May 2026 · 5 min read

The phishing program that actually changed behavior

At a biotech I worked for, I built and ran the phishing awareness program from scratch. By the time I handed it off, susceptibility had dropped about 40%, and more than 200 employees and new hires had been through the training that backed it. This post is about what made it work — and what I'd tell anyone whose "program" is currently an annual compliance video.

Annual training doesn't change behavior. Repetition does.

The standard model — a 30-minute module every October, a quiz, a certificate — satisfies auditors and accomplishes almost nothing else. Behavior changes through frequent, low-stakes practice, the same way anything else does. We ran simulated campaigns continuously throughout the year, so encountering a suspicious email stopped being an annual pop quiz and became a routine reflex.

The metric that matters is report rate, not click rate

Click rate is the number everyone puts on the slide, but it's the weaker signal. A user who ignores a phish is invisible. A user who reports it gives your security team a detection — and in a real campaign, the first report is what lets you pull the email from every other inbox before the second click happens.

A falling click rate means people are warier. A rising report rate means you've recruited the whole company into your detection pipeline. We optimized for the second.

So we made reporting effortless (one button in the mail client), acknowledged every report, and celebrated the catches — including the false alarms. A false alarm is a rehearsal, not a nuisance.

No shame. Seriously — none.

The fastest way to kill an awareness program is to make clicking a phish feel like getting caught. People who feel shamed don't get more careful; they get quieter — and the worst outcome in a real incident isn't the click, it's the employee who clicked at 9 a.m. and didn't tell anyone until 5 p.m.

Our rule: a click triggered a short, immediate, private micro-training. No manager reports for first offenses, no wall of shame, no gotcha tone. The message was always the same — the click is recoverable; the silence isn't. People will only report their own mistakes inside a culture that can absorb them.

Make the lures realistic for each audience

Generic "you've won a gift card" templates train people to spot generic templates. Real attackers tailor; so did we. Finance saw invoice and wire-transfer themes, scientists saw conference and journal lures, IT saw fake MFA resets. We also matched difficulty to tenure — new hires got fundamentals while veterans got the hard stuff, like reply-chain hijacks that quote a real-looking thread.

Connect it to something bigger than the inbox

The program worked partly because it wasn't an island. It plugged into a broader security education effort — onboarding training for every new hire, a Security Council that gave departments a voice, and policies that backed the behavior we were asking for. Awareness programs fail when they're a quarterly email from a team nobody knows. Ours had faces attached.

What I'd tell you if you're starting one

None of this is exotic. It's mostly the discipline to treat security awareness as an ongoing program with a feedback loop instead of a checkbox with a certificate. The 40% drop didn't come from a clever template — it came from showing up every month and making it safe to be honest.

Questions about standing up a program like this? Get in touch — happy to compare notes.