Key Summary
- The original author observes that certain users within the organization repeatedly record near-50% failure rates in phishing simulations, and has concluded that additional training alone does not drive behavioral change
- The original post reveals a perception that indifference plays a larger role than lack of learning ability
- The most frequently proposed solution in community responses is escalation to higher decision-making lines such as HR and executive leadership, an area that is difficult to address by the security team alone
Analysis
Table of Contents
- Key Summary
- Why the Same Person Keeps Clicking
- Redefining Phishing Simulation Failure Criteria
- 7-Step Practical Procedure for Repeat Failures
- Common Mistakes in Practice
- Combining Policy, Training, and Technical Controls on One Page
- What to Do Right Now
- Practical Application Points
- Frequently Asked Questions
- Reference Source
If you have ever reviewed phishing simulation results and seen the same name light up in red every quarter, you know the moment. One employee repeats a near-50% failure rate, and two or three others in the same department follow the same pattern. You send additional training, run another simulation, and the next quarter that name shows up again. This is the point where the security team can no longer solve the problem alone.
Why the Same Person Keeps Clicking
Phishing simulation failures fall into two categories. One is a lack of learning ability, and the other is sufficient ability without behavioral change. The cases you encounter repeatedly in practice are mostly the latter. Users know what phishing is, but work priorities, alert fatigue, and habitual clicking prevent behavior from changing.
There are clear structural reasons why training fails to deliver results. A 15-minute training session once per quarter is too low in intensity, immediate feedback after a failure is lacking, and above all, the issue tends to be framed as individual awareness improvement rather than organizational responsibility. The solutions frequently mentioned among practitioners sharing the same concern converge on one point: do not try to solve this with training alone — raise policy, training, and technical controls simultaneously.
Redefining Phishing Simulation Failure Criteria
The first thing to define is what “failure” means. “Opening an email” and “entering credentials” carry different risk levels. The former can happen out of simple curiosity or an automatic preview pane, while the latter is clearly a risky behavior. Bundling these two together as a single failure distorts actual exposure by department and seniority.
Next, failure data must be accumulated and tracked by department, seniority, and time period. Distinguishing whether the same person fails repeatedly every quarter, whether failures concentrate in a specific department, or whether they spike temporarily around year-end or the start of the year will naturally clarify your response priorities.
7-Step Practical Procedure for Repeat Failures
Step 1. Redefine Failure Criteria into Four Levels
Divide actions into four stages — “email opened → link clicked → credentials entered → attachment executed” — and document the risk level of each stage in the policy document. Credential entry and attachment execution should be tracked separately as high-risk behavior.
Step 2. Accumulate and Objectify Data
Separate quarterly failure rates, lists of repeat failures, departmental concentration, and high-risk behavior ratios into a dedicated dashboard. Whether a near-50% failure rate repeats for one individual or is spread across the organization determines the next step.
Step 3. Escalate to the HR and Executive Line
Individual-level sanctions cannot be decided by the security team alone. Submit quantitative data showing that repeat failures could lead to actual incidents, and secure alignment on policy changes and delegation of authority. This is the point where the author gets stuck longest in practice, because the act of restricting a user account itself touches HR and legal review territory.
Step 4. Tiered Mandatory Training
The pattern frequently discussed in the community is escalating intensity. One hour of mandatory training after the first failure, a full-day program after the second cumulative failure, and a one-week intensive course after the third. The key is that this is not an “additional notice” but a “mandatory schedule that cannot be avoided.” Hand over the authority for completion verification directly to HR.
Step 5. Automatic Lockout and Supervisor-Based Unlock
After three cumulative failures, automatically block external email access for the affected account. Design the unlock so that it is only possible with approval from a supervisor or the head of the security team. This policy is the most direct way to make users feel the “cost of clicking.” At the same time, separating approval authority so that the security team cannot arbitrarily unlock accounts increases policy credibility.
