Business Wire

FL-KNOWBE4

4.6.2024 19:45:32 CEST | Business Wire | Press release

Share
KnowBe4’s Annual Phishing Benchmarking Report Shows Focusing on the Human Element Still the Best Safeguard Against Cyber Threats

KnowBe4, the provider of the world’s largest security awareness training and simulated phishing platform, today released its new 2024 Phishing by Industry Benchmarking Report to measure an organization’s Phish-prone™ Percentage (PPP), which indicates how many of their employees are likely to fall for phishing or social engineering scams.

This year’s report shows that according to baseline testing conducted across all industries, without security awareness training, 34.3% of employees are likely to click on malicious links or comply with fraudulent requests. This is an increase of over one percent in comparison to the 2023 report and highlights the importance of building a strong security culture within organizations to mitigate the human risk that exists when safeguarding against cyber threats.

KnowBe4 analyzed over 54 million simulated phishing tests across more than 11.9 million users from 55,675 organizations in 19 different industries. The resulting baseline PPP measures the percentage of employees in organizations that had not conducted any KnowBe4 security training, who clicked a simulated phishing email link or opened an infected attachment during testing.

The report highlights a key fact: when simulated phishing security testing is integrated with security awareness training, it works. Organizations that commit to regular security awareness training and testing after the initial baseline test saw an average PPP drop to just 18.9% within 90 days. After 12 months of continuous training and testing, the PPP plummeted even further to 4.6%. These results show that to transform cybersecurity culture, existing habits first need to be broken to make way for more secure ones. As employees start to embrace new behaviors, they become habits, over time evolving into standard practices that shape organizational culture and, in turn, creating a workforce that instinctively makes security a priority in their day-to-day work.

Industries particularly vulnerable to cyber threats, scoring the highest PPP, and in dire need of security awareness training are also discussed in the report. The healthcare and pharmaceutical industry remains in the high-risk category with the highest PPP across small- and large-sized organizations scoring 34.7% and 51.4%, respectively. Across medium-sized organizations, the hospitality industry took top billing for the second time in three years with a score of 39.7%.

This report reinforces the crucial role the human element plays in cybersecurity. Although technology is important for preventing and recovering from cyberattacks, human error is still a big contributing factor to data breaches. In fact, according to Verizon's 2024 Data Breach Investigations report, 68% of data breaches were due to accidental actions, the use of stolen credentials, social engineering and malicious privilege misuse. Even though this is an improvement from last year’s 74%, organizations must continue to focus on strengthening the human firewall to safeguard against cyber threats.

An emerging threat vector highlighted in this year’s report is the rapid adoption of AI in certain industries which presents additional risks if not implemented with strong cybersecurity measures.

"The data does not lie; regular and focused security training reshapes how employees interact with potential threats. Our goals are to educate and change behaviors, for employees to instinctively put security first," says Stu Sjouwerman, CEO of KnowBe4. "Furthermore, we are seeing more sophisticated cyber threats emerge because of AI and the need for training is imperative.”

This year’s report also examines international phishing benchmarks from North America, South America, Europe, United Kingdom & Ireland, Africa, Asia, Australia and New Zealand.

To download a copy of the 2024 KnowBe4 Phishing by Industry Benchmarking Report, click here.

About KnowBe4

KnowBe4, the provider of the world’s largest security awareness training and simulated phishing platform, is used by more than 65,000 organizations around the globe. Founded by IT and data security specialist Stu Sjouwerman, KnowBe4 helps organizations address the human element of security by raising awareness about ransomware, CEO fraud and other social engineering tactics through a new-school approach to awareness training on security. The late Kevin Mitnick, who was an internationally recognized cybersecurity specialist and KnowBe4’s Chief Hacking Officer, helped design the KnowBe4 training based on his well-documented social engineering tactics. Organizations rely on KnowBe4 to mobilize their end users as their last line of defense and trust the KnowBe4 platform to strengthen their security culture and reduce human risk.

To view this piece of content from cts.businesswire.com, please give your consent at the top of this page.

View source version on businesswire.com: https://www.businesswire.com/news/home/20240604089157/en/

About Business Wire

Business Wire
Business Wire
101 California Street, 20th Floor
CA 94111 San Francisco

http://businesswire.com
DK

Subscribe to releases from Business Wire

Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.

