Not durably, no — and expecting it to is the most common mistake in the category. A single phishing simulation campaign produces a short awareness spike that fades within weeks; the measurable behaviour change — click rates falling and report rates rising — comes from a monthly cadence, where Cyber Aware's own reporting cites an average 80% reduction in clicked links within the first eight months. One campaign is a data point. A programme is a habit.
TL;DR
- One campaign gives you a baseline and a brief awareness bump, not lasting change.
- The spike fades in weeks; repeat clickers return to old behaviour without reinforcement.
- Monthly simulations with automatic coaching are what move click and report rates.
- One campaign still has value: it is the "before" number every later improvement is measured against.
What one campaign actually does
A single simulation delivers three things, and two of them are worth having:
A baseline. Until you phish your own staff once, your click rate is a guess. One properly run campaign converts "we think our people would probably spot it" into a number — often an uncomfortable one — that justifies the budget for everything that follows.
A short-lived spike. In the days after a simulation, reporting behaviour jumps: people talk about the email, the clickers get teased (hopefully gently), and vigilance rises. Industry phishing benchmark data has long shown this effect decays within weeks. By the time a real attacker sends the next convincing email, the spike is gone.
A named list of who needs help. The clickers in campaign one are not a disciplinary list — they are your highest-risk learners, and the human risk reporting view exists precisely so admins can coach them rather than guess who they are.
Why the effect fades
Awareness is a perishable skill. Staff who clicked a simulation in March click the same style of lure again in September unless something intervened in between — because memory of one email is not a reflex, and attackers rotate tactics. A team trained once a year faces twelve months of evolving lures — invoice fraud in January, fake SSO resets in July — with no practice in between.
The failure mode is also cultural. If the single campaign was followed by blame, staff learn to hide clicks, which poisons the report rate — the one metric that catches real attacks. A one-off event with no follow-up coaching teaches exactly the wrong lesson: that getting caught matters, not that reporting matters.
What actually changes behaviour: the monthly loop
The cadence matters more than the difficulty. A monthly rhythm with three components is what produces durable change:
- Varied simulation. Each month a different tactic — phishing simulation libraries now run 100+ templates covering invoice fraud, SaaS login resets, ATO impersonation and parcel scams — with difficulty ramping as the team improves.
- Immediate coaching. Anyone who clicks lands on a short explainer immediately and is auto-enrolled in a targeted micro-course. The correction happens within minutes of the mistake, when it sticks.
- Visible positive reinforcement. People who report get acknowledged. Reporting becomes a reflex only if it keeps being rewarded.
Run that loop monthly and the trend line does the arguing for you: click rate falls, report rate rises, time-to-report shortens. Cyber Aware's reporting of an average 80% reduction in clicked links within eight months is the pattern consistent with that cadence — no equivalent result exists for a once-a-year test.
If you can only afford one campaign
Then make it count, and plan it as the first of a series rather than a verdict:
- Pick an easy-to-medium template for the first one — the goal is a fair baseline, not a gotcha.
- Announce afterwards, not before. Pre-announcing measures nothing; a debrief email with the aggregate numbers builds goodwill.
- Coach every clicker within a day, using the platform's auto-enrolment rather than a manual email.
- Book the next campaign before you run the first. A series scheduled for 12 months is what turns the baseline into a trend.
And pair the simulations with security awareness training assignments so the coaching loop has content to enrol people into.
What a realistic 12-month schedule looks like
If the goal is durable change, here is the shape of a first year that works:
- Months 1-2 — baseline and easy wins. Two easy-difficulty simulations in different tactics (a parcel scam, then an invoice fraud). Publish the aggregate numbers to staff. Expect a high click rate and a low report rate — that is normal, and it is your floor.
- Months 3-6 — variety and coaching. Rotate tactics monthly: SaaS login resets, ATO impersonation, gift card scams. Auto-enrolment handles the coaching; the admin touches nothing.
- Months 9-12 — real-attack rehearsal. Bring the programme close to reality with harder lures — spoofed internal senders, threaded replies, urgent payment requests. Click rates will tick up briefly; the report rate is the number that should keep climbing.
Across the year, two numbers tell the whole story: click rate (should finish well below the month-1 floor) and report rate (should rise steadily, because reporting is the reflex that catches real attacks). Cyber Aware's average 80% reduction in clicked links over eight months is what this shape of programme produces in practice. The point of the schedule is that no single month matters much on its own — the compounding does the work, which is precisely what one standalone campaign cannot deliver.
How to measure whether behaviour really changed
Three numbers, tracked monthly, beat any single campaign result:
- Click rate — the headline number; watch the trend, not the single result.
- Report rate — rising reports of both simulations and real suspicious emails is the strongest sign of a working culture.
- Repeat clickers — the small group who drive most risk; they need targeted coaching, visible in human risk reporting.
If click rate has not fallen and report rate has not risen after three monthly campaigns, the tactic mix or the coaching is wrong — change the templates before you blame the staff.
FAQ
Can a single phishing simulation change staff behaviour permanently? No. It provides a baseline and a short awareness spike that fades within weeks. Durable change requires a monthly cadence with immediate coaching.
How many campaigns before you see improvement? Expect the trend to become visible over three to six monthly campaigns. Cyber Aware reports an average 80% reduction in clicked links within the first eight months of a consistent monthly cadence.
Should we punish employees who click simulated phishes? No. Punishing clicks suppresses reporting, and unreported clicks are the expensive ones. Clickers should get immediate coaching; reporters should get recognition.
What's the point of one campaign, then? It establishes your baseline click and report rates and identifies who needs coaching first — the "before" picture every later improvement is measured against.