The evidence

Why traditional phishing simulations don't work

Two decades of sending employees surprise phishing emails, catching the ones who click, and redirecting them to a training page. The assumption is that seeing a consequence produces lasting behaviour change. It has now been tested at scale — and the evidence consistently fails to support it.

CyberCoach phishing challenge badges
01
It's an attention problem

Phishing susceptibility is an attention problem, not a knowledge problem

4,554
employees studied
3
campaigns in 6 weeks
0
benefit from mandatory retraining

Lain, Jost, Matetic, Kostiainen and Capkun (ETH Zurich, ACM CCS 2024) tested which components of embedded phishing training actually drive improvement. Effectiveness comes almost entirely from the nudging effect of the exercise, not the knowledge content: most participants never read the training material, yet still improved after seeing the page. Deterrents alone — a consequence email — performed as well as full embedded training.

Asked why they fell for simulations, employees cited email volume and time pressure, not missing knowledge. Mandatory training for repeat failures produced no additional benefit. The paper asks whether the practice should be replaced by pre-announced reminders that deliver the same nudge without deception or overconfidence risk.

"I just didn't pay attention and didn't go any further down."Study participant [P26]
02
Failure fails to teach

Embedded training after failure can make things worse

14,733
participants over 15 months
43%
said the training page made them feel safe
40%
felt the organization was protecting them

In a longitudinal study at a large organization, Lain, Kostiainen and Capkun (ETH Zurich, IEEE Security & Privacy 2022) found that employees redirected to a contextual training page after failing a simulated phishing email went on to click more phishing emails than those who never saw the page. The surveys explain the mechanism: the page read as reassurance, not instruction.

"Embedded phishing training, as commonly deployed in the industry today, is not effective and can in fact have negative side effects."Lain, Kostiainen & Capkun, 2022
03
The metrics can be gamed

Falling click rates don't mean the training is working

12,511
employees studied
7%
click rate on easy lures
15%
click rate on hard lures

Rozema and Davis (Purdue University, ACM Web Conference 2026) found that neither lecture-based nor interactive phishing training produced meaningful improvements in detection — but attack difficulty strongly predicted click rates. What the metric mostly measures is how hard this month's lure was.

Click rates also fall over time as employees learn the visual patterns, sender names and scenario types their particular vendor tends to use. That pattern recognition offers no protection against real attackers, who follow no such playbook. And the vendor running the simulations is the same party measuring the outcome — a commercial incentive to show improving numbers, with no independent check on what is driving them.

04
Psychological safety matters

Unannounced fire drills are a thing of the past. Why are we still running unannounced phishing tests?

Google's security team reached the same conclusion from an organizational perspective. In a 2024 post on the Google Security Blog they explained why Google does not run surprise phishing tests internally.

Employees feel deceived
Trust between employees and security teams is damaged
No evidence successful phishing incidents fall
Google Security Blog, 2024
05
AI only makes it worse

Simulations are getting less effective and more expensive at the same time

Rozema and Davis also warn that AI-generated phishing is eroding the foundation of the click-rate model itself. Simulations are built around observable tells that trained employees learn to spot — spelling errors, suspicious URLs, mismatched sender names, formatting irregularities.

Spelling errors
Suspicious URLs
Mismatched senders
Odd formatting

AI-generated attacks increasingly lack those tells: contextually relevant, grammatically flawless, visually indistinguishable from legitimate mail. And if the answer is that employees should stop and verify with a colleague every time, the cost of the programme multiplies.

 
The hidden cost

Two costs the click rate never shows

Beyond simple ineffectiveness, the research points at two consistent side effects of simulated phishing campaigns.

01

Overconfidence

A meaningful share of employees read the training page as proof that the company's systems are catching real threats — not as a lesson.

Intended
Vigilance about the inbox
Observed
Trust in the inbox
A novel type of overconfidence: it comes from misunderstanding the exercise itself.
Lain et al., 2022 & 2024
02

Erosion of trust

One line item gets budgeted. Three more get paid for anyway.

Employee trust unbudgeted
Organizational culture unbudgeted
Resource allocation unbudgeted
Direct implementation cost on the invoice
Significant hidden costs found beyond direct implementation costs.
Brünken, Buckmann, Hielscher & Sasse — USENIX Security, 2023
 
What actually works

Three things the evidence supports

Security awareness training is not useless. The findings point consistently toward what does work.

01

Reminders beat knowledge transfer

Content that teaches a lesson
Regular, credible reminders where real threats arrive

The nudging component of simulations produces measurable effects even when the content itself is not read.

Lain et al., 2024
02

Psychological safety enables honesty

Named, visible to managers, remedial training
Anonymous, no audience, no consequence

Belief in your own ability to perform a behaviour is one of the strongest predictors of whether you will sustain it. Fear of being caught suppresses honest engagement.

Bandura — self-efficacy
03

Attacks are multi-channel

Email — simulated
SMS
Teams
LinkedIn
QR codes
Voice calls

Extending simulation to every channel would mean monitoring employees across their whole working life. The answer is practice, not surveillance: practice recognizing diverse tactics in one safe and motivating environment.

Simulation covers one many channels
 
CyberCoach's approach

Dialogue, not a training page

Dialogic pedagogy: understanding is constructed through reasoning, not just clicking.

Step 01

A realistic scenario

Delivered in the tool they already use — Teams, Slack or a browser.

Step 02

They answer in their own words

Reasoning out loud, not clicking through a page.

Step 03

Immediate, personal feedback

In context, while the scenario is still live in their head.

Step 04

Aggregate analytics only

Compliance and knowledge gaps at org level — never an individual surveillance record.

Anonymous by default — answers never visible to managers
Reminders where real threats arrive, not in a separate portal
No social cost to getting something wrong

Get notified of what's going on in AI and security awareness and compliance

Expert Tips: Stay informed with curated content, expert opinions, and case studies that are relevant to your organization's security awareness strategy.

Special Offers:
Access to CyberCoach promotions and campaigns. 


Stay Informed:
Get the latest insights and updates on security and AI compliance trends, threats, and best practices delivered directly to your inbox.