Most phishing-awareness programmes measure the wrong thing and change nothing. Sending a scary test email and publishing a click rate does not build a security culture. Here is what does — and how the approach cut phishing click-through from 15% to 11% at a large organisation I worked with.
Why most simulations fail
They are one-off, generic and punitive. People feel tricked, IT looks like the enemy, and behaviour reverts within weeks. Worse, punitive programmes teach exactly the wrong lesson: staff who fear blame stop reporting — and reporting is the behaviour that actually saves you during a real attack. Awareness is a habit, and habits are built with repetition and support, not a single gotcha.
Design for behaviour change
- Tailor scenarios to real threats. Finance sees fake invoices and payment-change requests; engineering sees fake repo and SSO prompts; executives see whaling. Generic “you won a prize” tests measure nothing.
- Teach in the moment. A short, friendly explainer right after a click — what the tell-tales were, what to do next time — beats an annual slideshow by a mile. The click is the teachable moment; don’t waste it on shame.
- Make reporting easy and celebrate it. One-click report buttons, fast feedback, and public credit for good catches. A high report rate is a better metric than a low click rate.
- Vary difficulty. Mix obvious lures with hard ones; an all-easy programme flatters the numbers and fools no attacker.
A cadence that builds the habit
Run small, regular waves — monthly or bi-monthly — rather than one annual blast. Rotate templates and departments, follow each wave with its micro-lesson, and brief managers so they reinforce rather than punish. Give repeat clickers extra coaching privately; give consistent reporters visibility. Over a few cycles the culture shifts from “don’t get caught” to “we catch these together” — and that shift is what shows up in the metrics.
Measure what matters
- Click-through rate — trended over time and by team, never as a single headline number.
- Report rate — the star metric: how many people flagged the simulation (and how fast).
- Time-to-first-report — your realistic detection window when a real campaign lands.
- Repeat-click cohort — small, addressable with coaching, and a far better use of energy than blaming everyone.
Improvement compounds when people understand the “why” and feel like part of the defence, not the problem. That 15% → 11% shift wasn’t a trick — it was months of consistent, supportive repetition, measured honestly.
Where this fits in your wider programme
Awareness is one control, not the whole defence. It belongs alongside technical hardening and governance — the same system of controls an ISO 27001 ISMS formalises, and the human complement to the technical weaknesses a penetration test finds.
Want a phishing-simulation and awareness programme that actually changes behaviour — designed, run and measured? That’s one of my core services. Get in touch and let’s talk about your team.