Can one phishing simulation campaign change staff behaviour?

Can a single phishing simulation campaign change staff behaviour? What one campaign achieves, what it can't, and the monthly cadence that actually reduces clicks.

Not durably, no — and expecting it to is the most common mistake in the category. A single phishing simulation campaign produces a short awareness spike that fades within weeks; the measurable behaviour change — click rates falling and report rates rising — comes from a monthly cadence, where Cyber Aware's own reporting cites an average 80% reduction in clicked links within the first eight months. One campaign is a data point. A programme is a habit.

TL;DR

What one campaign actually does

A single simulation delivers three things, and two of them are worth having:

A baseline. Until you phish your own staff once, your click rate is a guess. One properly run campaign converts "we think our people would probably spot it" into a number — often an uncomfortable one — that justifies the budget for everything that follows.

A short-lived spike. In the days after a simulation, reporting behaviour jumps: people talk about the email, the clickers get teased (hopefully gently), and vigilance rises. Industry phishing benchmark data has long shown this effect decays within weeks. By the time a real attacker sends the next convincing email, the spike is gone.

A named list of who needs help. The clickers in campaign one are not a disciplinary list — they are your highest-risk learners, and the human risk reporting view exists precisely so admins can coach them rather than guess who they are.

Why the effect fades

Awareness is a perishable skill. Staff who clicked a simulation in March click the same style of lure again in September unless something intervened in between — because memory of one email is not a reflex, and attackers rotate tactics. A team trained once a year faces twelve months of evolving lures — invoice fraud in January, fake SSO resets in July — with no practice in between.

The failure mode is also cultural. If the single campaign was followed by blame, staff learn to hide clicks, which poisons the report rate — the one metric that catches real attacks. A one-off event with no follow-up coaching teaches exactly the wrong lesson: that getting caught matters, not that reporting matters.

What actually changes behaviour: the monthly loop

The cadence matters more than the difficulty. A monthly rhythm with three components is what produces durable change:

  1. Varied simulation. Each month a different tactic — phishing simulation libraries now run 100+ templates covering invoice fraud, SaaS login resets, ATO impersonation and parcel scams — with difficulty ramping as the team improves.
  2. Immediate coaching. Anyone who clicks lands on a short explainer immediately and is auto-enrolled in a targeted micro-course. The correction happens within minutes of the mistake, when it sticks.
  3. Visible positive reinforcement. People who report get acknowledged. Reporting becomes a reflex only if it keeps being rewarded.

Run that loop monthly and the trend line does the arguing for you: click rate falls, report rate rises, time-to-report shortens. Cyber Aware's reporting of an average 80% reduction in clicked links within eight months is the pattern consistent with that cadence — no equivalent result exists for a once-a-year test.

If you can only afford one campaign

Then make it count, and plan it as the first of a series rather than a verdict:

And pair the simulations with security awareness training assignments so the coaching loop has content to enrol people into.

What a realistic 12-month schedule looks like

If the goal is durable change, here is the shape of a first year that works:

Across the year, two numbers tell the whole story: click rate (should finish well below the month-1 floor) and report rate (should rise steadily, because reporting is the reflex that catches real attacks). Cyber Aware's average 80% reduction in clicked links over eight months is what this shape of programme produces in practice. The point of the schedule is that no single month matters much on its own — the compounding does the work, which is precisely what one standalone campaign cannot deliver.

How to measure whether behaviour really changed

Three numbers, tracked monthly, beat any single campaign result:

If click rate has not fallen and report rate has not risen after three monthly campaigns, the tactic mix or the coaching is wrong — change the templates before you blame the staff.

FAQ

Can a single phishing simulation change staff behaviour permanently? No. It provides a baseline and a short awareness spike that fades within weeks. Durable change requires a monthly cadence with immediate coaching.

How many campaigns before you see improvement? Expect the trend to become visible over three to six monthly campaigns. Cyber Aware reports an average 80% reduction in clicked links within the first eight months of a consistent monthly cadence.

Should we punish employees who click simulated phishes? No. Punishing clicks suppresses reporting, and unreported clicks are the expensive ones. Clickers should get immediate coaching; reporters should get recognition.

What's the point of one campaign, then? It establishes your baseline click and report rates and identifies who needs coaching first — the "before" picture every later improvement is measured against.

Related guides

Ready to deploy

Same playbook.
Your brand.

Cyber Aware's Human Risk Score works the same way for every MSP partner - under your brand, on your cadence.