LIVE MONITORING
General Discussion

Phishing simulation results shocked our management

By February 17, 2026 0 replies 1 views
Observer · 0 XP
February 17, 2026

We ran our first phishing simulation and 43% of employees clicked the link, 28% entered their credentials. Management is shocked. Now they want to “punish” employees who failed. I’m trying to convince them that training is more effective than punishment. Anyone have data or studies to support this?

Maya Patel
Expert · 2,800 XP
February 4, 2026

The research is clear: punishment-based approaches INCREASE security risk because employees stop reporting suspicious emails out of fear. Share these studies with management:

  • Gartner: “Punitive approaches to security awareness are counterproductive”
  • SANS: Organizations with positive security cultures have 70% fewer incidents

Instead, implement: targeted training for repeat clickers, gamification with rewards, and celebrate employees who report phishing attempts.

You must be logged in to reply.