Proofpoint State of the Phish Report
An annual benchmark on phishing susceptibility, security awareness, and human-risk behavior.
Proofpoint's 2024 report drew on telemetry from more than 2.8 trillion scanned emails across 230,000+ organizations and 183 million simulated phishing attacks over 12 months, plus survey responses from 7,500 employees and 1,050 security professionals across 15 countries, finding 68% of employees knowingly took risky actions despite awareness training.
FAQs
Proofpoint State of the Phish Report: frequently asked questions
What is Proofpoint State of the Phish Report?
State of the Phish is Proofpoint's annual report analyzing real-world phishing simulation data alongside global end-user and security-professional survey findings, a widely cited benchmark for security-awareness content.
Where is Proofpoint State of the Phish Report based?
Proofpoint State of the Phish Report is based in Sunnyvale, CA, USA.
What is Proofpoint State of the Phish Report listed under on Cyber Resources?
Proofpoint State of the Phish Report is listed in the Research & Reports category of Cyber Resources, the curated directory of the cybersecurity marketing and growth ecosystem.
More Research & Reports
Verizon Data Breach Investigations Report (DBIR)
New York, USA
The Verizon DBIR analyzes thousands of confirmed breaches and security incidents contributed by law enforcement, forensic firms, and cyber insurers to map how breaches happen and who is behind them. Published annually, it is the most widely cited breach benchmark in the industry.
IBM Cost of a Data Breach Report
Armonk, USA
IBM's Cost of a Data Breach Report surveys hundreds of breached organizations across more than a dozen countries to quantify average breach cost, time to identify and contain, and cost factors such as AI governance and shadow AI. Research is conducted independently by the Ponemon Institute.
Mandiant M-Trends
Reston, USA
Mandiant's M-Trends draws on hundreds of thousands of hours of incident-response engagements to report on dwell time, initial infection vectors, and threat-actor tactics. A 17+ year staple for defenders, now published under Google Cloud.