Well‑Funded Companies Exhibit Highest Phishing Attachment Click Rates in 13.9 M Simulation Study
What Happened — A benchmark of 13.9 million simulated phishing messages found that only 10 % of recipients reported the attempt, while the remaining 90 % either clicked the malicious attachment or ignored it. Companies with the largest funding levels showed the highest click‑through rates, indicating that financial resources alone do not guarantee stronger human defenses.
Why It Matters for Compliance & Audit Readiness
- The low reporting rate and high click‑through expose a gap in the “people” control that SOC 2’s Security principle expects to be continuously monitored and evidenced.
- Without demonstrable, periodic security‑awareness testing, organizations struggle to provide audit‑ready proof that the human layer is effective against phishing.
- Verisq’s Security Awareness Training capability supplies the continuous evidence and control‑mapping needed to satisfy SOC 2 access‑control and risk‑management criteria.
Who Is Affected — Financial services, technology/SaaS firms, defense contractors, and any organization that runs regular phishing simulations.
Recommended Actions
- Align phishing‑simulation metrics (click‑rate, reporting‑rate) with SOC 2 control objectives and capture evidence in a centralized audit repository.
- Augment technical controls (email filtering, MFA) with a structured, recurring security‑awareness program that includes measurable training completion and simulated‑phishing results.
- Review and adjust reporting thresholds to avoid SOC overload while still catching early‑stage campaigns.
Source: Help Net Security – The best‑funded companies open the most phishing attachments
Technical Notes
- Attack vector: Phishing emails with malicious attachments or credential‑harvesting links.
- No specific CVEs; the threat leverages social‑engineering techniques (urgency, authority) and increasingly sophisticated Phishing‑as‑a‑Service kits that can bypass MFA.
- Data types targeted: login credentials, corporate network access, and potential malware payloads.