Latest releases from Business Wire

NTT DATA Signs Strategic Collaboration Agreement with AWS to Accelerate Enterprise Cloud and Agentic AI Adoption29.1.2026 14:00:00 CET | Press release

NTT DATA, a global leader in AI, digital business and technology services, today announced a multi-year Strategic Collaboration Agreement (SCA) with Amazon Web Services (AWS) to help enterprises modernize legacy systems, adopt agentic AI responsibly and scale innovation across industries. Combining NTT DATA’s expertise in cloud transformation, cloud-native modernization and Agentic AI with the scale and innovation velocity of AWS services, the collaboration will deliver tailored enterprise solutions that modernize mission-critical workloads, build secure cloud foundations and drive measurable business outcomes across regulated and high-growth industries. Under the agreement, NTT DATA and AWS will accelerate enterprise transformation in four priority areas: AI-driven large-scale cloud transformation: Accelerating the migration and modernization of on-premises workloads on AWS, leveraging generative and agentic AI, automation and data platforms to unlock new business models and drive int

U.S. Department of Energy and Kyoto Fusioneering Launch Strategic Partnership to Build Critical Fusion Infrastructure and Accelerate Deployment of Commercial Fusion Power29.1.2026 14:00:00 CET | Press release

Today, the U.S. Department of Energy (DOE) and Kyoto Fusioneering (KF) established a landmark partnership to deliver critical fusion infrastructure and perform collaborative R&D to drive down technology and commercialization risk. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260127164854/en/ Anchored by a new public-private partnership between KF and Oak Ridge National Laboratory (ORNL) that leverages each institution’s expertise in fusion technology to develop world-leading fusion test facilities and technology, this agreement establishes a new paradigm in U.S.-Japan allied cooperation and public-private partnership towards accelerating the deployment of commercial fusion power. Under the new partnership, KF and ORNL will commence joint research and development activities focused on fusion breeding blanket systems, a critical technology for producing the tritium fuel needed to sustain fusion power generation. This include

Esri Earns ISO Certification, Reinforcing Commitment to Data Security29.1.2026 14:00:00 CET | Press release

International Standard Ensures ArcGIS Readiness to Protect Information, Compliance Across Industries Esri, the global leader in location intelligence, has received ISO/IEC 27001:2022 certification. This certification enables Esri's ArcGIS users to meet data residency and local regulatory requirements and ensures that Esri’s security practices comply with the requirements set by the International Organization for Standardization (ISO). ISO/IEC 27001:2022 certification provides a globally recognized framework for establishing, implementing, maintaining, and continually improving an information security management system. Esri's certification demonstrates that its system preserves the confidentiality, integrity, and availability of the platforms, services, and applications used to process, transmit, and store customer assets. "As enterprises simultaneously navigate escalating cyber threats and complex data residency regulations, our certification provides critical assurance that we mainta

Dreamstime Adds Ten More Language Versions, Reaching 23 in Total29.1.2026 13:00:00 CET | Press release

Dreamstime, the world’s largest stock photography community, announced today the addition of new language versions—Czech, Japanese, Korean, Hindi, Turkish, Indonesian, Danish, and Norwegian—to expand its global reach and provide a more comprehensive digital experience worldwide. Hebrew and Arabic will be launched next. Key Takeaways: Dreamstime expands into 23 languages, increasing global reach and accessibility. AI-powered translation improves search relevance, onboarding, and cultural discovery. With billions of new pages and coverage in almost every country worldwide in native, official, or very popular languages, this is Dreamstime’s most prolific launch in its 25-year history. The platform already operates in 13 languages: English, French, Polish, Italian, Spanish, Portuguese, Dutch, Russian, Greek, Chinese, Swedish, German, and Romanian. With a stock photography collection of over 350 million files and millions of new items added monthly, Dreamstime manages a constantly growing d

NIQ Launches Breakthrough Framework That Exposes Billions Lost to the Say–Do Gap29.1.2026 13:00:00 CET | Press release

The new global framework quantifies the disconnect between consumer intent and real‑world buying behavior, unlocking powerful paths to reclaim volume and fuel growth NielsenIQ (NYSE: NIQ) today announced the launch of its Say–Do Gap Measurement Framework, an innovative behavioral metric set to transform how brands and retailers understand modern consumers and navigate a pressing challenge: consumers who say one thing but buy another. With economic uncertainty, shifting priorities, and increasingly value‑driven decision-making changing consumer habits, this growing disconnect has cost the industry more than 13 billion unit sales over the past five years—losses many companies can no longer afford to overlook. By unifying deep attitudinal insights with verified purchase data across 25+ global markets, the Say–Do Framework bridges this gap and exposes where brands are losing momentum, where unmet demand is hiding, and where opportunity is silently compounding. Brands and retailers can now

In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.

Visit our pressroom
World GlobeA line styled icon from Orion Icon Library.HiddenA line styled icon from Orion Icon Library.Eye