Click rate is not intelligence.
The security industry moved from open rate to click rate and stopped there. Click rate answers one question — how much happened — and treats that answer as if it were the conclusion. But "34 of 363 clicked" describes without explaining. And a description you cannot act on is not a result. It is a number waiting for a meaning that never arrives.
This is the difference between a data point and intelligence. A data point tells you that something happened. Intelligence tells you what to do about it.
We use phishing throughout, because it is the vector where the mistake is most expensive and most visible. But the argument is not about phishing. It is about how human risk is measured at all. A note on the other vectors is at the end.
Imagine a doctor who reports a fever and nothing else. Temperature, logged. No cause, no system, no next step. You would not call that a diagnosis. You would call it a thermometer.
A standard phishing report is a thermometer. It tells you the organization is running a temperature — 9.4%, say, comfortably under the sector average — and then it stops. The implicit conclusion, we're below average, we're fine, is the most dangerous sentence in security awareness, because it closes the conversation precisely where the useful part should begin.
Blame works the same way. "She should have known better" is the oldest explanation in information security, and the most useless, because after thirty years of programs built on it, successful phishing keeps rising everywhere.
If the explanation doesn't change the future, it isn't a diagnosis. It's an excuse with a number attached.
Intelligence does the opposite of closing the conversation. It opens a program.
The market's best report has three parts: a count of clicks, a percentage, and a sector benchmark. It feels rigorous. It is structurally blind in three places.
The click is the middle of an attack, not its end. What happens after the click — does the person hand over the credential, or stop? — matters as much or more. A standard report says "34 clicked" and falls silent. It never says how many of those went on to surrender credentials, and how many caught themselves. Those are two different failures, requiring two different defenses: one about not clicking, one about not submitting even after you've clicked. Click rate is blind to the second — and the second is where the breach actually happens.
"Financial services average 15%" folds together a generic password-reset template and a contextually personalized spear-phishing campaign as if they were the same event. A 9% driven by greed and a seasonal sale is a completely different phenomenon from a 9% driven by authority and an IT notice. The sector benchmark treats them as equivalent. They are not. It is the emotion the pretext activates — not the industry it lands in — that sets the realistic expectation of the result.
"You scored 9.4%, below sector average" — what does the person responsible do with that? At best, they order a round of generic awareness training. Generic, because the information they received was generic. When the diagnosis instead says the pretext exploited a specific psychological lever, operating through a specific emotion, and the failure point was the data-entry screen, not the click — now the training has an address. It stops being "phishing awareness" and becomes "resistance at the point of credential entry, for benefit-framed pretexts in a seasonal window." Specificity is what turns a simulation from a compliance exercise into behavioral development.
If click rate is the wrong answer, it's because the field has been asking the wrong question. The right question is not how many. It is through what mechanism.
Every well-built pretext works through two things, and they are not the same thing. A principle is the psychological lever the attacker pulls — authority, scarcity, reciprocity, social proof, familiarity. It is how the manipulation is engineered. It is what the attacker does. An emotion is the internal state the pretext activates in the target — fear, benefit, curiosity, belonging. It is what the person feels that makes them act. It is the effect inside the human.
A good pretext chains principles together to produce an emotion that suppresses rational analysis. The name of the mechanism is the address of the countermeasure.
This rests on a distinction every reader already knows in their own head. The cognitive literature calls it System 1 and System 2 — the fast, automatic, emotional mind that clicks before it thinks, and the slow, deliberate, analytical mind that checks the sender's domain. A well-built social engineering attack is, at its core, a machine for keeping the target in System 1 and preventing the switch to System 2. Every effective countermeasure is, at its core, a way of forcing that switch at the right moment.
That is why we classify by mechanism. Not as academic taxonomy, but because to know that a campaign worked through belonging and benefit is to know that the relevant training is not "how to spot generic phishing" — it is "how to recognize that collective-benefit framing is exactly the environment where the guard drops."
Principle and emotion rarely act alone. In a real, well-constructed attack they act in sequence, and each phase has its own window of vulnerability — and therefore its own countermeasure. This is the structure that connects the diagnosis to the action.
