No — a single missed phishing test should not justify firing an employee in most workplaces, because one click is a data point about a simulation, not evidence of misconduct, and punishing it destroys the reporting culture that actually stops breaches. Disciplinary action becomes defensible only after a pattern: repeated failures, ignored coaching, or a click that breaches a documented policy in a regulated role. The right first response to one failed test is coaching, not termination.
TL;DR
- One failed phishing test is a training signal, not a misconduct offence.
- Termination over a single click is hard to defend and worse for security outcomes.
- Blame-driven programmes make staff hide clicks — and hide real incidents with them.
- Progressive discipline needs a documented pattern: repeat failures, skipped training, policy breaches.
- Coaching on click, praise on report: that cadence is what measurably cuts risk.
Why this matters
Security awareness training exists to change behaviour, and behaviour research is unambiguous on one point: people avoid the activities that get them punished. Fire someone for clicking a simulated phish and every other employee learns that reporting a mistake is dangerous — so the next real phish goes unreported, and the click that mattered happens in silence.
The whole design of a modern phishing programme assumes the opposite. Clicks should surface who needs help; reports should be celebrated. That architecture collapses the moment a click becomes a firing offence.
What one failed test actually measures
A single simulated click measures one thing: this template, on this day, fooled this person. It does not measure intent, competence or loyalty. Well-crafted simulations use difficulty levels from "easy spot" to "hard to detect" precisely because even security professionals click on the hard ones.
Treating that data point as grounds for dismissal mistakes measurement for misconduct. There is no company harmed, no rule broken beyond the simulation itself, and no way to distinguish a moment of inattention from anything meaningful. The employee who clicks and then reports it has done more for your security posture than the employee who says nothing.
When discipline does become defensible
Disciplinary action can be justified when there is a documented pattern, applied consistently and fairly:
- Repeated failures with ignored coaching — the employee failed simulations, was assigned remedial training and did not complete it.
- A policy breach, not just a click — the click led to entering real credentials against policy after training on exactly that scenario.
- Refusal to engage — overdue courses, skipped refresher training and no response to follow-ups over several months.
- Regulated obligations — some compliance frameworks require documented remediation before escalation; skipping that sequence is itself the compliance failure.
Even then, the sequence matters: document, coach, re-test, and only then escalate. Employment law in most jurisdictions expects a fair process before termination, and "they clicked a phishing test" rarely survives one.
The no-blame alternative that actually works
Modern phishing programmes are built around coaching rather than punishment. When someone clicks a simulation on a platform like Cyber Aware, the click triggers an instant branded explainer and auto-enrolment in a failed-phishing course — a private learning moment, not a public shaming. Employees who report the email get a congratulations note with the simulation attached, so reporting is the celebrated behaviour.
This design choice is measurable. Programmes that keep a no-blame reporting culture see staff report suspicious emails more often and faster, which is the behaviour that stops real breaches. Human risk scores then target the right follow-up — extra help for the repeat clicker, not a dismissal letter.
What HR and IT should agree on
Before the first simulation campaign goes out, HR and IT should put the response ladder in writing:
- Click — private coaching moment, auto-assigned remedial course.
- Repeat click — same coaching plus a conversation with the line manager about context.
- Persistent pattern across months — documented performance conversation, not termination.
- Actual security incident caused by negligence after training — standard disciplinary process under existing policy, with the click as one piece of evidence among several.
Publishing this ladder to staff does two things: it removes the fear that makes clicks unreported, and it makes the escalation path defensible if it is ever needed.
FAQ
Can you fire an employee for failing one phishing test? In most workplaces, no. A single simulated click is a training signal, not misconduct, and termination over it is both hard to defend legally and destructive to the reporting culture that catches real phishing.
When can phishing simulation results justify disciplinary action? Only with a documented pattern: repeated failed simulations, skipped remedial training or a genuine policy breach after coaching — applied consistently through a fair process.
Does punishing phishing clicks improve security? No. Punishment makes staff hide clicks and stop reporting suspicious emails, so real incidents surface later and cost more. Coaching on click and celebrating reports measurably reduces repeat clicks instead.
What should happen after a failed phishing simulation? An instant private explainer, auto-enrolment in a short remedial course, and a note that the click feeds their risk score — with managers stepping in only when a pattern emerges over months.