Business Wire

FL-KNOWBE4

Share
KnowBe4’s Annual Phishing Benchmarking Report Shows Focusing on the Human Element Still the Best Safeguard Against Cyber Threats

KnowBe4, the provider of the world’s largest security awareness training and simulated phishing platform, today released its new 2024 Phishing by Industry Benchmarking Report to measure an organization’s Phish-prone™ Percentage (PPP), which indicates how many of their employees are likely to fall for phishing or social engineering scams.

This year’s report shows that according to baseline testing conducted across all industries, without security awareness training, 34.3% of employees are likely to click on malicious links or comply with fraudulent requests. This is an increase of over one percent in comparison to the 2023 report and highlights the importance of building a strong security culture within organizations to mitigate the human risk that exists when safeguarding against cyber threats.

KnowBe4 analyzed over 54 million simulated phishing tests across more than 11.9 million users from 55,675 organizations in 19 different industries. The resulting baseline PPP measures the percentage of employees in organizations that had not conducted any KnowBe4 security training, who clicked a simulated phishing email link or opened an infected attachment during testing.

The report highlights a key fact: when simulated phishing security testing is integrated with security awareness training, it works. Organizations that commit to regular security awareness training and testing after the initial baseline test saw an average PPP drop to just 18.9% within 90 days. After 12 months of continuous training and testing, the PPP plummeted even further to 4.6%. These results show that to transform cybersecurity culture, existing habits first need to be broken to make way for more secure ones. As employees start to embrace new behaviors, they become habits, over time evolving into standard practices that shape organizational culture and, in turn, creating a workforce that instinctively makes security a priority in their day-to-day work.

Industries particularly vulnerable to cyber threats, scoring the highest PPP, and in dire need of security awareness training are also discussed in the report. The healthcare and pharmaceutical industry remains in the high-risk category with the highest PPP across small- and large-sized organizations scoring 34.7% and 51.4%, respectively. Across medium-sized organizations, the hospitality industry took top billing for the second time in three years with a score of 39.7%.

This report reinforces the crucial role the human element plays in cybersecurity. Although technology is important for preventing and recovering from cyberattacks, human error is still a big contributing factor to data breaches. In fact, according to Verizon's 2024 Data Breach Investigations report, 68% of data breaches were due to accidental actions, the use of stolen credentials, social engineering and malicious privilege misuse. Even though this is an improvement from last year’s 74%, organizations must continue to focus on strengthening the human firewall to safeguard against cyber threats.

An emerging threat vector highlighted in this year’s report is the rapid adoption of AI in certain industries which presents additional risks if not implemented with strong cybersecurity measures.

"The data does not lie; regular and focused security training reshapes how employees interact with potential threats. Our goals are to educate and change behaviors, for employees to instinctively put security first," says Stu Sjouwerman, CEO of KnowBe4. "Furthermore, we are seeing more sophisticated cyber threats emerge because of AI and the need for training is imperative.”

This year’s report also examines international phishing benchmarks from North America, South America, Europe, United Kingdom & Ireland, Africa, Asia, Australia and New Zealand.

To download a copy of the 2024 KnowBe4 Phishing by Industry Benchmarking Report, click here.

About KnowBe4

KnowBe4, the provider of the world’s largest security awareness training and simulated phishing platform, is used by more than 65,000 organizations around the globe. Founded by IT and data security specialist Stu Sjouwerman, KnowBe4 helps organizations address the human element of security by raising awareness about ransomware, CEO fraud and other social engineering tactics through a new-school approach to awareness training on security. The late Kevin Mitnick, who was an internationally recognized cybersecurity specialist and KnowBe4’s Chief Hacking Officer, helped design the KnowBe4 training based on his well-documented social engineering tactics. Organizations rely on KnowBe4 to mobilize their end users as their last line of defense and trust the KnowBe4 platform to strengthen their security culture and reduce human risk.

To view this piece of content from cts.businesswire.com, please give your consent at the top of this page.

View source version on businesswire.com: https://www.businesswire.com/news/home/20240604089157/en/

About Business Wire

Business Wire
Business Wire
101 California Street, 20th Floor
CA 94111 San Francisco

http://businesswire.com
DK

Subscribe to releases from Business Wire

Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.

