Yes — only in narrow circumstances. Phishing simulation results can support disciplinary action when they show a documented pattern — repeated failed simulations, skipped remedial training, or a click that breaches a written policy — handled through a fair and consistent process. A single failed simulation is a training signal, not misconduct, and punishing it usually makes your security weaker, not stronger.
TL;DR
- A single failed simulation should never trigger disciplinary action: it measures a test you designed, not the employee's character.
- Simulation records are personal information, so collecting and using them carries privacy obligations.
- Discipline becomes defensible only with a documented pattern: repeated failures, ignored coaching, or a policy breach with real consequences, such as a payment made after a click.
- A coaching-first ladder — notify, micro-train, coach, escalate — fixes most click behaviour without touching employment action.
- Publish the rules before your first simulation, so nobody learns them from a disciplinary letter.
Why a single failed simulation is not misconduct
A phishing simulation is a test your security team designed. When an employee clicks, you learn how convincing the lure was, how busy that morning was, and how well your training covered that specific technique. You do not learn that the employee is careless or dishonest. Click rates on any single campaign are mostly a property of the lure: a well-crafted lookalike domain aimed at a finance team will fool experienced people, and security researchers make exactly this point when they warn that an individual phishing score is an evaluative judgment about a person, the kind of data employees most reasonably object to (CyberCoach).
There is also a data-quality problem. Simulations generate false positives: emails get forwarded, links get previewed by security tools, and mobile mail clients rewrite URLs. If your click data is not clean, you are making employment decisions on noise.
The biggest cost is cultural. Programs that punish clicks teach staff to hide mistakes, not report them. Your last line of defence against a real phishing attack is an employee who forwards the suspicious email to IT — and nobody forwards anything in a workplace where clicking a test email goes on their file. Best-practice guidance is consistent on this point: keep HR as a culture partner rather than an enforcer, and make sure managers tell teams that results are used for learning, not punishment (Hoxhunt; uSecure).
When simulation results can justify disciplinary action
Disciplinary action becomes defensible when three things are true at the same time:
- A written policy exists. Employees knew before the simulation ran that results feed a formal process, what the escalation ladder looks like, and what behaviour counts as a breach. A policy written after the click does not count.
- There is a documented pattern. Repeated failed simulations across several campaigns, remedial training skipped or ignored, coaching declined. One click is a signal; a trend across months is evidence.
- Real harm or a genuine breach occurred. The clearest case: an employee clicked, then authorised a payment despite a written call-back verification rule. That is a policy breach with consequences, and normal performance management applies.
Even when all three conditions are met, the process carries the decision. Apply the same standard to the CFO and the intern, keep an evidence file, give the employee a right of reply, and route the decision through HR rather than the security team. Regulated industries — financial services, critical infrastructure, health — can justify firmer consequences, but the pattern-and-process requirements do not change.
The legal backdrop: simulation data is personal information
In Australia, phishing simulation records — who clicked, who entered credentials, individual risk scores — are personal information under the Privacy Act 1988. Organisations already carry general obligations to protect personal information and to handle employee data lawfully, and commentary on the recent privacy reforms specifically anticipates security training and access controls extending to all staff and contractors who touch personal information (ICLG Australia; Piper Alderman). Practically: tell employees you run simulations, keep the data for security purposes only, and default to team-level reporting.
Where European staff are in scope, the analysis is stricter. Individual click tracking and automated risk scoring can amount to profiling, which triggers transparency duties and objection rights, and employees may have a right to access their own results (CyberCoach). If you employ across jurisdictions, design for the strictest one.
The coaching-first ladder that actually works
Most clicks are fixable with proportionate responses. A ladder that works in practice:
- Immediate micro-training. Everyone who clicks gets a short module targeting the exact technique in that simulation — the moment of failure is the best teaching moment you will ever get.
- Repeat-clicker coaching. When the same person appears across two or three campaigns, security and their manager hold a short, private conversation about what is tripping them up.
- Team-level intervention. If a whole team clicks above your baseline, the problem is usually the lure or the workflow, not the people. Fix the process.
- Escalation. Only after a documented pattern plus a breach of a written policy does formal performance management begin — and it runs through HR, not IT.
The framing throughout is cyber safety rather than enforcement: turn mistakes into learning opportunities, give supportive feedback instead of punishment, and keep technical controls like mail filtering doing the heavy lifting (Northwave).
Set expectations before your first simulation
- Announce the program, without spoiling individual tests: staff should know simulations happen and why.
- Publish the escalation policy before the first campaign, in plain language.
- Keep lures professional. Skip panic topics like layoffs or medical results — they erode trust and invite complaints.
- Report at team level. Individual names stay with security and HR.
- Reward reporting. An employee who forwards a simulated phish is demonstrating the exact behaviour you want, and recognising it publicly does more for your click rate than any policy.
How Cyber Aware treats simulation results
Cyber Aware runs automated phishing campaigns and treats every click as a training signal: employees who click are routed into follow-up training automatically, and human risk reporting tracks the trend at team level instead of naming individuals. The numbers that matter to management are the click-rate trend and the repeat-clicker count — both should fall month over month.
That design is not accidental. The point of a simulation program is to find the gaps before a real attacker does, and a program employees trust finds more of them.
FAQ
Can you fire an employee for clicking a phishing simulation? Not for a single click. Discipline or termination becomes defensible only with a documented pattern, a written policy, and a fair process.
Are phishing simulation results personal information? Yes. In Australia, click records and risk scores are personal information under the Privacy Act 1988; in Europe they can also amount to profiling.
Should repeat clickers be disciplined? Coaching comes first. Formal action is only appropriate once repeated failures are documented and a written policy defines the consequences.
Can simulation data appear in performance reviews? It should not. Keep simulation data to its security purpose; mixing it into performance management destroys the reporting culture the program depends on.
What if an employee reports the simulated email instead of clicking it? Recognise them. Reporting is the behaviour that stops real breaches, and public recognition beats any disciplinary threat.