← All posts
GuideSeptember 25, 2026 · 7 min read

The Report Button Nobody Clicks

Most employees never report the phish they spot. Why report rate beats click rate, what keeps people silent, and how to build a report-first culture.

Suspicious email card with a highlighted report button triggering an alert, beside the title on a navy NOUSEC-branded background

Every security team says it: "our employees are our best sensors." Then the numbers arrive. In its 2024 Data Breach Investigations Report, Verizon found that in phishing simulations, just 20% of users reported the phish without clicking it — and of those who did click, only 11% ever told anyone. The median user clicked 21 seconds after opening the email. The sensor network exists, but four out of five sensors never fire, and the ones that trip the alarm on themselves go quiet.

That silence is the most expensive gap in most security awareness programs, and it is not a knowledge gap. Employees who spot a phish and delete it have already done the hard part — the detection. What is missing is the last, cheapest step: telling you. This guide is about that step — why people skip it, why it is worth more than almost any metric you currently track, and how to build a culture where reporting becomes the default reflex.

Why one report is worth a hundred deletions

When an employee quietly deletes a phishing email, one inbox is safe. When they report it, the security team can pull the same campaign out of every inbox it reached, block the sender and its infrastructure, and check whether anyone else already clicked. One report converts a private near-miss into organizational telemetry.

The economics of timing make this dramatic. Attackers operate in seconds: 21 seconds to a click, under a minute to submitted credentials, per Verizon's 2024 data. Defenders, on average, operate in months — IBM's 2026 Cost of a Data Breach report puts the mean time to identify and contain a breach at 247 days. An early report is one of the very few controls that can collapse that asymmetry, cutting dwell time from months to minutes by starting the response before the attacker has established command and control or begun lateral movement.

This is why the joint phishing guidance from CISA, the NSA, the FBI and MS-ISAC puts user reporting alongside technical controls as a first-phase defense: training users "to recognize and report" is the wording, and the second verb is not decoration. With Verizon's 2026 DBIR attributing 62% of breaches to the human element, the human layer is already your largest attack surface. Reporting is what turns it into your largest detection surface.

A phishing report is the only security telemetry that improves when your people trust you. Every other sensor you can buy. This one you have to earn.

Why employees stay silent

If reporting is so valuable, why do so few do it? Five reasons come up in every honest program review.

Fear of blame. The 11% figure — clickers who report — is the culture number, not the click rate. Someone who clicked and realized it now faces a choice: confess and risk embarrassment, remedial training, or worse, or stay quiet and hope nothing happens. In a consequence-based program, silence is the rational choice. You built that incentive.

The responsibility gap. In Proofpoint's 2024 State of the Phish, 85% of security professionals believed most employees know they are responsible for security — while 59% of employees weren't sure they were responsible or said they weren't at all. The same survey found 71% of users admitting to risky actions, 96% of them knowingly. People who do not see security as their job do not see reporting as their job either.

The bystander assumption. "IT has filters — they must already know." "A hundred people got this; someone else will report it." Every unreported campaign is a room full of people each waiting for another sensor to fire.

Friction. If reporting means finding an address to forward to, or the button exists on desktop Outlook but not on the phone where half of email is read, most people won't bother. Seconds of friction are all it takes.

The black hole. The employee who did report last quarter and heard nothing back has learned that reports vanish. No acknowledgment, no verdict, no thanks — no second report.

Notice that none of these are fixed by another training module. They are fixed by program design — which is exactly the lever human risk management is supposed to pull: measure the behavior, find what suppresses it, change the conditions.

What the numbers say

Signal Figure Source
Users who reported a simulated phish without clicking 20% Verizon 2024 DBIR
Users who clicked and then reported 11% Verizon 2024 DBIR
Median time from opening a phish to clicking 21 seconds Verizon 2024 DBIR
Typical report rate, traditional awareness programs ~10% Hoxhunt Phishing Trends Report
Sustained report rate, behavior-focused programs 20%+ Hoxhunt Phishing Trends Report
Breaches involving the human element 62% Verizon 2026 DBIR
Average time to identify and contain a breach 247 days IBM Cost of a Data Breach 2026

The vendor benchmarks are directional rather than precise — methodologies differ — but the pattern across sources is consistent: most programs idle near 10%, mature ones sustain double that, and the ceiling is nowhere in sight. In the SANS 2025 Security Awareness Report, 80% of organizations ranked social engineering as their top human risk; the report rate is the single best measure of whether your workforce is actually equipped to meet it.

