Security Awareness Training That Actually Reduces Phishing Click Rates

Retool's new app builder is where AI-generated code ships safely
Building apps with AI is easy. Getting them to production safely is another story.
Security awareness programs are one of the most consistently funded and consistently disappointing investments in enterprise security. Organizations spend millions of dollars annually on training platforms, phishing simulation subscriptions, and awareness content, then watch their phishing click rates sit stubbornly at 15% to 25% year after year. The annual compliance training module is completed because it is required, not because it changes behavior. The monthly phishing simulations produce a spike of attention for the employees who clicked and brief irritation from everyone else. The click rate improves slightly in the weeks after a simulation and returns to baseline within a month. This is not a problem with training platforms or content quality. It is a problem with the behavioral model underlying most awareness programs. Security awareness training is not education in the traditional sense. It is behavior modification in a specific context, under time pressure, against adversaries who are specifically optimizing their attacks to bypass the defenses that training programs teach. This guide covers what the behavioral science research actually says about effective security behavior change, the simulation design principles that produce measurable improvement, and the program metrics that tell you whether you are making real progress or just generating compliance documentation.
Why Monthly Generic Phishing Simulations Plateau
The generic monthly phishing simulation model creates a Pavlovian response in employees that is different from the one program designers intend. After several months of monthly simulations, employees learn to recognize the simulation pattern, not the phishing threat pattern. They develop heuristics like checking whether a link domain is familiar, hovering over links before clicking, and being suspicious of any email that feels slightly off. These heuristics improve performance on simulations because simulations frequently reuse the same template patterns. They do not significantly improve performance against real phishing attacks because real attackers continuously adapt their techniques and do not send the same template to the same organization twice.
The research literature on expertise development distinguishes between performance on training examples and generalization to novel cases. Security awareness training produces performance improvement that is largely confined to the stimulus types seen during training. An employee who has seen 20 simulations using credential harvesting pretexts will perform better on credential harvesting simulations than they did at the start. They may not perform meaningfully better against a well-crafted spear phishing email using a pretext they have never seen in a simulation context.
The plateau effect is compounded by the annual training module model. Adults retain roughly 10% of what they hear and 70% of what they practice. A 45-minute annual compliance training video about phishing falls into the first category. It satisfies audit requirements. It does not produce durable behavior change. The employees who will click on the next real phishing email are the same employees who scored 85% on the annual phishing module.
The Shame Problem: Why Embarrassing Users Backfires
The security awareness industry has a significant design problem in how it handles employees who fail phishing simulations. Some platforms display immediate notification pages that tell employees they have been caught, explain why the email was a phishing attempt, and assign remediation training. The intent is to create a teachable moment. The actual effect in many organizations is to create embarrassment and resentment, which produces two counterproductive behaviors: employees begin forwarding suspicious emails to colleagues to get a second opinion before clicking (spreading the potential harm), and employees become less likely to report genuinely suspicious emails because they fear the social consequences of either being wrong (reporting a legitimate email) or being caught having almost clicked.
The behavioral science research on fear and shame as motivators is clear: negative emotion reliably increases attention to the immediate threat but decreases generalization and reduces help-seeking behavior. An employee who feels ashamed about nearly clicking a phishing simulation link will be more careful for approximately two weeks and will then avoid thinking about phishing at all, because thinking about it triggers the shame response. They will also be significantly less likely to report suspicious emails to the security team, which is exactly the behavior the program most needs to encourage.
The framing that produces better outcomes is collaborative rather than punitive. The simulation is an opportunity to practice a skill, not a test that can be failed. The notification page should say something like: you clicked on a simulated phishing link, which many people do. Here is what made this email effective, and here is how to report emails like this in the future. The emphasis should be on the action to take (report it) rather than on the mistake made (clicking). This framing maintains the teachable moment while redirecting the emotional valence from shame to capability.
Briefings like this, every morning before 9am.
Threat intel, active CVEs, and campaign alerts, distilled for practitioners. 50,000+ subscribers. No noise.
Behavioral Science: What Actually Changes Security Behavior
The research literature on behavior change in security contexts identifies three factors that consistently predict whether training produces durable behavior change: immediacy of feedback, personal relevance of the threat scenario, and low-friction alternatives to the risky behavior.
