Trained employees click phishing links because the moment of decision happens in under a second, months after the lesson was learned, in an inbox that looks exactly like real work. Awareness raises the baseline, but memory decays, attackers design for impulse, and a once-a-year course cannot compete with a well-crafted email that arrives on a busy Tuesday afternoon. Here is what actually drives the click after training — and what closes the gap in 2026.
The five reasons training alone does not stop the click
1. Memory decays faster than the email arrives
Hermann Ebbinghaus documented the forgetting curve in the 1880s: newly learned information loses most of its retention within days when it is never revisited. A staff member who completed a 45-minute security course in January is running on a fraction of that knowledge when the convincing invoice email lands in September. Spaced repetition flattens the curve — each revisited lesson resets the decay — but an annual course has no repetition at all.
2. The click happens in System 1
Phishing works because it targets fast, automatic thinking. A "shared document" notification or a "payment details changed" email arrives looking like the hundred legitimate messages a person processes that day. Deciding whether to click is not a considered risk assessment; it is a reflex. Training that teaches knowledge without rehearsing the reflex in a realistic setting does not reach the moment where the decision is actually made.
3. Attackers design for the trained audience
The scams that fool people are built to defeat generic training. Generic warnings say "beware of spelling mistakes and foreign senders" — so modern phishing has neither. The phishing simulation scenarios that generate the most clicks in 2026 use real sender display names, real internal thread context and time pressure tied to a genuine workflow, because that is exactly what criminal campaigns do.
4. Urgency and authority override caution
A message that appears to come from the CEO, an auditor or a supplier about a payment that must be made today creates social pressure that knowledge alone does not counter. The countermeasure is procedural, not educational: a rule that payment changes are always verified by phone on a known number. Staff need an escape hatch that makes pausing the easy, expected behaviour.
5. No consequence loop connects the lesson to the miss
In most organisations, clicking a simulation produces nothing: no follow-up, no data point, no targeted lesson. The click rate stays flat because the feedback loop is missing. Programmes that auto-enrol clickers in a short follow-up module and track the trend over time consistently bend the curve downward — Cyber Aware's programme data shows an average 80% reduction in phishing click rates over the first eight months of exactly that loop.
What actually moves the click rate
The fixes are cadence and consequence, not more content:
- Short monthly lessons instead of one annual course. Three-to-five-minute modules revisit the patterns before memory decays. The same budget of annual hours, spaced monthly, produces more retained recognition.
- Simulations that test behaviour, not reading comprehension. A realistic phishing simulation is the only rehearsal of the actual moment of decision.
- Immediate remediation for clickers. A clicked link should trigger a three-minute targeted lesson the same week, while the miss is memorable.
- A human risk score instead of completion tracking. Completion tells you who was enrolled; behaviour tells you who is at risk. Overdue lessons, failed quizzes and simulation outcomes measured per learner show whose training is not landing.
- Procedures that remove the judgment call. Payment-change verification and report-it-first rules make the safe action automatic rather than heroic.
What the data says about the human element
Verizon's 2026 Data Breach Investigations Report continues to find that the human element — social engineering, phishing and stolen credentials — remains among the most frequent causes of breaches, and this year's edition reports that mobile devices have become a favoured phishing target precisely because click rates there are higher than on desktop email. The report's own advice list is unchanged in substance: train employees to spot phishing, test defences regularly and keep software updated. The consistent finding across editions is that awareness is a control that must be exercised repeatedly to hold.
How to tell whether your training is working
Three measurements answer the question honestly:
- Click rate trend, not the point-in-time rate. A programme is working when the trend falls across successive simulations — roughly a 90-day window before measurable change, and material improvement by month eight.
- Report rate. The healthiest signal is not a falling click rate but a rising percentage of suspicious emails reported. Reporting is the behaviour that stops campaigns that evade filters.
- Risk concentration. Risk is rarely uniform: a small group of learners usually accounts for most clicks. Per-learner human risk reporting identifies them so remediation is targeted instead of universal.
Building the loop into your programme
A working 2026 programme looks like this: baseline onboarding training within the first two weeks; a short monthly module on a steady cadence through security awareness training; monthly or bi-monthly simulations matched to current scam patterns; automatic follow-up lessons for anyone who clicks; and a monthly review of the trend in a human risk report. If you are evaluating platforms for this loop, the compare page sets out the differences directly.
FAQ
Why does training fail to stop phishing clicks?
Because the click happens in under a second, months after the lesson was learned. Memory of training decays within days to weeks without reinforcement, and modern phishing is built to trigger fast, automatic decisions rather than considered ones.
How long after training do people forget?
The forgetting curve documented by Ebbinghaus shows most newly learned detail decays within days to weeks without review. That is why recurring short lessons outperform a single annual course on retention.
Do phishing simulations actually reduce clicks?
Yes, when they are recurring and paired with remediation. Programme data shows measurable improvement in roughly 90 days and an average 80% click-rate reduction by month eight. A one-off simulation with no follow-up moves nothing.
Is blaming employees who click fair?
No. Clicking is the designed outcome of a well-crafted attack aimed at a busy person. Treat a click as a signal that a lesson is due, not a performance failure — and audit the procedures (payment verification, reporting channels) that should have caught it.
How many employees actually fall for phishing in 2026?
It varies by campaign realism and industry. Verizon's 2026 Data Breach Investigations Report keeps the human element among the top breach causes and notes higher click rates on mobile devices. Measure your own baseline with a first simulation rather than relying on industry averages.
One last thing
The organisations with the lowest click rates did not find better employees — they found a cadence that outpaces the forgetting curve and a consequence loop that turns every miss into a three-minute lesson. The click rate is a systems metric, not a character judgement.
Sources
- Verizon 2026 Data Breach Investigations Report — human element as a leading breach cause, mobile click-rate findings
- Ebbinghaus forgetting curve — the retention decay that recurring training must outpace