How to build a report-first culture

Raising the report rate is a systems problem, not a slogan problem. Six moves, roughly in order of leverage:

1. Make reporting a one-click act — everywhere. A report button in the email client, on every platform including mobile, wired directly into your triage queue. If your users read mail in three clients, the button exists in three clients. Anything that requires remembering an address or forwarding with headers intact will lose to the delete key.

2. Put the no-blame rule in writing. State it in the security policy, repeat it in training, and have leadership say it out loud: nobody is ever punished for clicking, and nobody is ever punished for reporting late — the only losing move is silence. Then honor it, including in phishing simulations. No name-and-shame dashboards, no disciplinary escalation for repeat clickers as a first resort. The moment one employee is made an example of, your report rate becomes fiction.

3. Close the loop, fast. Automated acknowledgment on receipt; a human-readable verdict — malicious, simulation, benign — back to the reporter, same day where possible. Thank people for false positives explicitly: a false positive is a sensor that works and a calibration opportunity, not noise. The feedback loop is what separates a reporting system from a reporting culture.

4. Reward the catch, not just the miss avoided. Celebrate the first reporter of a real campaign by name (with their consent) in the channel everyone reads. Track and recognize reporting streaks. If you gamify anything in your program, gamify this — recognition for reporting beats leaderboards of failure every time, and it is the cheapest security nudge you will ever deploy.

5. Rehearse the reflex, and grade the rehearsal correctly. Run simulations where reporting is the win condition, not merely not-clicking — the difference between a program that produces cautious deleters and one that produces active sensors. Report-rate-per-simulation belongs next to click rate in every readout; our guide to simulation metrics that matter covers how to weight them. And when someone reports a simulation, tell them immediately: instant positive feedback at the exact moment of the desired behavior is how reflexes are built.

6. Measure it where decisions are made. Report rate, time-to-first-report per campaign, and the reported-after-clicking share are behavior signals, and they belong in your human risk score alongside click and credential-entry rates — per team, per role, trended over time. A department with a low click rate and a near-zero report rate is not your safest team; it is your quietest one, and the distinction deserves to be visible to leadership.

The cultural bar: reporting as psychological safety

Underneath the mechanics sits a simple question employees answer for themselves: what happens to me if I speak up? If the honest answer is "embarrassment, a mandatory module, or a manager's raised eyebrow," you will get 11%. If the answer is "a thank-you within the hour, whether or not I was right — even if I clicked first," the report button becomes what it should have been all along: the most-used control in your stack.

That bar — where admitting "I clicked something I shouldn't have" is treated as the good outcome — is the practical definition of a healthy security culture. It is also, not coincidentally, the property that determines how well your organization survives the phish that no filter and no training will ever catch. Someone in your company will see that email first. The only question is whether they say something.

Frequently asked questions

What is a good phishing report rate?

Benchmarks vary by vendor and methodology, but the direction is consistent: traditional awareness programs tend to plateau around a 10% report rate on simulations, while behavior-focused programs that reward reporting sustain 20% or more — a level Hoxhunt's trend data describes as the clearest sign of real behavior change. Treat the trend as the metric: a report rate that climbs quarter over quarter matters more than any single number, and a rising report rate with a falling click rate is the healthiest pattern a program can show.

Should employees be punished for clicking a phishing simulation?

No. Punishment teaches exactly one lesson: hide your mistakes. Verizon's 2024 DBIR found that only 11% of users who clicked a simulated phish went on to report it — and fear of consequences is a major reason clickers stay silent. A clicked phish that is reported within minutes is a contained incident; a clicked phish that is hidden is a breach with a head start. Consequence-based programs suppress the one behavior that saves you.

What should happen after an employee reports a suspicious email?

Three things, quickly: an immediate automated acknowledgment so the reporter knows the message arrived; triage by the security team or an automated pipeline; and a verdict back to the reporter — malicious, simulation, or benign — ideally within the same working day. The feedback step is the one most programs skip and the one that matters most. A report that disappears into a black hole teaches people not to bother next time, and a thank-you for a false positive teaches them the instinct itself is valued.

Why does reporting matter if we already have email filters?

Because filters miss, and when they miss, the gap between one employee clicking and someone telling you about it is your entire detection window. Verizon's 2024 DBIR put the median time-to-click at 21 seconds, with data entry following within about a minute — while IBM's 2026 Cost of a Data Breach report puts the average time to identify and contain a breach at 247 days. A single early report can collapse that gap from months to minutes, letting you pull the same email from every other inbox before the next click.

See your Human Risk Score

NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.

Book a demo