Sep 24, 2026
Security awareness training: why phishing simulations alone don't change behavior
A falling click rate looks like success, but measures very little. What actually changes behavior in security differs from what most training programs track.
Almost every mid-size-and-up company runs some kind of phishing simulation program: sends a controlled fake email, measures who clicked, reports a falling click rate year over year as proof the training works. The problem is that a click rate in a controlled simulation measures very little about how the same person reacts to a real attack, under time pressure, with technical quality that only keeps improving.
That becomes even clearer in light of how much synthetic content already fools people who know the problem exists — if human deepfake detection is already close to random, betting everything on someone's ability to "notice something's off" is a strategy with an increasingly short shelf life.
What click rate actually measures, and what it doesn't
A simulation measures whether someone clicked a controlled link, in a context that — no matter how well designed — the person knows, somewhere in the back of their mind, could be a company test. That's structurally different from recognizing a real attack, coming from a sender that perfectly imitates a genuine vendor, on a busy workday, with no signal at all that it's a test.
A falling click rate can mean real learning — or it can mean the team learned to recognize the specific pattern of that company's own simulations, which is pattern-matching, not risk judgment.
The problem with treating training as an annual event
Mandatory security training done once a year as a compliance checkbox has a behavior retention rate close to zero after a few months. Sustained behavior change requires spaced repetition and reinforcement at the moment the decision actually happens — not a video watched in October for a decision made in March.
Simulation turns into a cat-and-mouse game, not learning
After a few rounds, employees often learn to recognize the specific characteristics of their own company's simulations — sender domain, subject line pattern, time of day sent — without necessarily improving their ability to judge a genuinely unfamiliar email. The result is an optimized click-rate metric that doesn't reflect real risk reduction, just familiarity with the test.
That doesn't mean abandoning simulation — it means not treating it as the entire program's success metric, just one tool among several.
What actually changes behavior
Three elements account for most of the real effect: feedback at the exact moment of the decision (not an aggregated monthly report), a reporting mechanism easier than the attack itself — a "report suspicious" button that takes less effort than clicking —, and explicit positive reinforcement for reporting, even when the reported email turns out to be legitimate. Punishing only those who click, without rewarding those who report, teaches people to avoid visibility, not to act well.
The right metric isn't click rate, it's report rate
Companies that matured this program shifted the primary indicator from "how many clicked" to "how many reported, and how fast" — a metric that measures proactive behavior, not just absence of error. That shift in indicator also communicates better to the board: a rising reporting trend signals a maturing security culture, something far harder to tell a story about using click rate alone.
Habits are built, not decreed
No training program replaces technical control — EDR, email filtering, and multi-factor authentication remain the first line of defense —, but well-trained human behavior reduces the volume that ever reaches those controls. UNIQ helps clients design awareness programs with metrics that reflect real behavior, not just comfort with the test itself.