Repeat phishing clickers are a coaching problem, not a humiliation blackspot. This guide shows how to design an escalation path for repeat phishing clickers in 2026 — four clear tiers, metrics, and a 30-day stand-up you can defend to HR and the board.
TL;DR
- Escalation paths for repeat phishing clickers need four written tiers before the first sim.
- Verizon DBIR 2026 puts the human element in 62% of breaches — technique beats shame.
- IBM puts average phishing-initiated breaches near US$4.8 million (2025).
- Coach twice, restrict once, and measure report rate beside click rate.
- Never make the first return-to-work conversation a public fail board.
Why this matters
Every programme has a long tail: people who click the second or third phishing simulation even after a lesson. In 2026, leaders still ask whether that is “a firing offence.” The better question is whether you wrote the path before emotion entered the room.
Verizon’s 2026 DBIR still finds the human element in 62% of breaches. IBM’s 2025 numbers put phishing-initiated breaches near US$4.8 million on average. An unstructured reaction — public shame, random stern emails, or zero follow-up — either burns trust or leaves high-risk access untouched. A written path does both jobs: coach the recoverable, contain residual risk.
What you'll need
- HR and legal sign-off on coaching versus formal performance language
- Clear definitions: fail = click or credential submit on a live simulation (no password capture)
- Access to short remedial security awareness training paths
- Ability to tag users in human risk reporting
- Manager briefing template and a single security owner
- Thirty days to pilot the path on one department before company-wide use
The steps
1. Freeze definitions and privacy before any ladder
Write what counts as a fail, what counts as a report, and who can see named data. Reports are praised. First fails are private coaching events, not all-hands material.
Expected outcome: a one-page glossary HR and security both initial.
Common mistake: building an “escalation” pack that is only a shame flowchart.
2. Publish a four-tier ladder with time boxes
Use this 2026 default and adjust once, not every week:
- Tier 0 — coach: first fail in 90 days → immediate micro-lesson + manager note within 48 hours.
- Tier 1 — reinforce: second fail in 90 days → 15-minute manager conversation + extra lesson + optional peer buddy.
- Tier 2 — contain: third fail in 180 days → temporary removal from payment / admin AD groups until coach signs fitness, plus weekly 1:1 for four weeks.
- Tier 3 — formal: continued fails or real-incident correlation → HR performance path; security drops privileged access first.
Expected outcome: every manager can point to the same tiers without improvising.
Common mistake: jumping to Tier 3 on the second fail because “they should know better.”
3. Automate Tier 0 and Tier 1 in the platform
Wire fails to auto-enrol lessons the same day. Log completion inside the risk view. Manual chase lists die on leave calendars.
Expected outcome: 100% of first fails receive a lesson without a help-desk ticket.
Common mistake: waiting for a monthly report before anyone coaches.
4. Train managers on the conversation script
Give managers four lines: what happened, why the lure worked, what to do next time, how reporting is the win. Ban sarcasm. Ban cohort leaderboards that name high-fail people.
Expected outcome: managers hold Tier 1 talks inside five working days.
Common mistake: security sends the stern email and managers stay silent.
5. Tie containment to access, not vibes
At Tier 2, write the exact groups or apps that pause (bank file approve, vendor master, shared inbox send-as). Re-enable only when lessons and a short practical check pass.
Expected outcome: residual risk drops without waiting for a termination decision.
Common mistake: “watching them closely” with no access change.
6. Score the path monthly
Track cohort click rate, percent of fails closed inside 48 hours, report rate, number of people on each tier, and time-to-restore access. Review in the same pack as broader awareness outcomes.
Expected outcome: a QBR slide that proves coaching works before anyone asks for firings.
Common mistake: only exporting seat completion while Tier 2 counts grow quietly.
7. Pilot 30 days, then firm policy
Run the path on one non-IT department. Adjust wording with HR once. Then publish firm-wide policy dates so nobody claims surprise.
Expected outcome: company-wide go-live with zero first-week policy fights.
Common mistake: launching organ-wide on a Friday simulation with no manager brief.
Troubleshooting
Unions or works councils block named reporting. Aggregate tiers for leadership pack; keep named coaching inside manager-only views with HR rules.
High performers fail twice and leadership wants exceptions. Privileged access still pauses at Tier 2. Title is not a control.
Click rates fall but report rates stay near zero. The path is teaching avoidance, not Defence. Add report drills to every remedial lesson.
Managers never hold Tier 1 talks. Make the conversation a checklist item security can audit weekly for 60 days.
Someone fails on a broken or filtered sim. Void the fail when delivery logs show the template never reached a normal inbox path.
Security wants public leaderboards of worst clickers. Refuse. Public shame spikes ticket noise and kills reporting culture.
Tools and resources
- Simulation platform with auto-enrol on fail
- Short remedial lesson library
- Human risk view with tier tags
- Manager conversation one-pager
- Access control runbook for Tier 2 apps
What to do next
Draft the four tiers with HR this week, connect Tier 0 auto-enrol, and book a 30-day pilot department. When you need automation and client-ready reporting side-by-side, use the MSP-focused compare notes before tooling renewals.
FAQ
How do you design an escalation path for repeat phishing clickers in 2026?
Write four tiers before the next campaign: coach, reinforce, contain access, then formal HR — with time boxes, auto micro-lessons, and metrics on report rate plus time-to-close.
Should repeat clickers be fired?
Not as a default. Contain privileged access and use HR performance only after repeated fails or a live incident pattern. Coaching recovers most learners.
How many fails before access restrictions?
A workable 2026 default is the third fail inside 180 days, or sooner if the role can move money or dual-control keys.
Do reporters ever enter the escalation path?
No. Reporting is a positive signal. Only clicks or unsafe submits count as fails.
What metrics prove the path works?
Fail close-out under 48 hours, rising report rate above 20%, shrinking Tier 2 headcount, and stable or falling click rates across a quarter.
Can small teams run this without HR software?
Yes. A shared register, calendar reminders, and platform auto-enrol cover most needs under 200 staff.
Where does this sit next to real incidents?
Any confirmed live phish or BEC involvement jumps straight to containment and incident response — the ladder is for simulation behaviour, not active compromise.
Should executives follow the same path?
Yes. Executives need the same tiers; attackers prefer them. Title-based exemptions collapse the control.
One last thing
The quiet failure mode is a witty “gotcha” culture video and a spreadsheet of names nobody coaches. If your 2026 path cannot show how many people left Tier 1 after a real conversation, you do not have escalation — you have a scoreboard. Write the tiers, automate the first lesson, and protect the humans you can still teach.