
Phishing Report Highlights Value of Building a Security Culture
While cybersecurity groups have actually invested heavily in e-mail security, endpoint security, and identity controls, brand-new research study from Fortra suggests one difficulty stays difficult to solve: users.
The business’s 2025 Phishing Simulation Criteria Report evaluated 14 million simulated phishing receivers throughout more than 7,500 campaigns to analyze workers’ reactions to phishing attempts.
The findings highlight a relentless obstacle for security groups: Attackers continue to target people because jeopardized accounts can supply direct access to enterprise environments.
Throughout the simulations evaluated, Fortra found a 5.42% click rate and a 1.99% password submission rate, revealing that convincing phishing efforts can still encourage users to interact with destructive material.
The report also found that phishing reporting remains an obstacle. Only 10.5% of users reported simulated phishing e-mails, suggesting many potential risks could go unnoticed without additional security controls.
The findings enhance why identity security has become main to modern-day defense strategies.
As companies move more applications and data into cloud environments, taken qualifications can offer enemies with a course into delicate systems without requiring malware or standard exploits.
Multifactor authentication, conditional gain access to policies, user training and identity monitoring can all help in reducing risk, but Fortra’s research recommends innovation alone is not enough.
The report argues that phishing defense requires organizations to treat staff members as part of the security boundary– not simply as possible victims.
“The contemporary phishing ecosystem is no longer specified by isolated frauds, but by quickly developing criminal platforms that continually adjust to protective enhancements,” Fortra stated.
The challenge is clear: Obstructing phishing attacks needs more than more powerful e-mail filters. It requires developing a security culture where users recognize threats, report suspicious activity and end up being another layer of defense.
The full report is readily available here on the Fortra website.