Business Wire

FL-KNOWBE4

Share
KnowBe4’s Annual Phishing Benchmarking Report Shows Focusing on the Human Element Still the Best Safeguard Against Cyber Threats

KnowBe4, the provider of the world’s largest security awareness training and simulated phishing platform, today released its new 2024 Phishing by Industry Benchmarking Report to measure an organization’s Phish-prone™ Percentage (PPP), which indicates how many of their employees are likely to fall for phishing or social engineering scams.

This year’s report shows that according to baseline testing conducted across all industries, without security awareness training, 34.3% of employees are likely to click on malicious links or comply with fraudulent requests. This is an increase of over one percent in comparison to the 2023 report and highlights the importance of building a strong security culture within organizations to mitigate the human risk that exists when safeguarding against cyber threats.

KnowBe4 analyzed over 54 million simulated phishing tests across more than 11.9 million users from 55,675 organizations in 19 different industries. The resulting baseline PPP measures the percentage of employees in organizations that had not conducted any KnowBe4 security training, who clicked a simulated phishing email link or opened an infected attachment during testing.

The report highlights a key fact: when simulated phishing security testing is integrated with security awareness training, it works. Organizations that commit to regular security awareness training and testing after the initial baseline test saw an average PPP drop to just 18.9% within 90 days. After 12 months of continuous training and testing, the PPP plummeted even further to 4.6%. These results show that to transform cybersecurity culture, existing habits first need to be broken to make way for more secure ones. As employees start to embrace new behaviors, they become habits, over time evolving into standard practices that shape organizational culture and, in turn, creating a workforce that instinctively makes security a priority in their day-to-day work.

Industries particularly vulnerable to cyber threats, scoring the highest PPP, and in dire need of security awareness training are also discussed in the report. The healthcare and pharmaceutical industry remains in the high-risk category with the highest PPP across small- and large-sized organizations scoring 34.7% and 51.4%, respectively. Across medium-sized organizations, the hospitality industry took top billing for the second time in three years with a score of 39.7%.

This report reinforces the crucial role the human element plays in cybersecurity. Although technology is important for preventing and recovering from cyberattacks, human error is still a big contributing factor to data breaches. In fact, according to Verizon's 2024 Data Breach Investigations report, 68% of data breaches were due to accidental actions, the use of stolen credentials, social engineering and malicious privilege misuse. Even though this is an improvement from last year’s 74%, organizations must continue to focus on strengthening the human firewall to safeguard against cyber threats.

An emerging threat vector highlighted in this year’s report is the rapid adoption of AI in certain industries which presents additional risks if not implemented with strong cybersecurity measures.

"The data does not lie; regular and focused security training reshapes how employees interact with potential threats. Our goals are to educate and change behaviors, for employees to instinctively put security first," says Stu Sjouwerman, CEO of KnowBe4. "Furthermore, we are seeing more sophisticated cyber threats emerge because of AI and the need for training is imperative.”

This year’s report also examines international phishing benchmarks from North America, South America, Europe, United Kingdom & Ireland, Africa, Asia, Australia and New Zealand.

To download a copy of the 2024 KnowBe4 Phishing by Industry Benchmarking Report, click here.

About KnowBe4

KnowBe4, the provider of the world’s largest security awareness training and simulated phishing platform, is used by more than 65,000 organizations around the globe. Founded by IT and data security specialist Stu Sjouwerman, KnowBe4 helps organizations address the human element of security by raising awareness about ransomware, CEO fraud and other social engineering tactics through a new-school approach to awareness training on security. The late Kevin Mitnick, who was an internationally recognized cybersecurity specialist and KnowBe4’s Chief Hacking Officer, helped design the KnowBe4 training based on his well-documented social engineering tactics. Organizations rely on KnowBe4 to mobilize their end users as their last line of defense and trust the KnowBe4 platform to strengthen their security culture and reduce human risk.

To view this piece of content from cts.businesswire.com, please give your consent at the top of this page.

View source version on businesswire.com: https://www.businesswire.com/news/home/20240604089157/en/

About Business Wire

Business Wire
Business Wire
101 California Street, 20th Floor
CA 94111 San Francisco

http://businesswire.com
DK

Subscribe to releases from Business Wire

Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.

