KnowBe4
Reports
All Statistics
The three most vulnerable industries at baseline are Healthcare & Pharmaceuticals (42.7%), Insurance (38.1%), and Retail & Wholesale (36%).
Organizations reduce phishing susceptibility by 79% after one year of consistent security awareness training.
Before any training, roughly one in three employees is likely to engage with a phishing attempt.
97% of cybersecurity leaders are using metrics to track human-related cybersecurity risks, yet only 61% say these fully support their efforts
48% of surveyed organisations in the UK deploy autonomous AI agents capable of taking actions on their own
42% of cybersecurity leaders strongly believe that security awareness alone drives lasting behavior change
51% of leaders at UK organisations admit that AI usage within their perimeter is entirely unapproved or lacks formal corporate governance.
21% of UK employees say they don’t always use official corporate AI tools provided by their organisation
44% of the UAE & KSA employees confess that intense time constraints, cognitive overload, and everyday workplace distractions directly drive them to cut corners and make critical security errors, even when they are fully aware of safe protocols.
41% of local workers in the UAE & KSA admit that if official corporate AI tools are restricted or too slow, they will actively source their own unapproved agentic AI tools to bypass administrative blocks.
24% of leaders at organisation across the UAE & KSA admit that AI usage within their perimeter is entirely unapproved or lacks formal corporate governance.
36% of cybersecurity leaders report significant improvement in managing human risk within the last 12 months
13% of cybersecurity professionals report their organization never trains users on Teams, Slack, or SMS threats
60% of UK cybersecurity professionals say threats are already moving beyond email
66% of UK cybersecurity professionals believe employees are more likely to trust messages received through internal collaboration platforms
19% of cybersecurity leaders report their organizations have an integrated and culture-embedded approach in place to manage human-related cybersecurity risk.
64% of employees say it is possible that they could be tricked by AI-enabled attacks.
Over a third of employees commonly source their own agentic AI tools when options are unavailable or restrictive.
In the last six months, use of reverse proxies to steal Microsoft 365 credentials surged by 139%.
Internal team impersonation was present in 30% of phishing attacks by threat actors in Q1 2026.
In the last six months, Microsoft Teams attacks escalated by 41%.
The tendency to prioritise protecting work accounts over personal accounts reaches 66% for Gen Z, 65% for Millennials, and 35% for Gen X.
24% of Australians take no action after hearing about a major data breach unless directly notified.
66% of Australians reuse passwords across multiple online accounts.
Email-related incidents increased by 57%.
97% of cybersecurity leaders feel the need for increased budget allocations to bolster the security of the human element.
Incidents relating to the human element surged by 90%.
In 2025, cybercriminals increased their abuse of legitimate platforms like QuickBooks, Zoom, SharePoint, and PayPal by 67% year-to-date.
Phone-based vishing attacks increased by 449% in 2025 compared to 2024, with phone numbers appearing as the sole payload in 5.5% of phishing emails.
In 2025, 77% of callback numbers used AI-generated voices, while 69% of vishing attacks were financially motivated, requesting bank detail changes, fraudulent refunds, or transfers.
65% of organisations plan to increase cybersecurity budgets.
32% of respondents believe that AI-based cybersecurity tools have the greatest impact.
Nearly 90% of respondents express confidence in their ability to respond to cyberattacks
There has been a 25% year-on-year increase in financial institution intrusion events for 2024.
Analysis of over three million dark web posts shows stolen credentials far outpace credit card theft.
Internal-themed topics accounted for 98.4% of the top 10 most-clicked email templates in the phishing simulations.
PDFs comprised the majority, 61.1%, of the top 20 attachments clicked in phishing simulations.
HR-related themes were cited in 42.5% of phishing failures.
70% of surveyed state, local, tribal, and territorial (SLTT) organizations cite lack of sufficient funding as their top security concern
Security awareness training reduced phishing susceptibility from approximately 33.1% to just 4.1% after one year in state, local, tribal, and territorial (SLTT) governments.
Average ransom per attack on state, local, tribal, and territorial (SLTT) governments reached $872,656 between 2018 and December 2024, with total costs exceeding $1.09 billion.
Security training reduces global phishing click rates by 86%.
The global PPP fell by a total of 86% after 12 months of ongoing security training.
Globally, the top three most at-risk industries with the highest baseline PPP were Healthcare & Pharmaceuticals (41.9%), Insurance (39.2%), and Retail & Wholesale (36.5%).
60.7% of the phishing simulations that were clicked mentioned an internal team.
68.6% of clicked links involved domain spoofing.
Over 60% of top-clicked phishing emails were related to HR and IT.
94% of energy firms are pushing to adopt AI-driven cybersecurity due to revenue losses and disruptions caused by ransomware and phishing.
Successful reported cyberattacks on UK utility companies surged by 586% from 2022 to 2023.