“I am certain I did not click it.” In the first weeks of a training programme, we hear versions of this surprisingly often. When we review the event with the employee, the answer changes: they recognise the message and confirm that they did click—or even entered information. That moment is not proof that employees are careless. It shows why awareness alone is not enough: people need to see their own behaviour before they can change it.
What employees actually do
Training completion tells you that somebody opened a lesson. It does not tell you how that person responds when a plausible request arrives during a busy working day. Phishing simulations give a very different view.
Source: SpySecure® phishing simulation data · 2026 YTD
These figures describe three different behaviours. Opening a message is not the same as exposing information. Clicking creates more risk, while submitting confidential information is the point at which a convincing message can become a real incident. Combining all three into one “failure rate” would hide where the actual problem sits.
The percentages decline over time when employees receive regular training and targeted follow-up. That matters more than the starting score. The useful management question is not whether somebody failed once, but whether risky behaviour becomes less common and whether the right follow-up occurs when it does happen.
Phishing is only one of the risks employees face
Employees make security decisions throughout the working day, often without recognising them as security decisions. They approve sign-ins, share files, install tools, respond to messages and give applications access to company data. An effective programme therefore has to cover much more than identifying a suspicious e-mail.
The most useful topics are tied to situations employees actually encounter. These are five recurring areas we address.
Messages arrive through more than e-mail
Phishing can arrive through e-mail, but similar requests also appear in text messages, WhatsApp, collaboration tools and QR codes. Smishing often feels more immediate because people read it on a phone and have less context to inspect the sender or destination.
Social engineering exploits trust and urgency
An attacker may pose as a director, colleague, supplier, bank or IT provider. The request may involve a payment, changed bank details, a confidential document or an MFA code. Employees need a simple verification process for unusual requests—not an expectation that they will recognise every attacker on sight.
Passwords and MFA still require good decisions
Employees need to know why passwords should be unique, why a password manager is safer than reusing memorable passwords and why an unexpected MFA prompt must be rejected and reported. MFA is an important control, but it can still be undermined when somebody approves a prompt or shares a verification code.
Data leaves through legitimate tools
A third-party application does not have to be malicious to create risk. Employees may upload documents to an unapproved service, grant an application broad access or share a file with the wrong external account. Training should make the boundary between convenient sharing and controlled company data practical and visible.
AI tools can see and change more than employees expect
AI assistants can receive confidential information through prompts and uploaded files. Coding agents such as Claude Code or ChatGPT Codex may also read files, run commands, install components and change data on a laptop when given broad permissions. Employees need clear rules for approved tools, permitted information and the access an AI agent may receive.
Why one annual training changes so little
A yearly course can show that employees received security instruction. It is a weak way to change what they do months later, when a convincing message arrives during a busy working day.
Knowledge is difficult to apply without repetition. An employee may recognise every example during a scheduled course, but a real request looks different and competes with deadlines, meetings and routine work. Knowing the rule once is not the same as applying it automatically.
The risk changes throughout the year. New phishing methods, smishing, AI tools, applications and working processes create situations that did not exist when the annual course was completed. New employees may also join long after that training took place.
Completion measures attendance—not behaviour. A certificate does not show whether somebody clicks a realistic link, approves an unexpected MFA prompt or shares confidential information with the wrong service. It also does not trigger additional help when a risky action occurs.
If the objective is safer behaviour, employees need regular practice, quick feedback and relevant follow-up. That requires an ongoing programme rather than one annual event.
The programme we use in practice
The objective is not to make every employee a cybersecurity specialist. It is to make a small number of safer actions routine—and to identify where additional help is needed.
Good morning,
Attached is our latest invoice. Could you review and approve it today? The payment deadline expires today.
You can view the invoice using the link below.
Kind regards,
Administration
See how SpySecure® combines short lessons, realistic simulations, targeted follow-up and monthly reporting in our Security Awareness Training programme.
Short training every two weeks
Employees receive an engaging video that generally takes three to five minutes. Each lesson addresses one recognisable situation—such as smishing, social engineering, passwords, MFA, safe data sharing or the use of AI tools—instead of trying to cover cybersecurity in one long session. The short format makes the programme easier to fit into normal work and keeps the subject present throughout the year.
Require the correct answers—not just completion
Every video is followed by a short test. Employees must achieve a 100% score and can repeat the questions when necessary. This does not prove that behaviour has changed, but it does establish that the core lesson was understood. A completion percentage alone cannot do that.
Test behaviour without announcing the timing
Realistic phishing simulations show what happens outside a lesson or test. Employees are not told when a simulation will arrive. That preserves the value of the exercise: the organisation sees how people respond while handling normal e-mail, deadlines and requests.
Connect risky actions to immediate follow-up
Clicking a simulated link or submitting information triggers additional training. The employee receives help related to the behaviour that just occurred, while the situation is still recognisable. This is much more useful than waiting until the next annual training cycle.
Report the trend and manage the exceptions
SpySecure® provides a managed monthly report with organisation-wide and per-employee statistics. Management can see overall progress, identify repeated risky behaviour and confirm whether additional training was completed. The report turns separate training events into an improvement process.
Accountability works better without blame
The employee who initially insists that they did not click is usually not being dishonest. E-mail is processed quickly and many routine actions are barely remembered. Reviewing the actual event closes the gap between perception and behaviour. Awareness often rises quickly once employees see their own result or the overall performance of the team.
The response to the training itself also matters. Employees describe the short videos as engaging and insightful. We regularly receive requests to extend a deadline because somebody was on holiday and still wants to complete the training. That is a better sign than forced attendance at a long annual presentation: the programme is becoming part of normal work instead of an unwanted compliance exercise.
The objective is safer decisions
The programme should make employees more willing to pause, verify and report—not more afraid of making a mistake. Fast reporting can limit the impact of a real incident, even when somebody has already clicked.
Measure behaviour, not attendance
A useful programme separates four levels of evidence across the full training programme. Each answers a different management question.
Participation
Did the employee complete the training? This shows reach, but not understanding or changed behaviour.
Understanding
Could the employee answer every test question correctly? A 100% required score confirms the lesson was understood at that moment.
Behaviour
What happened in a realistic simulation? Opens, clicks and submitted information show different levels of exposure and require different follow-up.
Improvement
Does risky behaviour decline over time? The trend shows whether training and follow-up are producing a lasting change.
This is also why per-employee reporting matters. An overall percentage can improve while the same small group continues to take high-risk actions. Individual statistics make targeted support possible, while the organisation-wide trend tells management whether the programme as a whole is improving.
Three questions for management
What an active security layer looks like
Employees should never be the only defence against phishing. Technical e-mail security, MFA, monitoring and incident response remain essential. But employees can add an important layer when three actions become routine.
Pause
Stop before acting on an unexpected request involving money, credentials, sensitive information or urgent changes.
Verify
Confirm unusual requests through another trusted channel instead of replying to the same message or using its contact details.
Report
Report suspicious messages and mistakes quickly. Early reporting gives the security team time to investigate, warn others and limit the impact.
Want to discuss employee security in your organisation?
Tell us what you want to improve. We can discuss training, realistic phishing simulations and the reporting your organisation needs.
%20-%20no%20white%20space%20-%20resized-1.png?width=4164&height=948&name=logo%201%20(bold)%20-%20no%20white%20space%20-%20resized-1.png)