
A few years ago, during an engagement with a mid-sized financial firm, I got a call from an HR director. Her voice had that particular flatness people use when they’re trying not to sound panicked. “We have an employee,” she said, “who thinks he’s about to be fired. He hasn’t slept in two days.”
He hadn’t done anything wrong. He’d clicked a phishing simulation — one of those “URGENT: Your Payroll Details Require Verification” emails the security team sent out monthly, with a nice public “Hall of Shame” leaderboard circulated to management afterward. His name was on it. Third month in a row. He was convinced his manager was building a file on him. He wasn’t paranoid — he was reading the room correctly. That was the program.
I stood in that lobby and thought about all the years I’d run exactly this kind of program myself — in the army, at Comsec, as a CISO. Click-rate dashboards. Repeat-offender lists. Quarterly “gotcha” campaigns designed with the seriousness of a security control and the emotional intelligence of a parking ticket. And I asked myself the question that eventually became this article: what exactly are we optimizing for?
The Metric That Lies to You
Most awareness programs report one number to the board: click-rate. It went from 22% to 9%, everyone claps, the CISO gets a good slide. Except click-rate is a vanity metric dressed up as a security metric. It tells you people got better at spotting your simulated phish — the one with the slightly-off domain and the corporate logo template your vendor reuses across 400 clients. It tells you nothing about whether they’d catch a real spear-phish crafted by someone who spent an afternoon reading your CFO’s LinkedIn.
I’ve seen organizations with a 4% simulated click-rate lose six figures to business email compromise within the same quarter. The training worked on the test. It didn’t work on the exam.
Worse, punitive programs actively train people to hide, not to report. If clicking gets you shamed, the rational move is to quietly delete the email and say nothing — including on the day it’s a real attacker, not a simulation. I’ll take an employee who forwards a suspicious email to the SOC with “not sure about this one, sorry to bother you” ten times a year over one who’s terrified of being wrong even once. The second one is exactly who a real attacker is counting on to stay silent.

The Boardroom Reframe: This Is a BIA Problem, Not a Training Problem
When I sat down with that firm’s leadership, I didn’t propose better phishing emails. I asked a different question, the one I now open every awareness engagement with: if your most trusted, longest-tenured employee clicked the wrong link tomorrow, what would actually happen to the business?
Nobody in the room could answer cleanly. That’s the tell. Awareness training divorced from a real Business Impact Analysis is theater. You’re teaching people to avoid a scenario whose actual cost, blast radius, and recovery time nobody in the building has mapped. It’s like running fire drills in a building where nobody’s checked whether the sprinklers are connected to water.
So we rebuilt the program backwards. Instead of “how many people can we catch,” we asked “what are the three business processes that would hurt most if compromised — wire transfer approval, customer data export, privileged access — and who touches them?” We trained those people, on those scenarios, with context: “here’s what a real BEC attempt against a wire approver looks like, here’s the actual dollar figure a similar attack cost a peer company last year.” Specificity beats volume every time.
What I Replaced Punishment With
Three shifts made the difference, and none of them cost more than the old program:
- Report-rate over click-rate. The number I now put on the board’s slide is: how fast, and how often, did people report suspicious emails — real or simulated — to the SOC? A rising report-rate with a flat click-rate is a healthier signal than a falling click-rate alone, because it tells you the human sensor network is active, not just quieter.
- Radical transparency about real incidents. Instead of hiding breaches internally out of embarrassment, I started sharing sanitized post-mortems company-wide: what the attack looked like, who almost fell for it, what saved us. People engage with real stories about real colleagues far more than with generic vendor templates. It also does something punitive programs never can — it builds trust that security is trying to protect people, not police them.
- Role-based, not company-wide, simulations. A finance approver needs different training than a junior marketing hire. Blasting the same generic phish to 3,000 people and ranking them on one leaderboard ignores that risk isn’t evenly distributed. I map training to the BIA’s crown-jewel processes first.
The employee from that lobby story, by the way, is now one of the most reliable reporters in his company. Not because he got better at spotting fakes in a vacuum — because someone finally told him clicking once isn’t a career-ending event, and that reporting fast is the actual job.

The Ghosts in the Servers Don’t Care About Your Leaderboard
Here’s the uncomfortable truth I’ve had to sit with across twenty years of this work: attackers don’t study your training program, they study your people. They know your CFO travels every third Tuesday. They know your help desk resets passwords over the phone if you sound stressed enough. No leaderboard changes that human terrain. Only trust, context, and fast reporting do.
I think about this the same way I think about Formula 1 brakes — a metaphor I use often because it’s the one that sticks. Brakes don’t exist to slow the car down for its own sake; they exist so the driver can go faster into the corner with confidence. A punitive awareness program is brakes that lock up at the first sign of trouble. A good one lets your people move fast and stop safely when something’s actually wrong — because they know exactly when and how to hit them, and they’re not afraid to.
Practical Takeaways
- Kill the public leaderboard. Track report-rate and time-to-report as your headline metrics, not click-rate alone.
- Anchor training to a real BIA. Identify your three highest-impact business processes first, then build role-specific scenarios around them — not generic company-wide blasts.
- Share real incidents internally. Sanitized, blameless post-mortems build more resilience than any simulated phishing template ever will.
- Make reporting the win condition. Reward the fast “not sure about this one” email publicly; handle actual mistakes privately, coaching not shaming.
Closing the Loop
I still think about that HR director’s phone call. Not because it was a security failure — it wasn’t, click-rates happen to everyone — but because it was a program failure dressed up as a personnel issue. We’d built a system that turned a moment of human fallibility into a threat to someone’s livelihood, and then wondered why people stopped raising their hands.
Security awareness isn’t broken because people are careless. It’s broken where we built it to catch people instead of protect them. Fix the architecture of the program, and the people fix themselves.
I write From the CISO’s Diary from 20 years across BDO, ThriveDX, the IDF and my own ventures. Let’s connect: Omri Sagron on LinkedIn.