Step 6. Reinforce Technical Controls
Controls that rely solely on user behavior will eventually break down. At the mail security gateway, force new domain URLs through an automatic quarantine page, block macro attachments by default, and allow external cloud shared links to be opened immediately only for whitelisted domains. A safety net that makes the user’s click itself less dangerous is essential.
Step 7. Policy Documentation and Periodic Reassessment
If “who does what” is not left as a one-page policy, every procedure becomes blurred the moment the responsible person changes six months later. Formalize the responsible party, approval line, unlock procedure, and reassessment cycle (e.g., once per quarter), and obtain executive approval before publicizing it.
Common Mistakes in Practice
The most common mistake in operating phishing simulations is simply increasing the number of training sessions. User behavior is the result of system design, not training hours. Another mistake is setting failure criteria too broadly, burying high-risk behavior. Counting “email opened” as a failure makes the data richer but fails to surface actual incident risk.
If you strengthen policy without technical controls, users will find another path to meet their deadlines. Policy, training, and technical controls must move together to be effective.
Combining Policy, Training, and Technical Controls on One Page
Phishing simulation is not a project for the security team alone. Users, HR, executives, and IT infrastructure must all look in the same direction to reduce repeat failures, and that is what ultimately raises the organization’s overall phishing resilience. Starting from the smallest thing you can review today is a realistic starting point. Real-world discussions among practitioners on this topic can be found in the field discussion on users who repeatedly fail phishing simulations.
What to Do Right Now
- Within this week, redefine phishing simulation failure criteria into four levels (opened, clicked, credentials entered, attachment executed)
- Share the quarterly list of repeat failures with HR and request a single quantitative data meeting
- Review the new domain URL quarantine policy at the mail gateway as the top priority
- Submit a draft policy for automatic lockout after three cumulative failures and supervisor-based unlock as an executive agenda item
- Summarize the policy document into a one-page PDF, announce it internally, and register a quarterly reassessment schedule on the calendar
Practical Application Points
- Separate failure criteria into four levels and track only high-risk behavior (credential entry, attachment execution) separately
- Escalate repeat failures to the HR line with quantitative data to break out of the single-decision-maker structure
- Design automatic lockout after three cumulative failures with supervisor-based unlock to eliminate arbitrariness
- Lay a safety net with mail gateway, link quarantine, and attachment blocking to reduce click risk itself
- Summarize the policy document on one page and run a quarterly reassessment cycle
Frequently Asked Questions
How should phishing simulation failure criteria be defined?
In phishing simulations, it is effective in practice to divide user actions into four stages — email opened, link clicked, credentials entered, and attachment executed — and aggregate only the latter two as a separate high-risk group for tracking. Bundling them as a single failure distorts actual exposure by department and clouds priority decisions.
Doesn’t the automatic lockout policy cause significant user backlash?
When applied only after three cumulative failures, with unlock authority separated to a supervisor or the head of the security team, users perceive it not as an “arbitrary block” but as an “approval-based procedure.” Announcing it in a policy document in advance and securing HR approval significantly increases acceptance.
Does tiered mandatory training really work?
Mandatory scheduling is a bigger variable than training hours. Escalating intensity to one hour for the first failure, one day for the second, and one week for the third, with HR directly verifying completion, is effective. It is the fact that the training “cannot be avoided” that changes user behavior, not the content itself.
If technical controls are strengthened, is training unnecessary?
No. Even if technical controls reduce click risk, leakages recur when bypass routes emerge (personal email, external messengers, mobile mail apps). Policy, training, and technical controls must move together for the effect to be sustained.
