Cybersecurity · Training

Why every failed phishing test should start a conversation

Written by the Mono training team · · 15 min read Share
Executive summary When an employee fails a phishing simulation, most platforms respond the same way: assign a remediation module, mark the user as high-risk, and move on. The evidence says this approach doesn't work — and in many cases actively undermines the behaviour change it claims to produce. This article examines why automated remediation fails, what adult learning research actually recommends, and how a structured, human-led intervention produces measurably better outcomes by treating a failed simulation as a diagnostic signal, not a compliance event.
Data sources
Prümmer et al., Leiden University — 2024 meta-analysis of 69 studies·Hoxhunt Phishing Trends Report (2026)·ASD's ACSC Annual Cyber Threat Report 2024–25·Edmondson, A. — psychological safety research, Harvard Business School
Figures reflect publicly reported research as of mid-2026. Findings evolve — verify current studies before citing externally.
01A closed loop that doesn't close anything

The standard response to a failed phishing test is broken

The pattern is ubiquitous. An employee clicks a simulated phishing link. The platform flags them. An automated remediation module is assigned — typically a 10–15 minute video or slide course explaining what phishing is and how to spot it. The employee completes the module. The platform marks them as remediated. Everyone moves on.

This sequence feels like accountability. It looks like a control. On a compliance dashboard, it presents as a closed loop. But the evidence says it doesn't produce the behavioural outcome it claims to — and in many cases, it produces the opposite.

Most platforms measure whether someone completed a remediation module. Almost none measure whether the remediation changed anything.

It treats a behavioural signal as a knowledge gap. The assumption behind automated remediation is that the employee clicked because they didn't know what phishing looks like. In most cases, that isn't what happened — they clicked because they were distracted, under time pressure, trusted the sender, or were operating on autopilot. A module explaining what phishing is doesn't address any of those causes.

It assigns the same intervention regardless of cause. A finance director who clicked a sophisticated BEC lure during quarter-end receives the same generic module as a new starter who clicked a mass-market credential harvest. The platform can't distinguish between these — it doesn't ask why, it only records that.

02The cost nobody's measuring

The reporting paradox

There's a second, less visible cost. Employees who've been through the remediation loop once become measurably less likely to report suspicious activity next time. The logic is straightforward: if clicking something suspicious triggers a mandatory training module, the safest course of action is to not report at all. The remediation loop, designed to improve detection, suppresses the very behaviour — reporting — that matters most.

ASD's ACSC records social engineering in 60% of all cyber incidents reported to Australian authorities in FY2024–25, and explicitly flags under-reporting as a systemic concern. Punitive remediation contributes directly to the gap between what's happening and what organisations actually know about.

Research on psychological safety in learning environments — most notably Amy Edmondson's foundational work at Harvard Business School — is unambiguous on this pattern: people who feel punished for mistakes learn to hide mistakes, not to avoid them. A remediation loop experienced as punishment, even when organisations frame it otherwise, produces exactly this effect.

03A different model entirely

A conversation, not a module: the Supported Growth Pathway

The Supported Growth Pathway is a six-stage, human-led intervention model for employees who emerge as high-risk through behavioural indicators. It's non-punitive, confidential, and evidence-based. Its foundational principle: a failed simulation is a diagnostic signal — it tells you something about the employee's context, confidence, or cognitive load that a module can't address and a platform can't see.

Stage 01 · Identification

The platform flags an individual as high-risk based on multi-factor behavioural indicators — a pattern across simulation performance, module engagement, and reporting behaviour, not a single failure. Invisible to the employee. No notification, no shame trigger, no manager alert at this stage.

Stage 02 · Root cause diagnostic

A trained consultant or internal champion conducts a brief, private, structured 15–20 minute conversation — the cornerstone of the pathway. Does the individual understand why security matters in their role? Are they overwhelmed by content volume? Is there a confidence issue with digital tools? Is workload a factor? Do they feel safe reporting without fear of blame?

