Skip to main content
VendorsKnowBe4

KnowBe4

Cybersecurity reports and statistics published by KnowBe4

8 categories10 reports

Recent Statistics & Reports

Organizations with 10,000+ employees showed a global baseline PPP of 40.5%.

5/13/2025
Phishing

After 12 months of security training, the global Phish-prone™ Percentage (PPP) dropped to 4.1%.

5/13/2025
Phishing

Across different regions, the highest baseline PPPs were found in South America (39.1%), North America (37.1%), and Australia and New Zealand (36.8%).

5/13/2025
Phishing

From 2024 to 2025, the general trend of around one-third of employees clicking on a simulated phishing link before training remained fairly consistent.

5/13/2025
Phishing

In organizations of 1,000-9,999 employees, three sectors achieved PPP improvement rates of 91% after 12 months of ongoing training: Healthcare & Pharmaceuticals, Hospitality, and Legal.

5/13/2025
Phishing

Internal communications are a significant driver of phishing failures. Emails impersonating internal teams, particularly HR and IT, received the most failures in phishing simulations.

4/28/2025
EmailPhishingHR

People were more likely to click on links related to internal topics or impersonating known brands, accounting for 61.6% of clicks.

4/28/2025
EmailPhishingImpersonation

Over 60% of top-clicked phishing emails were related to HR and IT.

4/28/2025
EmailPhishingImpersonation

In attachment-based campaigns, people were most likely to open certain file types: PDFs (53%), HTML files (28.5%), Word files (18.5%).

4/28/2025
EmailPhishingImpersonation

In attachment-based campaigns, people were most likely to open certain file types: PDFs (53%), HTML files (28.5%), Word files (18.5%).

4/28/2025
EmailPhishingImpersonation

68.6% of clicked links involved domain spoofing.

4/28/2025
EmailPhishingImpersonation

49.7% of clicked phishing simulations mentioned HR.

4/28/2025
EmailPhishingImpersonation

60.7% of the phishing simulations that were clicked mentioned an internal team.

4/28/2025
EmailPhishingImpersonation

The top three QR codes scanned in simulations related to: A new drug and alcohol policy from HR (14.7%), A DocuSign for review and signing (13.7%), A Workday happy birthday message (12.7%).

4/28/2025
EmailPhishingImpersonation

Security awareness training has significantly reduced phishing susceptibility in large energy organisations, dropping from 47.8% to 4% in one year.

4/23/2025
EnergyPhishingSecurity awareness training

Phishing was behind 34% of attacks reported in the energy sector.

4/23/2025
Cyber attackEnergyPhishing

The energy sector reported three times more operational technology (OT)/industrial control system (ICS) cyber incidents than any other industry in 2023.

4/23/2025
Cyber attackEnergy

The average number of cyberattacks against the energy and utilities sector more than doubled between 2020 and 2022.

4/23/2025
Cyber attackEnergy and utilities

Successful reported cyberattacks on UK utility companies surged by 586% from 2022 to 2023.

4/23/2025
Cyber attackUtilityUK

94% of energy firms are pushing to adopt AI-driven cybersecurity due to revenue losses and disruptions caused by ransomware and phishing.

4/23/2025
AIEnergyRansomware

Showing 61-80 of 175 results