KnowBe4

215 stats21 reports

All Statistics

The three most vulnerable industries at baseline are Healthcare & Pharmaceuticals (42.7%), Insurance (38.1%), and Retail & Wholesale (36%).

PhishingHealthcareInsuranceRetail

Organizations reduce phishing susceptibility by 79% after one year of consistent security awareness training.

PhishingSecurity AwarenessEmployee Behavior

Before any training, roughly one in three employees is likely to engage with a phishing attempt.

PhishingEmployee Behavior

97% of cybersecurity leaders are using metrics to track human-related cybersecurity risks, yet only 61% say these fully support their efforts

Human Risk

48% of surveyed organisations in the UK deploy autonomous AI agents capable of taking actions on their own

AI AgentsUK

42% of cybersecurity leaders strongly believe that security awareness alone drives lasting behavior change

Human RiskSecurity Awareness

51% of leaders at UK organisations admit that AI usage within their perimeter is entirely unapproved or lacks formal corporate governance.

AI GovernanceUK

21% of UK employees say they don’t always use official corporate AI tools provided by their organisation

Shadow AIUK

44% of the UAE & KSA employees confess that intense time constraints, cognitive overload, and everyday workplace distractions directly drive them to cut corners and make critical security errors, even when they are fully aware of safe protocols.

Human RiskUAEKSA

41% of local workers in the UAE & KSA admit that if official corporate AI tools are restricted or too slow, they will actively source their own unapproved agentic AI tools to bypass administrative blocks.

Shadow AIUAEKSA

24% of leaders at organisation across the UAE & KSA admit that AI usage within their perimeter is entirely unapproved or lacks formal corporate governance.

Shadow AIUAEKSA

36% of cybersecurity leaders report significant improvement in managing human risk within the last 12 months

Human RiskHuman Risk Management

13% of cybersecurity professionals report their organization never trains users on Teams, Slack, or SMS threats

Security TrainingCollaboration Tools

60% of UK cybersecurity professionals say threats are already moving beyond email

PhishingMulti-Channel AttacksUK

66% of UK cybersecurity professionals believe employees are more likely to trust messages received through internal collaboration platforms

Collaboration ToolsUser BehaviorUKPhishing

19% of cybersecurity leaders report their organizations have an integrated and culture-embedded approach in place to manage human-related cybersecurity risk.

Security CultureRisk ManagementHuman Error

64% of employees say it is possible that they could be tricked by AI-enabled attacks.

AI AttacksEmployee RiskHuman Error

Over a third of employees commonly source their own agentic AI tools when options are unavailable or restrictive.

Shadow AIAI AdoptionInsider RiskAgentic AI

In the last six months, use of reverse proxies to steal Microsoft 365 credentials surged by 139%.

Reverse ProxiesMicrosoft 365Credential Theft

Internal team impersonation was present in 30% of phishing attacks by threat actors in Q1 2026.

Social EngineeringInsider ImpersonationPhishing

In the last six months, Microsoft Teams attacks escalated by 41%.

PhishingCollaboration ToolsMicrosoft Teams

The tendency to prioritise protecting work accounts over personal accounts reaches 66% for Gen Z, 65% for Millennials, and 35% for Gen X.

AustraliaGenerational BehaviorWorkplace SecurityConsumer Behavior

24% of Australians take no action after hearing about a major data breach unless directly notified.

AustraliaData BreachConsumer Behavior

66% of Australians reuse passwords across multiple online accounts.

AustraliaPassword SecurityAccount SecurityPassword ReuseConsumer Behavior

Email-related incidents increased by 57%.

Email SecurityIncident Trends

97% of cybersecurity leaders feel the need for increased budget allocations to bolster the security of the human element.

Budget Human Risk

Incidents relating to the human element surged by 90%.

Human RiskSecurity Incidents

In 2025, cybercriminals increased their abuse of legitimate platforms like QuickBooks, Zoom, SharePoint, and PayPal by 67% year-to-date.

Phishing

Phone-based vishing attacks increased by 449% in 2025 compared to 2024, with phone numbers appearing as the sole payload in 5.5% of phishing emails.

PhishingPhonevishing

In 2025, 77% of callback numbers used AI-generated voices, while 69% of vishing attacks were financially motivated, requesting bank detail changes, fraudulent refunds, or transfers.

PhishingAI

65% of organisations plan to increase cybersecurity budgets.

Budget

32% of respondents believe that AI-based cybersecurity tools have the greatest impact.

AIAI tools

Nearly 90% of respondents express confidence in their ability to respond to cyberattacks

Cyber attackPreparadness

68% of attacks originate from email.

Financial Email

There has been a 25% year-on-year increase in financial institution intrusion events for 2024.

Financial Intrusion

Analysis of over three million dark web posts shows stolen credentials far outpace credit card theft.

Financial Dark webStolen credentialsCredit card theft

Internal-themed topics accounted for 98.4% of the top 10 most-clicked email templates in the phishing simulations.

Phishing

PDFs comprised the majority, 61.1%, of the top 20 attachments clicked in phishing simulations.

Phishing

HR-related themes were cited in 42.5% of phishing failures.

Phishing

70% of surveyed state, local, tribal, and territorial (SLTT) organizations cite lack of sufficient funding as their top security concern

GovernmentBudget

Security awareness training reduced phishing susceptibility from approximately 33.1% to just 4.1% after one year in state, local, tribal, and territorial (SLTT) governments.

GovernmentSecurity awareness trainingPhishing

Average ransom per attack on state, local, tribal, and territorial (SLTT) governments reached $872,656 between 2018 and December 2024, with total costs exceeding $1.09 billion.

GovernmentRansomwareRansom

Security training reduces global phishing click rates by 86%.

Phishing

The global PPP fell by a total of 86% after 12 months of ongoing security training.

Phishing

Globally, the top three most at-risk industries with the highest baseline PPP were Healthcare & Pharmaceuticals (41.9%), Insurance (39.2%), and Retail & Wholesale (36.5%).

Phishing

60.7% of the phishing simulations that were clicked mentioned an internal team.

EmailPhishingImpersonation

68.6% of clicked links involved domain spoofing.

EmailPhishingImpersonationSpoofing

Over 60% of top-clicked phishing emails were related to HR and IT.

EmailPhishingImpersonationHRIT

94% of energy firms are pushing to adopt AI-driven cybersecurity due to revenue losses and disruptions caused by ransomware and phishing.

AIEnergyRansomwarePhishingAI adoption

Successful reported cyberattacks on UK utility companies surged by 586% from 2022 to 2023.

Cyber attackUtilityUK