Reference Source
This article was written after reviewing the following original source: r/cybersecurity — Users repeatedly failing phishing campaigns
Expert Commentary (AI)
Information Security Expert
The shift from training to systems is a validated direction, but a punishment-centric design and failure to reflect the MFA era are major weaknesses
The approach of addressing the repeat failure problem not through individual training but through a combination of policy, training, and technical controls aligns with the standard evolution path of a mature security program, and the idea of layering failures into opened, clicked, credentials entered, and attachment executed is a worthwhile design that reflects the risk-level differences of the actual phishing kill chain. However, a punishment structure centered on automatic lockout and cumulative sanctions directly conflicts with industry experience and research showing that punitive structures lower the voluntary reporting rate of suspicious emails, and without a parallel design that tracks core metrics not only by click rate but also by reporting rate and time-to-report, defense measurement can move backwards. The four-level classification also represents a structural gap in that it does not include MFA approval behavior. In an era where AiTM man-in-the-middle phishing and push bombing have become mainstream threats, the last line of defense after credential entry is whether MFA is approved, so this classification system remains rooted in an outdated threat model. The direction of mandatorily layering technical safety nets such as link quarantine, macro blocking, and whitelisting is correct. In the long term, as passkeys and phishing-resistant authentication become widespread, the very meaning of measuring credential-entry-type training will be redefined, so this procedural framework should also be viewed as a subject for annual redesign.
Industrial/Organizational Psychology & Security Culture Expert
The problem definition that behavior is a product of the environment is valid, but the disciplinary procedure thinly addresses labor risk and motivation balance
The diagnosis that indifference and alert fatigue are a larger cause of failure than lack of learning ability is a standard insight from behavioral science, and the thesis that environmental design, not training hours, determines behavior is a fact repeatedly confirmed in organizational behavior research. The design of attaching prior notice, separation of approval authority, and supervisor-based unlock procedures to cumulative sanctions is a strength in that it meets procedural fairness requirements. However, sharing individual lists and account lockouts effectively have the effect of personnel sanctions, so implementing them without reviewing procedures under labor standards law, explicit statements in the rules of employment, and the legal basis for processing personal information carries a significant dispute risk. In addition, without a diagnostic procedure that distinguishes whether a 50% failure rate is a signal of individual carelessness or a signal of mismatch between training difficulty and actual work context, the organization easily converges on a “blame the employee” frame. Returning to a purely punitive approach without positive enforcement devices such as rewards for rapid reporting carries the risk of the security culture devolving into a game of surveillance and evasion.
Critical Analyst
Behind the narrative of the “indifferent repeat failure,” the budget and authority-expansion interests of the security side holding difficulty calibration power lurk
On the surface, it reads as sound practical advice to shift from training to systems, but looking at the other side, this entire discussion takes for granted metrics produced by the party that holds the authority to set simulation difficulty and aggregate failure rates, without any external channel to verify them. From the perspective of the security team or external vendor that designs and aggregates training campaigns, the higher the failure rate, the greater the structural incentive for budget, tool adoption, and account control authority expansion, so the figure of 50% is both an indicator of employee indifference and possibly an indicator colored by the designer’s interests. The flow of taking a community thread as raw material, repackaging it as a 7-step procedure and checklist with external links for distribution reads less like educational content and more like a typical pipeline aimed at search traffic and consulting leads. The automatic lockout and supervisor-based unlock policy, while wearing the face of constraining the security team’s arbitrariness, can in practice become an institutional channel that permanently delegates account usage restriction discretion to the management line. What we should really pay attention to is not the sophistication of the 7-step procedure, but the fact that the question of who defines failure and difficulty and whose budget and authority is allocated by those numbers passes through without any verification channel anywhere. Before the employee is marked as a failure, who will verify the conflict of interest of the training designer first.
Underlying Scenarios
- Scenario in which simulation difficulty is internally adjusted upward to inflate failure rates and secure budget and sponsorship: The figure of an individual repeatedly recording a failure rate approaching 50% every quarter is abnormally high at standard difficulty, and can be read as circumstantial evidence of intervention by the designer’s authority in the repeated deployment of spear-phishing-level difficult campaigns.
- Scenario in which the lockout/approval unlock policy hardens into a labor control tool under the banner of security: Once HR escalation and automatic lockout are standardized, the discretion to restrict account access is effectively transferred to the management line as a standing authority, opening a structural channel for it to be repurposed not for security but as justification for performance pressure or managing underperforming employees.
Leave a Reply