Can phishing simulation results justify disciplinary action?

Yes — but only with a documented pattern, a written policy and a fair process. When phishing simulation results justify discipline, and the coaching-first alternative that works better.

Yes — only in narrow circumstances. Phishing simulation results can support disciplinary action when they show a documented pattern — repeated failed simulations, skipped remedial training, or a click that breaches a written policy — handled through a fair and consistent process. A single failed simulation is a training signal, not misconduct, and punishing it usually makes your security weaker, not stronger.

TL;DR

Why a single failed simulation is not misconduct

A phishing simulation is a test your security team designed. When an employee clicks, you learn how convincing the lure was, how busy that morning was, and how well your training covered that specific technique. You do not learn that the employee is careless or dishonest. Click rates on any single campaign are mostly a property of the lure: a well-crafted lookalike domain aimed at a finance team will fool experienced people, and security researchers make exactly this point when they warn that an individual phishing score is an evaluative judgment about a person, the kind of data employees most reasonably object to (CyberCoach).

There is also a data-quality problem. Simulations generate false positives: emails get forwarded, links get previewed by security tools, and mobile mail clients rewrite URLs. If your click data is not clean, you are making employment decisions on noise.

The biggest cost is cultural. Programs that punish clicks teach staff to hide mistakes, not report them. Your last line of defence against a real phishing attack is an employee who forwards the suspicious email to IT — and nobody forwards anything in a workplace where clicking a test email goes on their file. Best-practice guidance is consistent on this point: keep HR as a culture partner rather than an enforcer, and make sure managers tell teams that results are used for learning, not punishment (Hoxhunt; uSecure).

When simulation results can justify disciplinary action

Disciplinary action becomes defensible when three things are true at the same time:

Even when all three conditions are met, the process carries the decision. Apply the same standard to the CFO and the intern, keep an evidence file, give the employee a right of reply, and route the decision through HR rather than the security team. Regulated industries — financial services, critical infrastructure, health — can justify firmer consequences, but the pattern-and-process requirements do not change.

The legal backdrop: simulation data is personal information

In Australia, phishing simulation records — who clicked, who entered credentials, individual risk scores — are personal information under the Privacy Act 1988. Organisations already carry general obligations to protect personal information and to handle employee data lawfully, and commentary on the recent privacy reforms specifically anticipates security training and access controls extending to all staff and contractors who touch personal information (ICLG Australia; Piper Alderman). Practically: tell employees you run simulations, keep the data for security purposes only, and default to team-level reporting.

Where European staff are in scope, the analysis is stricter. Individual click tracking and automated risk scoring can amount to profiling, which triggers transparency duties and objection rights, and employees may have a right to access their own results (CyberCoach). If you employ across jurisdictions, design for the strictest one.

The coaching-first ladder that actually works

Most clicks are fixable with proportionate responses. A ladder that works in practice:

  1. Immediate micro-training. Everyone who clicks gets a short module targeting the exact technique in that simulation — the moment of failure is the best teaching moment you will ever get.
  2. Repeat-clicker coaching. When the same person appears across two or three campaigns, security and their manager hold a short, private conversation about what is tripping them up.
  3. Team-level intervention. If a whole team clicks above your baseline, the problem is usually the lure or the workflow, not the people. Fix the process.
  4. Escalation. Only after a documented pattern plus a breach of a written policy does formal performance management begin — and it runs through HR, not IT.

The framing throughout is cyber safety rather than enforcement: turn mistakes into learning opportunities, give supportive feedback instead of punishment, and keep technical controls like mail filtering doing the heavy lifting (Northwave).

Set expectations before your first simulation

How Cyber Aware treats simulation results

Cyber Aware runs automated phishing campaigns and treats every click as a training signal: employees who click are routed into follow-up training automatically, and human risk reporting tracks the trend at team level instead of naming individuals. The numbers that matter to management are the click-rate trend and the repeat-clicker count — both should fall month over month.

That design is not accidental. The point of a simulation program is to find the gaps before a real attacker does, and a program employees trust finds more of them.

FAQ

Can you fire an employee for clicking a phishing simulation? Not for a single click. Discipline or termination becomes defensible only with a documented pattern, a written policy, and a fair process.

Are phishing simulation results personal information? Yes. In Australia, click records and risk scores are personal information under the Privacy Act 1988; in Europe they can also amount to profiling.

Should repeat clickers be disciplined? Coaching comes first. Formal action is only appropriate once repeated failures are documented and a written policy defines the consequences.

Can simulation data appear in performance reviews? It should not. Keep simulation data to its security purpose; mixing it into performance management destroys the reporting culture the program depends on.

What if an employee reports the simulated email instead of clicking it? Recognise them. Reporting is the behaviour that stops real breaches, and public recognition beats any disciplinary threat.

Related guides

Ready to deploy

Same playbook.
Your brand.

Cyber Aware's Human Risk Score works the same way for every MSP partner - under your brand, on your cadence.