Why Annual Phishing Training Videos Don't Work
Most organizations still run security awareness training as a once-a-year video with a quiz at the end. Employees click through it to check a compliance box, and retention is close to zero by the time an actual phishing email lands in their inbox. The organizations that meaningfully reduce click-through rates on real phishing attempts do something different: they run realistic, low-stakes simulations regularly, and โ critically โ they debrief every single simulation with specific, memorable detail.
What Makes a Simulation Realistic (Without Being Reckless)
An effective phishing simulation mirrors the tactics real attackers use, not generic "this email is a phishing test" content. The five scenario categories that consistently produce the most useful training data are:
- Fake IT Password Reset โ exploits urgency and fear of lockout, and tests whether employees click reset links instead of navigating to a known internal portal directly.
- Fake CEO Urgent Wire Request โ a classic Business Email Compromise pattern that exploits authority and secrecy to bypass financial controls.
- Fake Vendor Invoice โ tests whether accounts payable staff verify "updated bank details" requests through a separate channel before paying.
- Fake Package Delivery Notice โ targets personal habits (most people are expecting some package) with a tiny "redelivery fee" that also validates payment details.
- Fake HR Benefits Update โ exploits deadline pressure around a real annual event (open enrollment) to request SSNs and bank details.
Each of these succeeds because it combines a plausible pretext with a specific psychological lever: urgency, authority, fear of loss, or a mundane routine task most employees do on autopilot.
The Debrief Is Where the Learning Happens
Running the simulation is only half the exercise. The debrief is where behavior change actually occurs, and it works best when it's specific rather than generic. Instead of telling employees "watch out for phishing," walk through the exact email they just saw or almost fell for, and point to the precise red flags: the sender domain that almost โ but doesn't quite โ match the real company domain, the generic greeting instead of their actual name, the artificial 24-hour deadline, the request to bypass a normal approval process.
A good debrief checklist covers:
- Sender domain mismatch โ did the "From" address actually match the organization it claimed to represent?
- Urgency and fear framing โ was there a countdown, a threat of suspension, or a loss framing designed to short-circuit careful thinking?
- Requests that bypass normal process โ does this ask you to skip a verification step you'd normally take (calling the real CEO, checking a known vendor contact)?
- Sensitive data or payment requests via a link or reply โ legitimate systems very rarely ask you to re-enter a password, SSN, or bank details through an emailed link.
- Generic greetings and inconsistent tone โ "Dear User" or "Dear Employee" instead of your actual name is a signal worth teaching people to notice.
Cadence and Scope
Quarterly simulations, rotating through different scenario types, tend to outperform both one-off annual tests and overly frequent monthly tests (which can breed resentment and "test fatigue"). Vary the scenario each round so employees learn to recognize patterns rather than memorize one specific email. Track click-through rates and reported rates over time by department, and use the trend โ not any single test โ as your signal of whether training is working.
A Critical Boundary
Any phishing simulation must be run only against your own employees, with organizational authorization, ideally with HR and legal sign-off on the program. Simulation content should always be clearly built for internal training use and must never be sent to real external targets or used outside an authorized program โ doing otherwise crosses from training into an actual phishing attack.