Phishing Simulation Score Calculator
Analyze phishing simulation campaign results with click rates, credential submission rates, and organizational resilience scoring.
About this calculator
A phishing simulation only tells you something useful once its raw counts get turned into rates you can compare across campaigns of different sizes and against industry norms. This calculator converts every result — opens, clicks, credential submissions, and reports — into a percentage of total emails sent, since a 50-click result means something very different for a 500-person campaign than a 5,000-person one. Click rate doubles as "phish-prone percentage," the standard industry metric for what share of your workforce would have fallen for a real attack of similar sophistication, and it's compared against a benchmark that scales with how difficult you rated the campaign, since an obvious, poorly-written scam email should catch far fewer people than a highly targeted, realistic spear-phishing attempt.
The resilience score combines three behaviors into one 0-100 number: it penalizes clicking (worth double weight) and especially submitting credentials (worth triple weight, since that's the point where real damage happens) while rewarding employees who reported the email as suspicious, on the theory that a workforce that actively reports suspicious emails is more resilient even if a few people still click. Annualized risk translates credential submissions into a rough dollar figure using an estimated average breach cost per compromised credential and an assumed 10% chance any single submission actually leads to a real breach — a deliberately conservative, illustrative estimate meant to make the abstract risk tangible for budget conversations, not a precise actuarial prediction for your specific organization.
Inputs
Results
Click Rate
10%
Resilience Score
80
How to Use This Calculator
- Enter the number of employees who received the simulated phishing email.
- Enter the number of links clicked, credentials submitted, and emails reported as suspicious from the simulation results.
- Select the Campaign Difficulty — obvious spam, realistic spear-phish, or highly targeted.
- Review the phishing susceptibility score and benchmark against industry average.
- Use the score to prioritize training for high-risk departments and repeat clickers.
How the result changes with Emails Sent
| Emails Sent | Click Rate | Resilience Score |
|---|---|---|
| 250 | 20% | 60 |
| 375 | 13.3% | 73 |
| 750 | 6.7% | 87 |
| 1,250 | 4% | 92 |
What each input means
- Emails Sent
- Total simulation emails sent.
- Emails Opened
- Number of emails opened/previewed.
- Links Clicked
- Users who clicked the phishing link.
- Credentials Submitted
- Users who entered credentials on the fake page.
- Emails Reported
- Users who reported the email as suspicious.
- Campaign Difficulty
- Select the campaign difficulty
What each result means
- Resilience Score
- 0-100, higher = more resilient.
- Organization Grade
- 1=F to 5=A.
- vs Industry Benchmark
- Negative = better than benchmark.
How this is calculated
Worked example, using the default values
- Identify Input Parameters4 parametersEmails Sent = 500, Emails Opened = 200, Links Clicked = 50, Credentials Submitted = 15 = 6 input(s) provided
- Calculate Click RateClick Rate = (linksClicked / emailsSent) * 10010 = 10
- Calculate Resilience ScoreResilience Score80 = 80
- Calculate Credential Submit RateCredential Submit Rate = (credentialsSubmitted / emailsSent) * 1003 = 3
- Calculate Report RateReport Rate = (reported / emailsSent) * 1006 = 6
Engine last updated . Checked against 1 independently-derived test — how we verify calculators. Built by Paul Gunder, a software engineer, not a licensed financial, medical, or legal professional.
Frequently Asked Questions
Why does credential submission count for more in the resilience score than just clicking a link?
Clicking a phishing link is a mistake, but no credentials or data have necessarily been exposed yet — submitting credentials on the fake page is the point where a simulated attack would have actually succeeded in a real incident. The resilience formula weights credential submissions three times as heavily as clicks to reflect that meaningfully greater severity, rather than treating every risky action as equally damaging.
Why does the click rate benchmark change depending on campaign difficulty?
A crude, obviously fake phishing email should fool far fewer people than a highly targeted, realistic spear-phishing attempt crafted to look like it came from a trusted colleague or vendor. Comparing your click rate against a benchmark that scales with difficulty avoids the misleading conclusion that your organization is unusually vulnerable just because you ran a more sophisticated (and appropriately harder) test.
Is a positive number for 'vs Industry Benchmark' always bad?
A positive percentage means your click rate came in higher than the benchmark for that difficulty level, which generally does indicate more employees fell for the simulation than is typical — worth investigating further. But a single campaign's result can also be skewed by factors like timing, a particularly convincing pretext, or a smaller sample size, so one elevated result is a signal to watch rather than an automatic verdict on your security culture.
How reliable is the annualized risk dollar figure as an actual cost estimate?
It's a deliberately simplified, illustrative estimate built from an average breach cost per credential and an assumed 10% probability that any given submission leads to a real breach, meant to translate an abstract click-rate statistic into a tangible number for budget discussions. Real breach costs and likelihoods vary enormously by industry, data sensitivity, and existing defenses, so treat this figure as a conversation-starter rather than a precise financial forecast.
Related Calculators
The questions that sit next to this one — chosen by subject, including calculators filed under a different category.
Security Awareness Training ROI Calculator
Calculate return on investment for security awareness training programs based on phishing risk reduction and incident prevention.
CybersecurityRansomware Impact Calculator
Estimate the total financial impact of a ransomware attack including downtime, recovery, legal costs, and reputation damage.
CybersecuritySecurity Budget Calculator
Calculate recommended cybersecurity budget based on industry benchmarks, company size, and risk profile with spending allocation.
Accessibility & ADAColor Blindness Check
Approximate RGB shifts for protanopia, deuteranopia, and tritanopia (Brettel-style simplification).
More in Technology & Computing.