How should the hit rate be interpreted?
The hit rate shows how many users reacted to a simulated phishing scenario. A reaction includes, for example:
- clicking on a link,
- entering login credentials, or
- opening an email attachment.
The higher the value, the worse the result is from the customer's perspective.
Where can you find the hit rate?
You can find the hit rate in the Control Panel under Security Awareness Service > Statistics in the Phishing tab in the table Successful Phishing Emails. This table shows the success of specific phishing emails.
The Hit Rate column shows the percentage value for each scenario.
How to read the "Hit Rate" column
The hit rate is an effectiveness metric per scenario.
Each row represents a simulated phishing email and contains the following information:
- Subject: The subject line of the sent phishing email.
- Hit Rate: Shows in percentage how successful the phishing email was.
- Level: The level users must be at to receive this phishing email.
- Number: Indicates how many phishing emails were sent.
- Links: Indicates how many links were clicked by users. This also counts scanned QR codes.
- Credentials: Indicates how often users disclosed their login credentials due to the simulated phishing email.
- Documents: Indicates how often users opened attached documents in the phishing email.
- Macros: Indicates how often users ran macros in attached documents of the phishing email.
How should the value be interpreted?
The more hits a scenario has, the more users reacted to the simulated attack. A high value therefore indicates that the company is more vulnerable to this type of attack.
100% means that every email belonging to this scenario triggered a hit. This is the worst possible value.
Further information
What exactly counts as a hit is explained in the article What counts as a clicked link?.
Details about the statistics can be found in our manual: Statistics in the Security Awareness Service