QuietHours by securITDiscuss your scope

Operations

Why security awareness training fails, and what phishing simulation should measure

Most awareness programmes are designed to be completed, not to change anything. They generate a completion percentage for an auditor and a click rate for a board, and neither number has much relationship to whether your organisation would survive a targeted attack.

Minimalist dot field with one accented point and crosshair

NIS2 requires basic cyber hygiene practices and cybersecurity training, and requires management to undergo training as well. That obligation is being met across Europe with annual e-learning modules and quarterly phishing simulations. The obligation is satisfied. The risk is largely unchanged. It is worth understanding why.

The three structural failures

1. Annual training fights forgetting and loses

A thirty-minute module in January has limited bearing on a decision made under time pressure in September. This is not a failure of attention or of content quality; it is how memory works for material that is not reinforced and not immediately applied.

Short, frequent, contextual interventions outperform long annual ones consistently. Two minutes of relevant content at the moment something is encountered beats thirty minutes of comprehensive content eight months earlier.

2. Click rate is the wrong target

Click rate is easy to measure, easy to reduce, and easy to game. Sending obvious simulations produces excellent numbers and teaches nothing. More importantly, click rate measures the wrong stage of the incident.

Someone will always click. In a large enough organisation, a sufficiently well-crafted lure will succeed against someone every time — including against security-aware staff, because a good pretext exploits legitimate work pressure rather than ignorance. Building a defence that depends on a zero click rate is building on a foundation that cannot hold.

3. Punishment destroys the thing that actually helps

Programmes that name, shame or discipline clickers reliably reduce reporting. Staff who click and fear consequences stay silent, which converts a two-minute containment into a two-week investigation. The behaviour you most need is a rapid report from someone who has just made a mistake, and punitive programmes are precisely engineered to prevent it.

What to measure instead

MetricWhy it mattersHealthy direction
Reporting rateDetermines whether you can contain a live campaignUp, consistently
Time to first reportDetermines how much of the campaign you can pull backDown, measured in minutes
Report-to-click ratioBalances the two behaviours in one numberUp
Repeat clickers who also reportShows the culture is working even when the click happensUp
Triage time per reportReporting only helps if someone acts on itDown, and staffed
Click rateStill worth tracking as contextSlowly down, not optimised

The fifth row is the one organisations forget. A successful reporting culture generates volume, and if reports sit in a shared mailbox for six hours, you have trained people to do something useless. Reporting must be paired with a triage capability and a visible response, or the behaviour extinguishes.

Designing simulations that teach something

  1. Use realistic pretexts drawn from your actual environment — your suppliers, your systems, your internal terminology. Generic templates teach people to spot generic templates.
  2. Vary difficulty deliberately and report results by tier. An easy campaign and a hard one measure different things, and averaging them measures neither.
  3. Make reporting one click, in the tool people already use, with immediate acknowledgement. Friction here dominates every other design decision.
  4. Give feedback within seconds of a click, in context, short. A landing page that explains the three specific signals in that specific email is worth more than a module.
  5. Never punish. Publish improvement at team level rather than failure at individual level.
  6. Include leadership. Executives are the most targeted group and often the most exempted from simulation, which is precisely backwards. NIS2 explicitly requires management training.

What awareness cannot fix

This matters for budget allocation. Some risks are commonly assigned to awareness training and are not solvable there.

  • Credential phishing is fundamentally solved by phishing-resistant authentication, not by vigilance. If a stolen password alone is enough to log in, awareness is compensating for an architectural gap.
  • Business email compromise is defeated by a payment verification process with an out-of-band check, not by staff scepticism under deadline pressure.
  • Malicious attachments are an endpoint control problem. Attachment handling policy and endpoint protection do more than training.
  • Consent phishing — where a user grants an OAuth application access rather than entering a password — is largely an admin consent policy question. Most users cannot reasonably evaluate a permission request.

The honest framing is that awareness training is a detection layer, not a prevention layer. Its job is to produce a fast report when a technical control has already failed. Measured against that job, it is genuinely valuable — and it is measured by reporting rate, not by click rate.

A programme that works

Short monthly content tied to something real that happened, ideally internally. Quarterly simulations with varied difficulty and realistic pretexts. One-click reporting with acknowledgement in seconds and visible triage. No punishment, ever. Leadership included rather than exempted. Reporting rate on the board slide instead of click rate. And phishing-resistant authentication deployed underneath all of it, so that the occasions when awareness fails are survivable.

Frequently asked questions

What is a good phishing simulation click rate?

Click rate is a weak target because it is easy to game with obvious simulations and because someone will always click a sufficiently good lure. Reporting rate and time to first report are far better measures, since they determine whether a live campaign can be contained before most recipients open it.

Should employees be punished for failing phishing simulations?

No. Punitive programmes reliably reduce reporting, because staff who click and fear consequences stay silent — turning a two-minute containment into a lengthy investigation. Publish improvement at team level rather than failure at individual level.

Does NIS2 require security awareness training?

NIS2 lists basic cyber hygiene practices and cybersecurity training among the minimum risk-management measures, and Article 20 separately requires members of management bodies to follow training. Entities are also encouraged to offer similar training to employees on a regular basis.

Talk to the team

Need this tested rather than described?

QuietHours is a European cybersecurity practice operated by the securIT team. Send us the system, service, or control you are concerned about and we will help turn it into a workable scope.

Discuss your scope

Related reading