Immediacy of feedback means that learning is most effective when feedback occurs at the moment of the behavior, not a week later when the connection between the action and the consequence has faded. Just-in-time training, which fires immediately when an employee clicks a simulation link, is demonstrably more effective than the same training content delivered in a scheduled session. The employee's attention is fully on the phishing topic because they have just experienced a concrete example of it. The feedback loop is tight. The behavioral research on timing consistently finds that feedback delayed by even a few hours is significantly less effective than immediate feedback, and that feedback delayed by a day or more produces minimal behavior change.
Personal relevance means that employees learn better from examples that match their actual work context. A finance employee who receives phishing simulations using IT helpdesk password reset pretexts is being trained to recognize IT-themed phishing. Their actual risk is executive impersonation and wire transfer fraud pretexts. The mismatch between training content and real threat profile reduces transfer of training to the real-world context. Role-based simulation design is not a nice-to-have; it is a fundamental requirement for relevant training.
Low-friction alternatives to risky behavior means that the easiest action should be the safe action. If reporting a suspicious email requires opening a separate interface, finding the reporting button, writing a description, and submitting a ticket, most employees will not do it. If reporting requires a single button click via an email client plugin that sends the email directly to the security team, the reporting rate increases dramatically. Reducing friction for safe behavior is more effective than increasing friction for risky behavior.
Subscribe to unlock Remediation & Mitigation steps
Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.
Just-In-Time Training: The Intervention That Works
Just-in-time (JIT) training is the delivery model where training content is presented at the exact moment an employee demonstrates the behavior the training is designed to address. In phishing simulation terms, this means: employee clicks a simulation link, they are immediately redirected to a brief (2 to 3 minute maximum) training interaction that explains specifically why this email was a phishing attempt, what signals they should have noticed, and what to do when they receive emails like this in the future. The training concludes with a single practice scenario to reinforce the learning.
The effectiveness advantage of JIT over scheduled training is large in the research literature. Studies comparing the two approaches consistently find 30% to 50% improvement in subsequent simulation performance for JIT-trained employees versus the same employees receiving scheduled annual or quarterly training. The mechanism is not surprising from a memory consolidation perspective: information is encoded more durably when it is encountered in a state of activated attention toward the relevant domain, which is exactly the state an employee is in when they have just realized they clicked a phishing simulation link.
Implementing JIT training requires your phishing simulation platform to support custom landing pages with training content. Most major platforms (KnowBe4, Proofpoint Security Awareness Training, Cofense) support this. The landing page should be brief, non-shaming in tone, specific to the technique used in the simulation (not generic phishing advice), and must end with a clear call to action that is the reporting behavior you want to reinforce. Do not use JIT as an opportunity to deliver a compliance lecture. Two minutes of relevant, technique-specific content with a single actionable takeaway is more effective than 15 minutes of comprehensive phishing education.
Role-Based Targeting: Matching Lures to Real Threat Profiles
Generic phishing simulations use templates that approximate the average phishing email. Real attackers targeting your organization are not sending average phishing emails. They are researching specific employees and crafting pretexts tailored to their function, relationships, and context. The gap between generic simulation templates and real threat scenarios is the primary reason why even employees who perform well on simulations still fall victim to sophisticated spear phishing.
Role-based simulation design closes this gap by aligning simulation pretexts with the actual attack patterns targeting each role category. Finance employees are most commonly targeted with BEC (Business Email Compromise) pretexts: impersonated executives requesting urgent wire transfers, fake vendor invoices requiring payment update, or HR-spoofed payroll redirect requests. Simulations for finance teams should use these pretexts specifically. Generic IT helpdesk templates are not the relevant threat.
Executives and their assistants are targeted with spear phishing using publicly available information: board meeting dates pulled from SEC filings, conference appearances sourced from LinkedIn, and personal details aggregated from social media. Simulations for executive-level employees should reflect this research-driven personalization. The simulation pretext might reference an actual upcoming conference the executive is attending or a board member whose name is in the proxy statement.
IT staff are targeted with credential harvesting through fake IT tool update notifications, fake multi-factor authentication prompts, and social engineering through the help desk channel. IT-specific simulations should use these vectors. The VPN renewal notification, the MFA re-enrollment request, and the fake GitHub security alert are all more realistic threats for IT staff than the standard invoice approval lure.
Subscribe to unlock Remediation & Mitigation steps
Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.
The Reporting Metric That Matters More Than Click Rate
Most security awareness programs optimize for click rate reduction as the primary success metric. This is understandable because click rate is easy to measure and produces a clear number to report to leadership. But click rate measures the wrong behavior. Click rate measures how many employees fail. It does not measure how many employees succeed at the behavior that actually matters for organizational security: reporting suspicious emails to the security team before clicking.
