The average click rate for untrained employees sits at roughly 33 percent. After a year of regular simulation and training, organisations typically get that under 5 percent. Those two numbers are why phishing simulation exists as a service category.
They are also why most programmes stall. A team runs a campaign, sees a click rate fall, declares progress and stops. Click rate is the easiest metric to move and the weakest predictor of whether your organisation would survive a real campaign. This post covers how phishing simulation services actually work, which metrics matter, and what determines the cost of running one properly.
A simulation is not a single email blast. A programme has four moving parts that run continuously rather than once.
Phishing simulation measures workforce behaviour through baseline campaigns, realistic scenarios and training triggered on click. Click rate is the weakest metric; resilience ratio, report rate divided by click rate, above 3 to 1 indicates a strong security culture. Cost is driven by headcount, frequency, scenario customisation and training depth.
Baseline campaign. An initial simulation sent without warning, to establish where you actually are. Announcing it in advance produces a flattering number and no useful data.
Scenario design. Templates built to match plausible threats against your organisation rather than generic bait. For an Indian finance team that might be a vendor payment change request. For an engineering team, a fake single sign on prompt. Realism is what makes the exercise diagnostic.
Delivery and measurement. Campaigns sent in waves across departments, with tracking on delivery, opens, clicks, credential submission and reports.
Training response. Targeted training triggered by behaviour, delivered close to the moment of the click, when it is most likely to land.
The programme then repeats at a cadence, usually monthly or quarterly, with scenario difficulty increasing as performance improves.
Four numbers tell you the truth. Most reports show only the first.
The percentage of recipients who clicked the link. Useful as a baseline and easy to move, which is exactly why it should never be reported alone. A falling click rate can mean genuine improvement, or it can mean your scenarios got easier.
The percentage who proactively reported the email to your security team. Report rates across industries typically range from 9 to 29 percent. This is the metric that reflects active defence rather than passive avoidance. An employee who deletes a phishing email protects themselves. An employee who reports it protects everybody.
Report rate divided by click rate. A ratio above 3:1 indicates a genuinely strong security culture. This single figure resists the gaming that click rate invites, because you cannot improve it by making scenarios trivially easy: easy scenarios lower clicks and lower reports together.
If you report one number to your board, report this one.
The percentage who not only clicked but entered credentials on the landing page. This is the number closest to real loss. A high click rate with near zero submission is a different risk profile from a moderate click rate with frequent submission, and the two need different training responses.
| Metric | Typical range | Strong performance |
|---|---|---|
| Click rate, untrained | Around 33 percent | Under 5 percent after sustained training |
| Report rate | 9 to 29 percent by industry | Above 30 percent |
| Resilience ratio | Often below 1:1 at baseline | Above 3:1 |
| Financial services click rate | 4 to 7 percent | Sector leading |
These are global figures. Treat them as directional for an Indian organisation rather than as a target your board should hold you to, because sector, language mix and email culture all shift the baseline.
There is a line between a simulation that builds capability and one that damages trust. Programmes cross it when they use bait that is cruel rather than realistic: fake bonus announcements, fabricated layoff notices, false news about a colleague.
Those campaigns produce high click rates and an angry workforce, and the second effect outlasts the first. Employees who feel tricked stop reporting, which destroys the metric that actually matters.
Good scenarios mirror what attackers genuinely send to organisations like yours. Mapping them to MITRE ATT&CK initial access techniques keeps the programme anchored to real adversary behaviour rather than to whatever gets the highest click rate. Realistic and difficult is the goal. Humiliating is not.
Three things shape phishing programmes for Indian organisations in ways global templates miss.
Language and register. Multilingual workforces and the specific register of Indian corporate email mean templates written for a US office read as obviously foreign. Local phrasing raises realism, which is the point.
Vendor payment fraud. Business email compromise targeting vendor payment changes is a persistent pattern against Indian finance teams. Any programme covering an organisation with a payables function should include this scenario, because it is where the largest single losses occur.
Reporting obligations. Where a phishing incident results in an actual compromise, the CERT-In six hour reporting clock applies. A simulation programme is a reasonable place to rehearse that path, and continuous monitoring is what makes meeting it realistic, since the report to your security team is the first step in the same chain that ends in a regulatory notification.
For NCR organisations specifically, the concentration of IT services and BPO operations means large distributed workforces where email is the primary interface with clients. Scale makes both the exposure and the training logistics harder.
Public pricing for phishing simulation in India is thin, and any firm quoting a rate before understanding your scope is guessing. Rather than a number that would not survive contact with your environment, here is what actually moves the price.
Employee count and campaign frequency. Most commercial models price per user per year, with frequency as a multiplier. A quarterly programme costs materially less than a monthly one.
Scenario customisation. Off the shelf template libraries are cheap. Custom scenarios built around your vendors, your systems and your internal language cost more and produce better data.
Training depth. Automated micro training triggered on click is the low cost option. Facilitated sessions for high risk groups such as finance and executive assistants cost more and are usually worth it for those groups specifically.
Reporting and integration. Board level reporting, integration with your ticketing system, and a real report button in your mail client add setup effort.
Whether it is bundled. Phishing simulation as part of a broader offensive security programme usually costs less per exercise than buying it standalone, because scenario design shares research with the red team work.
Ask any provider for pricing broken into setup, per user licensing and services, so you can see what you are actually buying.
Questions worth asking a provider:
A provider who cannot answer the first question is selling a mailing tool.
SecureRoot runs phishing simulation as part of our offensive security practice, which means scenario design draws on the same research as our red team engagements. Templates reflect techniques we see used against Indian organisations rather than a generic library, and the results feed your incident response process rather than a standalone dashboard.
We also report resilience ratio by default, because click rate on its own tells your board a story that may not be true. See the full range on our services page.
Monthly or quarterly for most organisations. Less than quarterly and there is not enough repetition for behaviour to change. More than monthly and fatigue sets in, with employees treating every unusual email as a test rather than thinking about it.
Tell them a programme exists. Do not announce individual campaigns. Transparency about the programme protects trust and improves reporting. Advance warning of a specific campaign produces a flattering number and no diagnostic value.
Treat it as a training and role risk question, not a disciplinary one. Some roles receive far more external email than others, and a finance team member clicking a well built vendor scenario is a different signal from a general click. Punitive responses suppress reporting, which costs you more than the clicks do.
No. Simulation measures workforce behaviour at scale across many recipients. A red team engagement uses social engineering as one route toward a specific objective, testing detection and response rather than aggregate awareness. Organisations commonly run both, and simulation data helps target red team scenarios.
Yes. Both expect security awareness activity, and a documented programme with measured outcomes is stronger evidence than an annual slide deck with an attendance list. The reporting you produce for the board usually serves as audit evidence unchanged.
If you are running simulations already and only seeing click rate, or have not started and want a baseline, we can scope a programme around your headcount and risk profile.
Book a 30 minute scoping call, or call +91 73071 48874.