Activation — the pretext earns attention
A person receives dozens of emails a day and discards most without real processing. What makes one get opened is a dominant principle striking something the person already carries: a want, a worry, a bond, a gap in what they know. The email does not create the emotional state. It finds the one that already exists and triggers it.
Countermeasure — not learning to spot the suspicious email, but building the habit of pausing the instant an email evokes an immediate feeling, because that is the precise moment System 1 has taken the wheel.
Legitimation — the source looks trustworthy
An email that activates curiosity but arrives from an obviously strange sender is discarded. What keeps the target in the funnel is the perception that the source is legitimate. Brand spoofing lives here: visual identity convinces where the sender alone would not.
Countermeasure — technical and behavioral at once: verify the real sending domain, not the display name, and install the rule that visual familiarity is not proof of legitimate origin.
Compromise — the first click
Where most generic training focuses, and where most of it stops. "Don't click suspicious links." The problem: if the attack got this far, the email did not look suspicious. The click is not a knowledge failure — it is the result of two earlier phases executed well.
Countermeasure — deliberate friction at the moment of the click: before entering any data, read the URL in the address bar, not the page title.
Conversion — the handover of data
The last point where defense can still work, and the one that gets the least training. Whoever reaches the entry screen has passed through three phases of context-building. The unconscious logic is "I've come this far, it would be strange to stop now."
Countermeasure — the most counterintuitive of all: teaching that stopping in the middle is correct. Typing the password is always the final, irreversible step of an attack. No matter how many steps already happened, that is where the barrier has to be.
Without the diagnosis, training is a shot in the dark. With it, you know which phase the attack was most effective in, and which barrier your organization failed at. This is what turns the cycle of simulate → analyze → train → simulate again into something that evolves instead of something that merely repeats.
Everything above is an argument. Arguments are cheap. So here is the part that isn't.
We hold empirical benchmarks from hundreds of custom-built social engineering campaigns — real ones, designed and run, not template libraries. That dataset is the floor under everything in this manifesto, and it says three things a sector benchmark structurally cannot.
We are not printing the figures here. Not because they're secret for the sake of it, but because a number is a diagnosis, and a diagnosis is something you run on your own people — not something you read in a manifesto and apply to someone else's. The exact benchmarks, and where your organization sits against them, are what a SEA.map report exists to show you. The manifesto tells you the shape of the truth. The report tells you yours.
This is not opinion dressed as data, either. The behavioral-security literature has held for years that susceptibility to social engineering is a function of measurable psychological factors, not technical ignorance (Workman, 2008); that relational trust is the strongest single predictor — and, counterintuitively, that prior experience with cybercrime can raise vulnerability through vigilance fatigue (Albladi & Weir, 2018); and that contextually personalized pretexts reach open rates many times those of generic ones, the driver being personalization, not volume (Aleroud & Zhou, 2017). Our data doesn't contradict the literature. It operationalizes it.
We argued this through phishing because it is where the cost is clearest. But nothing in the argument is specific to email.
A principle is vector-agnostic. Authority works through a phone call (vishing), a lanyard at a reception desk (physical), or a connection request (social) exactly as it works through an inbox. The emotion the target feels is the same emotion. What changes from vector to vector is only the instrumentation — the concrete technique that carries the pretext. The logic of the diagnosis does not change.
Measure the mechanism, not the medium. Click rate is just the version of the mistake that happens to have a percentage attached.
That a simulation should stop being a test your people pass or fail, and become an instrument that tells you something.
The number on its own — 9.4%, below average — closes the conversation and changes nothing. The mechanism behind the number opens a program: it names which lever was pulled, which emotion answered, which phase failed, and therefore what to build next. Do that across campaigns, and you stop running the same exercise every quarter and start running a trajectory — one where each point is comparable to the last because each one is classified by mechanism.
That trajectory is the whole point. The value was never in any single campaign. It was in the line they draw over time — and the line is only legible because every point on it has a name.
Click rate told you that something happened.
We think you deserve to know what to do about it.
OES designs and runs custom-built social engineering simulations, and turns them into behavioral intelligence through the SEA ecosystem. To see where your organization actually sits — emotion by emotion, phase by phase — that's what a SEA.map report is for.
intel@oes.seg.br