The suspicious email report rate (sometimes called the resilience ratio: reports divided by clicks) is the metric that predicts actual organizational risk reduction. An organization where 5% of employees click phishing simulations and 30% report them before clicking is significantly more resilient than an organization where 3% click and 2% report. In the first scenario, the security team receives early warning about phishing campaigns targeting the organization and can respond before the 5% of clickers create an incident. In the second scenario, the security team is blind until an incident has occurred.
Building the reporting rate requires both the technical infrastructure (one-click reporting plugin) and the cultural infrastructure (positive acknowledgment of reports, visible follow-through when employees report real threats). The security team should review every reported phishing email, even simulation reports, and respond with a brief acknowledgment and a note about whether the email was a simulation or a real threat. This response loop communicates to the reporting employee that the report was received, was useful, and had a concrete outcome. That feedback loop is what converts a one-time reporter into a habitual reporter.
Interpreting Simulation Data Honestly
Phishing simulation data is subject to significant interpretation bias that produces misleading program metrics if not addressed explicitly. The most common form of bias is measurement frequency distortion: running monthly simulations creates artificial awareness elevations in the days following each simulation, which depresses the click rate for the measurement period while not representing the actual sustained behavioral change.
A cleaner measurement methodology is to run a quarterly baseline simulation using a new template that has not been used before, rather than monthly simulations with consistent templates. The quarterly baseline measures the actual behavioral state of the employee population without the recency effect of a recent simulation. Monthly simulations can continue for training purposes, but the reported metric should be the quarterly baseline, not the monthly simulation result. The monthly numbers should be used for program management and content improvement, not for leadership reporting.
Simulation template difficulty must be controlled for when comparing click rates over time. A program that starts with generic Microsoft password reset templates and evolves to use personalized executive impersonation templates will show an increasing click rate even if employee security behavior is actually improving. Maintain a consistent difficulty tier for baseline measurements, and report template difficulty alongside click rate in any longitudinal comparison. Improvement against hard templates is more meaningful than improvement against easy templates, and the trend only makes sense when template difficulty is held constant.
Integrating Simulations With Real Phishing Investigation
One of the most underutilized aspects of mature phishing simulation programs is the integration between simulation reporting workflows and real phishing investigation workflows. In most organizations, these two workflows are completely separate: reported simulations go to the training platform dashboard and are tracked as simulation metrics, while reported real phishing emails go to the security team for analysis. Employees experience them as completely different processes, which creates a mental model disconnect.
Integrating the two workflows means having reported simulations go through the same triage process as reported real phishing emails. The security team receives the report, analyzes it (or in the case of known simulations, flags it as such quickly), and responds to the employee with the outcome. When an employee reports a real phishing email that the security team determines is malicious, the security team can treat this as a high-signal event: send a notification to the full organization about the active campaign, pull the email from other recipients' inboxes using the email security platform's admin tools, and initiate any threat hunt work suggested by the indicators in the email.
This integration produces a clear organizational value chain: employee receives suspicious email, employee reports using the plugin, security team identifies a real campaign, security team removes the email from other recipients before they click. The employees who report are directly contributing to a security outcome that is visible and communicated. This is the organizational reinforcement loop that converts a compliance program into a genuine security culture. The ROI calculation is straightforward: the labor cost of triaging reported simulations is small compared to the value of a single real phishing email caught before it produces an incident.
What Good Looks Like: Metrics, Timelines, and Leadership Reporting
A well-designed security awareness program with role-based simulation design, JIT training, and active reporting culture produces measurable improvements on a 12 to 18 month timeline. The expected trajectory is: initial baseline of 10% to 25% click rate depending on organization and industry, dropping to 8% to 12% within 6 months as the JIT training and frequent simulation cadence takes effect, dropping to below 5% within 12 to 18 months as role-based simulation design closes the gap between training content and real threat scenarios, and a reporting rate that grows from near-zero to 20% to 40% of employees over the same period.
These targets are achievable, but they require the program design changes described in this guide. Organizations running generic monthly simulations with no JIT training and no reporting culture infrastructure will plateau at 8% to 12% click rate and a reporting rate below 5%. That plateau is the empirical signature of a compliance program that is not producing meaningful behavior change.
For leadership reporting, the three-metric summary that communicates program health accurately is: click rate trend (quarterly baseline over trailing 4 quarters), report rate trend (percentage of simulation emails reported before clicking, same period), and real-threat report rate (actual phishing emails reported per thousand employees per month, which is the metric that demonstrates the program's operational security value). The click rate alone tells leadership nothing about organizational resilience. The combination of decreasing click rate and increasing report rate tells the story of a program that is actually working.
