The standard response to a failed phishing test is broken
The pattern is ubiquitous. An employee clicks a simulated phishing link. The platform flags them. An automated remediation module is assigned — typically a 10–15 minute video or slide course explaining what phishing is and how to spot it. The employee completes the module. The platform marks them as remediated. Everyone moves on.
This sequence feels like accountability. It looks like a control. On a compliance dashboard, it presents as a closed loop. But the evidence says it doesn't produce the behavioural outcome it claims to — and in many cases, it produces the opposite.
Most platforms measure whether someone completed a remediation module. Almost none measure whether the remediation changed anything.
It treats a behavioural signal as a knowledge gap. The assumption behind automated remediation is that the employee clicked because they didn't know what phishing looks like. In most cases, that isn't what happened — they clicked because they were distracted, under time pressure, trusted the sender, or were operating on autopilot. A module explaining what phishing is doesn't address any of those causes.
It assigns the same intervention regardless of cause. A finance director who clicked a sophisticated BEC lure during quarter-end receives the same generic module as a new starter who clicked a mass-market credential harvest. The platform can't distinguish between these — it doesn't ask why, it only records that.
The reporting paradox
There's a second, less visible cost. Employees who've been through the remediation loop once become measurably less likely to report suspicious activity next time. The logic is straightforward: if clicking something suspicious triggers a mandatory training module, the safest course of action is to not report at all. The remediation loop, designed to improve detection, suppresses the very behaviour — reporting — that matters most.
ASD's ACSC records social engineering in 60% of all cyber incidents reported to Australian authorities in FY2024–25, and explicitly flags under-reporting as a systemic concern. Punitive remediation contributes directly to the gap between what's happening and what organisations actually know about.
Research on psychological safety in learning environments — most notably Amy Edmondson's foundational work at Harvard Business School — is unambiguous on this pattern: people who feel punished for mistakes learn to hide mistakes, not to avoid them. A remediation loop experienced as punishment, even when organisations frame it otherwise, produces exactly this effect.
A conversation, not a module: the Supported Growth Pathway
The Supported Growth Pathway is a six-stage, human-led intervention model for employees who emerge as high-risk through behavioural indicators. It's non-punitive, confidential, and evidence-based. Its foundational principle: a failed simulation is a diagnostic signal — it tells you something about the employee's context, confidence, or cognitive load that a module can't address and a platform can't see.
The platform flags an individual as high-risk based on multi-factor behavioural indicators — a pattern across simulation performance, module engagement, and reporting behaviour, not a single failure. Invisible to the employee. No notification, no shame trigger, no manager alert at this stage.
A trained consultant or internal champion conducts a brief, private, structured 15–20 minute conversation — the cornerstone of the pathway. Does the individual understand why security matters in their role? Are they overwhelmed by content volume? Is there a confidence issue with digital tools? Is workload a factor? Do they feel safe reporting without fear of blame?
Based on the diagnostic, one of three tailored tracks is activated — each addressing the identified root cause and rebuilding confidence, because confidence is what turns knowledge into action.
Return to active simulations is staged around one principle: small wins build confidence, and confidence produces lasting behaviour change. Simulations begin at reduced complexity and increase only as performance improves.
When behavioural indicators improve consistently over a defined period — typically 60 days — the individual transitions back to the standard risk tier, noted positively rather than as a lingering flag.
For the small cohort of persistent non-improvers, the research is consistent: the most powerful force for change isn't a program — it's a person. A trained internal champion is paired as a peer guide, providing reinforcement no module can replicate.
Three tracks, three different root causes
Stage 03's intervention is only as good as the diagnostic that precedes it. Three tracks cover the vast majority of root causes uncovered in practice.
Low awareness
Role-specific scenario walkthrough, delivered 1:1 or in a small private group. Content drawn from current sector threat intelligence, not a generic library.
Low confidence
Simplified, confidence-building content. Buddy system with a trained internal security champion. Security reframed as personal empowerment, not obligation.
High workload
Micro-bursts of 3–5 minute content, different delivery timing, and optional consent-based manager awareness to reduce cognitive load rather than add to it.
Why this can't be automated
The natural question is whether this pathway could be replicated by a platform — using AI to conduct the diagnostic, assign the intervention, and manage re-entry. The honest answer is that it can't, and understanding why matters for evaluating any awareness program.
The diagnostic conversation is the control that matters. It can't be replicated by a chatbot, a survey, or an adaptive module because it requires reading context — tone, the unspoken factors behind a click — that only a human can perceive. An employee overwhelmed by workload won't tell a platform that. They'll tell a person they trust, in a conversation where they feel safe.
The peer guide intervention requires social trust. Pairing a struggling employee with a trained internal champion works because of the relationship between those two people — not the content delivered. Platforms can assign mentors; they can't manufacture the trust that makes mentorship work. And the decision to increase simulation difficulty for a recovering employee isn't a threshold calculation — it requires distinguishing genuine confidence from surface compliance, a distinction visible to a human observer in ways it isn't to a scoring algorithm.
What to take into your next program review
Automated remediation measures completion, not change
Assigning a module creates a compliance record. It doesn't identify why the employee clicked, and doesn't measure whether anything changed.
Punitive responses suppress reporting
Employees who experience remediation as punishment become less likely to report suspicious activity — undermining the exact behaviour the program needs most.
A 15-minute conversation outperforms a 15-minute module
The root cause diagnostic finds what a platform can't see — workload, confidence, role-specific confusion — and matches the intervention to the cause.
Behaviour-based, human-led training works
Organisations using behaviour-based training see up to 87% fewer malicious clicks and 6× better reporting within six months (Hoxhunt) — evidence that this approach, not automation alone, moves the numbers that matter.
From your most vulnerable employee to your strongest line of defence.
If your current awareness program responds to failed simulations with automated modules and compliance dashboards, this is the conversation worth having. Click or Flick Corporate treats every simulation failure as a diagnostic signal, not a compliance event.