Awareness · Composite metric

Phish-Prone Score (PPS)

Not a simple click rate — a per-employee score combining 5 real signals. Lets you prioritize coaching, identify repeat offenders and report to the board in a single understandable number.

Capabilities

Weighted click rate

Clicks per channel, weighted by simulation severity. A click on a CFO BEC weighs more than on a generic newsletter.

Submit intent (creds) V1.1

If the employee reached the credential-entry step on a fake login (without storing them — privacy by design), PPS reflects it as high risk.

Repeat offender detection

Anyone falling for 3 simulations in 6 months is 10x more likely to fall for a real attack. Automatic flag + manager alert.

Training adherence

Completed JIT lessons weigh negatively in the score — an employee who trains after falling lowers their PPS.

Report rate

Employees who REPORT phishing (button) lower their PPS. We reinforce defensive behavior, not only penalize mistakes.

Trend 30/90/365

Individual and cohort trend. Board sees "organizational PPS dropped from 42 to 28 in 6 months" as an exec metric.