How I Took Phishing Click Rates From 70% to 8%
A number I still think about: when I walked into one of Chicago’s largest hospital networks, roughly seven out of ten people clicked the phishing test. Seventy percent — in healthcare, where the thing on the other end of that click is a patient’s record, and sometimes a patient’s care. It would have been easy to panic, or to conclude the workforce was hopeless. Both would have been wrong.
Six months later it was eight percent. Here’s how I got there, and more importantly, what actually moved the needle versus what everyone assumes does — because the conventional wisdom about security awareness is mostly wrong, and it’s wrong in ways that make people click more.
Blame the training, not the people
The reflex when you see a high click rate is to decide your people are careless. They’re not. They’re busy. A nurse mid-shift is not going to forensically analyze a sender domain, and she shouldn’t have to — her attention belongs on the patient in front of her, not on your email headers. If your security depends on every human being suspicious 100% of the time, your security is already broken, because that is not a thing humans can do. Fatigue, urgency, and a convincing lure will beat vigilance eventually, every time, for everyone. I’ve clicked test emails myself on a bad day.
So I stopped treating it as a people problem and started treating it as a design problem. The question isn’t “how do I make people more careful?” It’s “how do I make the safe behavior the easy, default, low-effort one, so being careful costs almost nothing?” That reframe is the whole difference between the programs that work and the ones that just generate shame and quarterly reports.
What actually worked
I made the fake attacks look like the real ones. Generic “foreign prince” tests teach nothing, because nobody’s real inbox looks like that. I modeled the simulations on the lures actually landing in the organization — the fake IT password resets, the fake benefits-enrollment emails, the genuinely convincing ones tuned to a healthcare workforce. When someone got caught, it was by something realistic, the exact thing that would fool them for real, and the lesson stuck because it wasn’t a cartoon.
I killed the shame. No manager ever got a list of who failed. Clicking a test dropped you into a 90-second, no-judgment explainer — here’s the single tell you missed — and that was the end of it. No email to your boss, no public wall of shame, no HR flag. People learn when they aren’t bracing to be embarrassed. The moment a phishing program becomes a punishment engine, people stop reporting their mistakes, and a mistake nobody reports is the most dangerous kind there is.
I made reporting one click. A “Report Phish” button right in the mail client. Suddenly employees weren’t just targets, they were sensors — thousands of them, distributed across every department, watching for exactly the thing my tooling might miss. On a good week I’d get a live, real campaign flagged by a user before the automated defenses caught it, which meant I could pull it from every other inbox before it did damage.
Reward the report, not just the catch
Here’s a subtle one that mattered more than I expected: I made a point of thanking people who reported, including the ones who reported things that turned out to be harmless. The instinct is to correct them — “that was actually fine” — but that instinct trains people to stop reporting. I’d rather field a hundred false alarms than miss the one real campaign because someone worried they’d look foolish. Positive reinforcement builds a workforce that leans toward reporting. Correction and embarrassment build one that stays quiet and hopes.
Measure reporting, not just clicking
Most programs obsess over the click rate and ignore the number that actually predicts how you’ll do against a real attack: the reporting rate. A workforce where 8% click but nobody reports is far more dangerous than one where 12% click but the other 88% hit the button within minutes — because on a real campaign, that fast, high-volume reporting is what lets you contain it before it spreads. I watched the reporting rate as closely as the click rate, and honestly weighted it higher. Clicking measures your exposure. Reporting measures your immune system.
The part that gets skipped
None of this survives as a one-time campaign. Awareness decays — run one big training push and the effect fades within months as people forget and new hires arrive. I ran it continuously and quietly, forever, and the 8% held because it turned into muscle memory instead of a memo. If you run one phishing test a year and call it “training,” you’re not measuring your people. You’re measuring their luck on that particular Tuesday.
Security awareness isn’t about making people paranoid. It’s about making the safe thing the easy thing.