Stage 03 · Personalised micro-intervention

Based on the diagnostic, one of three tailored tracks is activated — each addressing the identified root cause and rebuilding confidence, because confidence is what turns knowledge into action.

Stage 04 · Graduated re-engagement

Return to active simulations is staged around one principle: small wins build confidence, and confidence produces lasting behaviour change. Simulations begin at reduced complexity and increase only as performance improves.

Stage 05 · Transition and recognition

When behavioural indicators improve consistently over a defined period — typically 60 days — the individual transitions back to the standard risk tier, noted positively rather than as a lingering flag.

Stage 06 · Peer guide intervention

For the small cohort of persistent non-improvers, the research is consistent: the most powerful force for change isn't a program — it's a person. A trained internal champion is paired as a peer guide, providing reinforcement no module can replicate.

04Matching the cause, not the symptom

Three tracks, three different root causes

Stage 03's intervention is only as good as the diagnostic that precedes it. Three tracks cover the vast majority of root causes uncovered in practice.

Low awareness

Role-specific scenario walkthrough, delivered 1:1 or in a small private group. Content drawn from current sector threat intelligence, not a generic library.

Low confidence

Simplified, confidence-building content. Buddy system with a trained internal security champion. Security reframed as personal empowerment, not obligation.

High workload

Micro-bursts of 3–5 minute content, different delivery timing, and optional consent-based manager awareness to reduce cognitive load rather than add to it.

05The honest answer

Why this can't be automated

The natural question is whether this pathway could be replicated by a platform — using AI to conduct the diagnostic, assign the intervention, and manage re-entry. The honest answer is that it can't, and understanding why matters for evaluating any awareness program.

Automated platform response
Employee clicks simulated phish → platform assigns remediation module → employee completes module → platform marks as remediated.
Time: 15 minutes Human involvement: zero Root cause identified: none Outcome measured: completion only
Human-led pathway response
Behavioural pattern triggers identification → private diagnostic conversation → root cause identified → tailored intervention → graduated re-entry → transition celebrated.
Time: days to weeks Human involvement: central Root cause identified: always Outcome measured: performance, reporting, confidence

The diagnostic conversation is the control that matters. It can't be replicated by a chatbot, a survey, or an adaptive module because it requires reading context — tone, the unspoken factors behind a click — that only a human can perceive. An employee overwhelmed by workload won't tell a platform that. They'll tell a person they trust, in a conversation where they feel safe.

The peer guide intervention requires social trust. Pairing a struggling employee with a trained internal champion works because of the relationship between those two people — not the content delivered. Platforms can assign mentors; they can't manufacture the trust that makes mentorship work. And the decision to increase simulation difficulty for a recovering employee isn't a threshold calculation — it requires distinguishing genuine confidence from surface compliance, a distinction visible to a human observer in ways it isn't to a scoring algorithm.

Key takeaways

What to take into your next program review

01

Automated remediation measures completion, not change

Assigning a module creates a compliance record. It doesn't identify why the employee clicked, and doesn't measure whether anything changed.

02

Punitive responses suppress reporting

Employees who experience remediation as punishment become less likely to report suspicious activity — undermining the exact behaviour the program needs most.

03

A 15-minute conversation outperforms a 15-minute module

The root cause diagnostic finds what a platform can't see — workload, confidence, role-specific confusion — and matches the intervention to the cause.

04

Behaviour-based, human-led training works

Organisations using behaviour-based training see up to 87% fewer malicious clicks and 6× better reporting within six months (Hoxhunt) — evidence that this approach, not automation alone, moves the numbers that matter.

Enjoyed this article?

From your most vulnerable employee to your strongest line of defence.

If your current awareness program responds to failed simulations with automated modules and compliance dashboards, this is the conversation worth having. Click or Flick Corporate treats every simulation failure as a diagnostic signal, not a compliance event.