The bottom line
Security awareness training works when it is built on behavioral science rather than compliance assumptions. The organizations with sub-5% phishing click rates did not get there through more training. They got there through better-timed training (just-in-time at the moment of failure), more relevant content (role-based simulation design that matches real attack patterns), and a deliberate effort to make the safe behavior (reporting) easier than the risky behavior (clicking). The metric that proves the program is working is not click rate alone. It is the ratio of reports to clicks, and the real-phishing reports per thousand employees per month that demonstrate the program's actual security value. Build toward those metrics and the click rate improvement follows.
Frequently asked questions
How many phishing simulations per year is the right cadence?
The research on simulation frequency suggests that more frequent simulations (monthly or bi-monthly) produce better outcomes than quarterly or annual simulations, provided the templates change with each campaign and the JIT training is properly implemented. Running the same template monthly produces diminishing returns after the second or third exposure. The practical recommendation is monthly simulations with template rotation, using a quarterly unannounced baseline simulation with a novel template for the official program metric. Avoid running simulations around major holidays or high-stress periods, as timing effects can confound your data and the contextual validity of those simulations is lower.
Should we tell employees that we run phishing simulations?
Yes, at a program level. Employees should know that phishing simulations are part of the security program and that clicking a simulation link will result in brief training, not disciplinary action. This transparency does not meaningfully reduce click rates because knowing simulations exist does not help employees identify which specific emails are simulations. What it does do is eliminate the trust damage that occurs when employees feel they were deceived, which consistently reduces program participation and reporting rates. Disclose the program. Keep individual simulation content confidential.
How should we handle departments with chronically high click rates that do not improve?
Departments with chronically high click rates despite consistent training are telling you something important: either the training content is not relevant to their actual threat environment, the organizational culture in that department creates barriers to security-conscious behavior (time pressure, performance metrics that conflict with security), or there is a leadership signal problem where managers are modeling risky behavior. The intervention for chronic high-rate departments should start with a conversation with department leadership about the specific threats targeting that function and get their buy-in for role-specific simulation design. Top-down modeling of security behavior by department leadership is one of the strongest predictors of department-level behavior change.
Is there a risk that too much simulation training creates alert fatigue and makes employees ignore legitimate security notifications?
Yes, this is a real risk that is underappreciated in most programs. Employees who receive many simulations, especially simulations using templates that resemble legitimate security notifications (fake IT alerts, fake MFA prompts), can develop habituation to security warning signals. The mitigation is to design simulations that impersonate external senders rather than internal IT communications, to keep the JIT training notification visually distinct from actual security tool alerts, and to avoid using the same visual format for simulations and for real security notifications. The goal is to train employees to be appropriately skeptical of external communication, not to be skeptical of all security communications.
How do we measure the ROI of a security awareness program to justify the budget?
The most defensible ROI calculation for security awareness training combines three data points: the average cost of a phishing-originated security incident in your industry (the Verizon DBIR provides industry-specific figures), the reduction in phishing click rate attributable to the program, and the number of employees in the organization. A 10 percentage point reduction in click rate for a 2,000 employee organization with a $500,000 average phishing-originated incident cost and one phishing campaign per quarter produces an expected value calculation that is straightforward to defend. The reporting rate improvement has additional value that is harder to quantify but meaningful: every real phishing email caught through the reporting workflow potentially prevents an incident entirely.
Sources & references
Free resources
Critical CVE Reference Card 2025–2026
25 actively exploited vulnerabilities with CVSS scores, exploit status, and patch availability. Print it, pin it, share it with your SOC team.
Ransomware Incident Response Playbook
Step-by-step 24-hour IR checklist covering detection, containment, eradication, and recovery. Built for SOC teams, IR leads, and CISOs.
Get threat intel before your inbox does.
50,000+ security professionals read Decryption Digest for early warnings on zero-days, ransomware, and nation-state campaigns. Free, daily, no spam.
Unsubscribe anytime. We never sell your data.

Founder & Cybersecurity Evangelist, Decryption Digest
Cybersecurity professional with expertise in threat intelligence, vulnerability research, and enterprise security. Covers zero-days, ransomware, and nation-state operations for 50,000+ security professionals every morning.
Win a $2,495 Black Hat pass.
Full-access to Black Hat USA 2026 in Las Vegas. Subscribe free to enter.
