Phishing Simulations That Actually Change Behaviour

Most phishing-awareness programmes measure the wrong thing and change nothing. Sending a scary test email and publishing a click rate does not build a security culture. Here is what does — and how the approach cut phishing click-through from 15% to 11% at a large organisation I worked with.

Why most simulations fail

They are one-off, generic and punitive. People feel tricked, IT looks like the enemy, and behaviour reverts within weeks. Worse, punitive programmes teach exactly the wrong lesson: staff who fear blame stop reporting — and reporting is the behaviour that actually saves you during a real attack. Awareness is a habit, and habits are built with repetition and support, not a single gotcha.

Design for behaviour change

  • Tailor scenarios to real threats. Finance sees fake invoices and payment-change requests; engineering sees fake repo and SSO prompts; executives see whaling. Generic “you won a prize” tests measure nothing.
  • Teach in the moment. A short, friendly explainer right after a click — what the tell-tales were, what to do next time — beats an annual slideshow by a mile. The click is the teachable moment; don’t waste it on shame.
  • Make reporting easy and celebrate it. One-click report buttons, fast feedback, and public credit for good catches. A high report rate is a better metric than a low click rate.
  • Vary difficulty. Mix obvious lures with hard ones; an all-easy programme flatters the numbers and fools no attacker.

A cadence that builds the habit

Run small, regular waves — monthly or bi-monthly — rather than one annual blast. Rotate templates and departments, follow each wave with its micro-lesson, and brief managers so they reinforce rather than punish. Give repeat clickers extra coaching privately; give consistent reporters visibility. Over a few cycles the culture shifts from “don’t get caught” to “we catch these together” — and that shift is what shows up in the metrics.

Measure what matters

  • Click-through rate — trended over time and by team, never as a single headline number.
  • Report rate — the star metric: how many people flagged the simulation (and how fast).
  • Time-to-first-report — your realistic detection window when a real campaign lands.
  • Repeat-click cohort — small, addressable with coaching, and a far better use of energy than blaming everyone.

Improvement compounds when people understand the “why” and feel like part of the defence, not the problem. That 15% → 11% shift wasn’t a trick — it was months of consistent, supportive repetition, measured honestly.

Where this fits in your wider programme

Awareness is one control, not the whole defence. It belongs alongside technical hardening and governance — the same system of controls an ISO 27001 ISMS formalises, and the human complement to the technical weaknesses a penetration test finds.

Want a phishing-simulation and awareness programme that actually changes behaviour — designed, run and measured? That’s one of my core services. Get in touch and let’s talk about your team.

Bader Alkandery

Freelance cybersecurity, GRC & data-protection consultant in Kuwait — MSc Cyber Security & Networks (Best Paper), CompTIA Security+.

Keep reading

More insights