Latest releases from Business Wire

Galderma Announces First Patient Enrollment in Study to Assess Nemolizumab in Adults With Chronic Pruritus of Unknown Origin11.12.2025 07:00:00 CET | Press release

Chronic Pruritus of Unknown Origin (CPUO) is characterized by a persistent, chronic itch with an unknown cause and is associated with very high burden of disease due to severe itch, sleep deprivation and mental distress1 Galderma’s phase II study builds on emerging research that reinforces the role of IL-31 – a neuroimmune cytokine that is involved in driving itch – in CPUO1 Nemolizumab is a monoclonal antibody that specifically targets the IL-31 receptor alpha, inhibiting the signaling of IL-312 It is approved by multiple regulatory authorities for the treatment of moderate-to-severe atopic dermatitis and prurigo nodularis – conditions in which IL-31 plays a key role in driving itch, inflammation, epidermal dysregulation, and, in prurigo nodularis, fibrosis2-6 Galderma (SIX: GALD), the pure-play dermatology category leader, today announced the first patient enrollment for its phase II study investigating the efficacy and safety of nemolizumab in treating patients living with Chronic P

Ant International and HSBC Test New Cross-Border Payments Solution Using Tokenised Deposits on Swift’s Network and Powered by ISO 2002211.12.2025 04:00:00 CET | Press release

ISO 20022-enabled solution allows blockchain interoperability on Swift’s network, using Ant International’s technology and HSBC’s Tokenised Deposit Service Integration with Swift’s network extends AML and anti-fraud capabilities to tokenised deposits transactions Proof of concept (POC) marks a step towards enabling seamless money movement across borders Ant International, HSBC and Swift today have completed a successful Proof of Concept (POC) for the cross-border transfer of tokenised deposits using ISO 20022 standards. The initiative leverages Swift’s global messaging network and HSBC’s recently launched Tokenised Deposit Service, combined with Ant International’s blockchain technology. The POC marks a key milestone in Ant International, HSBC, and Swift’s efforts to help businesses unlock the full benefits of tokenisation for enhanced liquidity, programmable finance, and 24/7 real-time settlement. As part of this initiative, Ant International and HSBC successfully integrated Ant Inter

Andersen Consulting styrker sit udbud af cybersikkerhed med tilføjelsen af S-RM11.12.2025 00:05:00 CET | Pressemeddelelse

Andersen Consulting indgår en samarbejdsaftale med S‑RM, en global efterretnings- og cybersikkerhedsvirksomhed, og styrker dermed sin evne til at understøtte globale kunder med risikostyring, hændelsesrespons og strategisk rådgivning. S-RM har hovedsæde i Storbritannien og leverer integrerede ydelser, der spænder over cyberrådgivning, digital efterforskning, hændelseshåndtering, virksomhedsefterretning og due diligence i forbindelse med transaktioner. Firmaet betjener family offices, kapitalfonde, Fortune 500-virksomheder og mellemstore virksomheder inden for bl.a. finans-, olie- og sundhedssektoren, og tilbyder praktisk cybersikkerhedsstyring samt tilpassede risikoplatforme. Med døgnåben hændelseshåndtering og dybdegående efterforskningsekspertise hjælper S-RM organisationer med at styrke deres modstandsdygtighed og træffe informerede beslutninger i komplekse miljøer. "I en tid, hvor trusler konstant udvikler sig, skal organisationer være proaktive, ikke reaktive," udtaler Heyrick Bon

Canva Unveils 2026 Design Trends: The Year of ‘Imperfect by Design’10.12.2025 23:52:00 CET | Press release

Canva’s third annual Design Trends Report uncovers insights from millions of Canva users and billions of designs to predict the must-know visual trends for creators and brands in 2026.90% surge in DIY-inspired searches, reflecting a shift toward raw, personal, and imperfect design.85% increase in searches for Zine and Substack inspired layouts as creators gravitate toward editorial style storytelling.80% of creators say 2026 is the year to regain creative control, embracing AI as a partner while prioritizing styles that feel human.54% growth in searches for clean layouts and simple branding as audiences gravitate toward pared back styles.527% surge in lo-fi aesthetic searches in favor of nostalgia driven, emotionally expressive visuals.220% jump in searches for “liminal” and “uncanny” content as lines between real and surreal blur. Canva, the world’s leading all-in-one visual communication platform, today unveiled its third annual Design Trends Report with bold predictions for creativi

Audiencerate Achieves Google Customer Match Partner Status, strengthening its role as a Global Data Provider10.12.2025 22:40:00 CET | Press release

Audiencerate, an international technology company specializing in data activation solutions and platforms within the AdTech and MarTech sectors, has been officially awarded by Google as a Customer Match Upload Partner. This certification is granted to a restricted number of global operators (https://support.google.com/google-ads/answer/7361372?hl=en) authorized to manage and onboard first-party data into the Google Ads and DV360 ecosystem. The company strengthen its strategic partnership with Google by adding the Customer Match Upload Partner accreditation to its existing status as a certified Google Data Provider. This new credential enables Audiencerate to seamlessly integrate proprietary audience segments and data into Google’s advertising platforms. The combination of these two accreditations represents an exceptionalsituation in the international landscape and solidifies Audiencerate's position in the digital advertising market, which is increasingly reliant on first-party data. T

In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.

Visit our pressroom
World GlobeA line styled icon from Orion Icon Library.HiddenA line styled icon from Orion Icon Library.Eye