Latest releases from Business Wire

Transition Industries Signs Strategic Agreements for the Pacifico Mexinol Project, the Largest Standalone Ultra-Low Carbon Chemical Production Facility in the World30.6.2025 20:30:00 CEST | Press release

Pacifico Mexinol project, a 6,130 MT per day ultra-low carbon methanol production facility worth more than US$3.3b will be located near Topolobampo, Ahome, Sinaloa. Once operational in 2029, Pacifico Mexinol is poised to be the largest standalone ultra-low carbon chemical production facility in the world. Transition Industries LLC, a developer of world-scale, net-zero carbon emissions methanol and green hydrogen projects in North America, held a signing event for an Engineering, Procurement, and Construction (EPC) contract with the consortium of Samsung E&A Co., Ltd. (Samsung E&A), Grupo Samsung E&A Mexico, S.A. de C.V., and Techint Engineering and Construction for the Pacifico Mexinol project located in Ahome, Sinaloa, Mexico, which is contingent upon the fulfillment of customary conditions precedent and obtainment of all required approvals. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20250630940954/en/ MAIRE group’s techn

Westinghouse and ITER Sign a $180M Contract to Advance Nuclear Fusion30.6.2025 15:45:00 CEST | Press release

The contract includes the assembly of the fusion reactor’s vacuum vessel, a key milestone which gets the project closer to replicating fusion energy on Earth Westinghouse Electric Company and ITER signed a contract for $180 million for the assembly of the vacuum vessel for the fusion reactor. This is a key milestone in the construction of the ITER reactor, leading the way toward the use of fusion as a practical future source of reliable carbon-free energy. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20250630497810/en/ The ITER Tokamak pit with the two vacuum vessel sector modules installed. Westinghouse has participated in the fabrication of the sectors of the vacuum vessel, as part of the Fusion for Energy (F4E) Consortium with its partners Ansaldo Nucleare and Walter Tosto. Westinghouse will be responsible for completing the vacuum vessel which is ITER’s most critical component: a hermetically sealed, double-walled steel

Monetate Acquires SiteSpect to Deliver AI-Native Personalization and Testing at Enterprise Scale30.6.2025 15:00:00 CEST | Press release

Monetate’s Real-Time Personalization Unites with SiteSpect’s Zero-Flicker Testing to Optimize Digital Experiences with Unmatched Speed, Precision, and SecurityNow Global Ecommerce and Digital Experience Leaders Can Access a Best-in-Class, Enterprise-Grade Personalization, Testing, and Optimization Platform Monetate, the leading AI-driven personalization platform, today announced it has acquired SiteSpect, a leader in A/B testing, to drive next-generation digital experience optimization. This acquisition accelerates Monetate’s vision to deliver intelligent, intentional, and individualized experiences at scale, powered by agentic AI and backed by the industry’s most advanced, enterprise-grade infrastructure. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20250630514541/en/ The combination of Monetate’s real-time personalization and SiteSpect’s zero-flicker testing will yield an industry-first solution for enterprise-grade person

SS&C Blue Prism Recognized as a Gartner® Magic Quadrant™ RPA Leader for the Seventh Consecutive Year30.6.2025 15:00:00 CEST | Press release

SS&C Technologies Holdings, Inc. (Nasdaq: SSNC) today announced that SS&C Blue Prism has been recognized as a Leader in the 2025 Gartner Magic Quadrant for Robotic Process Automation (RPA). “We’re delighted SS&C Blue Prism has been named a Leader in the Gartner Magic Quadrant for Robotic Process Automation for the seventh year running,” said Bill Stone, CEO and Chairman of SS&C Technologies. “SS&C Blue Prism combines market-leading RPA and orchestration technologies with the latest artificial intelligence so organizations can tackle more complex tasks and dynamic business processes. We’ve scaled to more than 2,700 digital workers and AI agents across our own operations, resulting in over $200 million in annual savings. With SS&C leading the charge on deployment, customers can be confident in rolling out SS&C’s automation solutions securely, effectively, and responsibly.” More than 2,800 companies worldwide leverage SS&C Blue Prism for AI-powered automation, helping organizations delive

Takeda Announces U.S. FDA Approval of GAMMAGARD LIQUID ERC, the Only Ready-to-Use Liquid Immunoglobulin Therapy with Low Immunoglobulin A (IgA) Content130.6.2025 14:00:00 CEST | Press release

GAMMAGARD LIQUID ERC [immune globulin infusion (human)] with Less Than or Equal to 2 µg/mL IgA in a 10% Solution is Approved for Intravenous or Subcutaneous Use in People Aged Two and Older with Primary Immunodeficiency1U.S. Commercialization of GAMMAGARD LIQUID ERC Projected to Begin in 2026Company Announces Future Manufacturing Discontinuation End Date for Takeda's First-Generation Low-IgA Product, A Freeze-Dried Formulation in Company’s Differentiated Immunoglobulin Portfolio of Ready-to-Use Liquids2 Takeda(TSE:4502/NYSE:TAK) today announced that the U.S. Food and Drug Administration (FDA) has approved GAMMAGARD LIQUID ERC [immune globulin infusion (human)] with less than or equal to 2 µg/mL IgA in a 10% solution, the only ready-to-use liquid immunoglobulin (IG) therapy with low immunoglobulin A (IgA) content, as replacement therapy for people two years of age and older with primary immunodeficiency (PI). As a ready-to-use liquid, GAMMAGARD LIQUID ERC may help ease the administratio

In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.

Visit our pressroom
World GlobeA line styled icon from Orion Icon Library.HiddenA line styled icon from Orion Icon Library.Eye