FOUNDit
Security5 min readMay 6, 2026

Phishing training that people don't ignore

Phishing training that people don't ignore

Annual security slideshows don't change click rates β€” the data on this is brutal. People forget 90% of a lecture within a week, and the phishing email arrives on week three. What actually works is short, specific and slightly uncomfortable.

Test first, train after

We start with a harmless simulated phishing campaign β€” no shaming, no name lists on the wall. The point is a baseline number. It's usually 20–35%, and seeing it is what convinces management this is a real problem.

Thirty seconds, right at the moment

Whoever clicks the simulation immediately sees a 30-second explainer: here's the email, here are the three signs it was fake. Training at the exact moment of the mistake sticks better than an hour of theory a month later.

Make reporting a win

The goal isn't zero clicks β€” it's fast reporting. When employees report a suspicious email in one click and get thanked for false alarms too, the security team starts seeing attacks in minutes instead of days.

The numbers

Across our clients, click rates fall from ~30% to under 8% within three months, and average report time drops from 'never' to under 15 minutes. That's not perfection β€” it's a different risk category.