cheapest group in the agency to convert into reporters, because they have already done the difficult part. All that stands between them and a report is the effort of making one.

What the Results Do Not Mean
This is the part few programs write down, and leaving it out is how they lose credibility in their second year.
A click rate describes 1 behavior, under 1 set of conditions, against 1 message, which means it is not a measure of the probability that your agency will be breached. Treating it as a security score lends the method a precision it does not have.
Nor does a low rate on a single campaign prove much. The template may simply have failed to land that morning, so 1 good result is a data point rather than a verdict. A program built around defending a good number will quietly stop testing anything difficult.
The most important limit is also the easiest to cross. Results have no business in performance management, because the moment staff believe a click will follow them into a review, reporting becomes self-incrimination and stops. You lose the measure that matters most, and no announcement that the policy has changed will bring it back quickly. Trust of that kind is rebuilt across several campaigns, if at all, which is why that rule belongs in writing before the first send rather than after the first uncomfortable result.
Where KC Phishing Fits
Reading a report this way depends on having those numbers in the first place. Some tools record the click without tracking who reported, how fast, where the clusters sit, or who opened the message and neither clicked nor reported.
KC Phishing, KnowledgeCity's security awareness solution, runs the simulation and records the data behind all 4 findings. You build a campaign, choose who receives it, and send it once the authorized-use acknowledgment is recorded. What comes back is a diagnosis instead of a single percentage.
Staff flag a suspicious message by using a 1-click report button or by forwarding it to a monitored reporting mailbox. Each report is tied to the campaign it came from, so report rate is measured directly. Every event, from send to open to click to report, carries a time stamp, so time to first report can be read straight from the campaign timeline. Results break down by department and group instead of collapsing into 1 agency-wide average, so concentration is visible on the day the numbers land. When a staff member does click, a training rule can enroll them in a course or learning path in KC LMS, which turns the follow-up into a next step rather than a scolding email.
See What a Simulation Reports Back
Look at how a phishing simulation is run and what the results show about each department.
Getting a Result Worth Reading
Good instrumentation still needs a program built around it, and 6 habits make most of the difference.
- Announce the program, and keep the campaign dates private: People should know that simulations happen without knowing when the next one lands, because an ambush buys 1 dramatic number at the cost of the trust on which the whole program depends.
- Agree on the metrics before the first send: Write down report rate, time to first report, concentration, and the number who noticed and said nothing, so that nobody can relitigate the measures once an uncomfortable result arrives.
- Run quarterly rather than annually: A single campaign each year produces a snapshot, and every conclusion drawn from it is an anecdote. A quarterly cadence produces a trend, and a trend is what survives a budget conversation.
- Segment from the very first campaign: Concentration stays invisible unless the data is built to reveal it, and retrofitting segmentation later leaves you with no early baseline to compare against.
- Make reporting take 1 click, and acknowledge every report you receive: Someone who reports a genuine invoice has done exactly what you asked of them, so treating that as a nuisance teaches precisely the wrong lesson.
- Send the results to whoever owns the workflow as well as to IT: A cluster in benefits intake is a process finding, and the person who can actually fix it runs benefits intake.
The Right Meeting
Go back to that Tuesday. The page on the director's desk said 37% clicked. Read as a verdict, it produced a meeting about blame and a course assigned to everyone in the building.
Read as a diagnosis, the same page said something far more useful. It showed how many people would have raised the alarm and how long the agency would have taken to hear about the attack. It named the team carrying the exposure. It counted the people who saw something and said nothing.
Every one of those describes how the agency works, and that is the part you can redesign. Training still matters, and the people who clicked should get it. But an agency that responds with training alone is spending on the hardest thing to shift and leaving the 4 easier fixes untouched.
So the meeting worth having has the workflow owner sitting next to the security lead, and it ends with a change to a process. The next campaign will tell you whether the change worked.
Frequently Asked Questions
1. What does a phishing simulation actually measure?
It records who clicked, who reported the message, and how long that report took, against 1 message sent under 1 set of conditions. The click rate is the least useful of those numbers on its own. The 4 findings worth reading are report rate, time to first report, concentration by team or shift or location, and the count of staff who noticed something and said nothing.
2. Why does a click rate mislead in a government agency?
Agency inboxes are built to receive official-looking mail from senders nobody recognizes, through interdepartmental notices, procurement portals, grant systems, and shared-service providers. Procurement, HR, records requests, and benefits intake exist to open documents from strangers, so a simulation appears to punish the behavior the job requires. The US Bureau of Labor Statistics put median public sector tenure at 6.2 years in January 2024 against 3.5 years in the private sector, and that long familiarity is what a convincing message imitates.
3. Is a low click rate better than a high report rate?
An agency at a 20% click rate and a 45% report rate is in better shape than one at 8% and 3%. The second looks healthier on paper and sees no attack coming, because nothing reaches its security team until something has already broken. Report rate measures whether the organization notices an attack still in progress, which is the capability you can build.
4. Should simulation results go into performance reviews?
Results have no business in performance management. The moment staff believe a click will follow them into a review, reporting becomes self-incrimination and stops, which costs you the measure that matters most. Put that rule in writing before the first send, because trust of that kind is rebuilt across several campaigns if it returns at all.
5. How often should an agency run a simulation?
Run them quarterly, because a single campaign each year produces a snapshot and every conclusion drawn from it is an anecdote. A quarterly cadence produces a trend, and a trend is what survives a budget conversation. Segment the data from the first campaign, because concentration stays invisible unless the data is built to reveal it.
References
- US Bureau of Labor Statistics. Employee Tenure in 2024. , September 26, 2024.
- Verizon. Data Breach Investigations Report.
- Cybersecurity and Infrastructure Security Agency. Phishing Guidance: Stopping the Attack Cycle at Phase One. , October 18, 2023.
- Cybersecurity and Infrastructure Security Agency. Cybersecurity Training and Exercises.
- National Institute of Standards and Technology. SP 800-50 Rev. 1, Building a Cybersecurity and Privacy Learning Program, September 2024.