Pistachio's Research Redefines Phishing Awareness Testing
Pistachio's recent research challenges conventional security awareness testing by highlighting employee behavior and industry-specific vulnerabilities in phishing resistance.

New findings from Norwegian-based Pistachio, a leader in automated human risk management and phishing simulation, are challenging traditional methods of security awareness training. Their recent research, covering a year-long study from June 1, 2025, to May 31, 2026, involved launching over 2.47 million simulated phishing attacks across more than 123,000 employees in 1,200 organizations. The results shed light on the effectiveness of current awareness programs and stress the need for more nuanced testing methods.
Pistachio's Phishing Simulation Program
Pistachio, founded in 2019 with headquarters in Oslo, has positioned itself as a pioneering force in cybersecurity training. The company's phishing simulations were tailored via an AI-driven platform that determined the difficulty and format of each attack based on the employee's role and previous behavior in prior simulations. These attacks utilized various delivery channels, including email and Microsoft Teams.
Key Findings on Employee Behavior
The findings from the simulation research reveal alarming trends regarding employee susceptibility to phishing:
- 30% of employees in tech development and IT clicked on at least one phishing link.
- Construction and real estate sectors demonstrated a 20% rate of credential leaking post-simulation.
- By contrast, employees in the financial services sector showed the highest resilience, outperforming other industries in terms of click, leak, and reporting rates.
Surprisingly, the performance of technical teams was not as robust as expected, with click rates significantly high among IT specialists. For instance, 30.27% of tech development users clicked on phishing simulations, highlighting the need for improved training even among skilled professionals.
The Importance of Beyond Click Metrics
Pistachio’s report emphasizes the need for organizations to reevaluate how they measure phishing resistance. The traditional measure of success—the click rate—is criticized for offering a narrow view of phishing risk. According to the research, a low click rate could create a false sense of security. Instead of just monitoring clicks, organizations are encouraged to observe how employee behaviors evolve over time with regards to phishing interactions.
As Joe Jones, CEO and co-founder of Pistachio, asserts, "Clicking a phishing link is just one moment in a much longer chain of employee behavior, and on its own, it says little about whether someone... is actually getting more resilient." The true measure of improvement lies in understanding how employees respond after the initial click, including whether they recognize the attack, report it, or mistakenly submit credentials.
Phishing Resilience by Sector
Interestingly, the susceptibility to phishing varied widely across sectors, with click rates ranging considerably:
| Sector | Click Rate (%) | Credential Leakage Rate (%) | Reporting Rate |
|---|---|---|---|
| Design | 26.35% | Data N/A | Data N/A |
| Construction | 41.31% | 20% | Data N/A |
| Financial Services | Lowest rate | Data N/A | Highest reporting rate |
| IT/Tech | 30.27% | Data N/A | Data N/A |
Behavioral Insights Over Time
The longitudinal analysis conducted by Pistachio illustrated various behaviors over the duration of the training program. For example, participants reported suspicious emails at nearly double the rate they clicked on simulations by the end of the program. This suggests that ongoing training can foster vigilance among employees rather than merely reducing the click rates.
However, it is crucial for companies to realize that improved awareness does not occur instantaneously. During the first six months of the program, rates for both clicks and leaks initially rose before beginning to decline, implying that awareness training must be sustained to yield lasting behavioral change.

The Need for Geographic Analysis
A notable gap in the research was the absence of geographic analysis in the findings. Despite the substantial size of the dataset utilized by Pistachio, the study did not explore potential differences in phishing susceptibility across various regions. Addressing this could help organizations tailor their training programs more effectively. While there is no definitive proof that phishing susceptibility varies by location, it would be beneficial for organizations operating globally to investigate potential regional differences that may warrant additional training efforts.
Implications for Future Phishing Tests
The implications of the Pistachio research highlight that organizations must approach the development of phishing simulation tests with a nuanced perspective. As cybersecurity threats continue to evolve, the importance of a thorough understanding of employee behavior patterns will become crucial for effective training strategies. Organizations are encouraged to view simulations as not just a training exercise but as an opportunity to build resilience against social engineering attacks.
Key Takeaways
- Pistachio's research involved over 2.47 million phishing simulations across 123,000 employees over a year.
- 30% of tech and IT employees clicked on phishing simulations, which points to a significant training gap.
- Financial services demonstrated the highest phishing resilience, outperforming other sectors.
- Behavioral change is crucial; click rates alone are insufficient to measure phishing resistance.
- Absence of geographic analysis in the findings suggests that future studies should explore regional differences in phishing susceptibility.
Conclusion
In summary, the findings from Pistachio's research reshape the conversation around phishing awareness testing. By prioritizing behavior over mere click rates and recognizing industry-specific vulnerabilities, organizations can enhance their training efficacy. As phishing tactics grow increasingly sophisticated, understanding and adapting to employee behavior will be vital for developing effective defenses.
Frequently Asked Questions
