A small group of employees can create an outsized phishing risk. In an analysis of 6,000 employees who received simulated phishing emails, approximately 6% of users accounted for nearly 29% of all failures.
Identifying these repeat clickers allows organizations to deliver more targeted training, reinforce the behaviors that need improvement, and make better use of security awareness resources. By focusing additional support on employees who are most susceptible to phishing, security teams can reduce human risk and strengthen their organization’s overall security posture.
What Is a Repeat Clicker?
A repeat clicker is an employee or user who repeatedly engages with simulated phishing emails, even after completing security awareness training. Because behavior change takes time, organizations should define repeat clickers using clear criteria based on their training schedule and risk tolerance. For example, this may include employees who fail two or more phishing simulations within a three- or six-month period.
Why Do Employees Keep Clicking?
Understanding why employees fall for phishing emails is essential to changing risky behavior. Cybercriminals often exploit common emotional triggers, including:
- Fear: Urgent or threatening language pressures employees to act quickly to avoid negative consequences.
- Authority: Messages that appear to come from executives or other trusted figures encourage compliance without verification.
- Reward: Promises of money, prizes, or exclusive benefits prompt employees to act before questioning the message.
- Helpfulness: Requests for urgent assistance take advantage of an employee’s desire to support a colleague or customer.
Heavy workloads, distractions, mobile device use, and increasingly convincing social engineering tactics can also make phishing messages harder to recognize. Identifying the factors behind repeated failures enables organizations to deliver targeted training that addresses specific behaviors rather than relying on a one-size-fits-all approach.
How to Support and Manage Repeat Clickers
Managing repeat clickers requires more than assigning additional training or imposing consequences. Security leaders should focus on understanding the behaviors behind repeated failures, delivering targeted support, and motivating employees to make more secure decisions.
- Reinforce key messages regularly. Use newsletters, posters, phishing alerts, and microlearning to keep phishing warning signs and reporting procedures top of mind.
- Deliver targeted security awareness training. Provide repeat clickers with engaging, relevant security awareness training based on their behaviors and knowledge gaps. Interactive content, gamification, and realistic scenarios can make lessons more memorable.
- Use phishing simulations to measure progress. Run ongoing phishing simulations to identify higher-risk users, evaluate whether training is working, and determine where additional reinforcement is needed.
- Recognize improvement. If it aligns with your organization’s culture, use rewards and friendly competition to acknowledge employees who improve their simulation results or consistently report suspicious messages.
- Provide timely, constructive feedback. Explain why a simulated message was suspicious and what the employee should do differently next time. Avoid shaming employees, which can discourage them from reporting future mistakes or security concerns.
- Apply additional safeguards when necessary. For employees who continue to engage with phishing simulations, consider stronger technical controls, more frequent training, one-on-one coaching, or limited access to high-risk systems. Any action should reflect the employee’s role, risk level, and organizational policies.
A supportive, risk-based approach can turn repeated mistakes into opportunities for lasting behavior change. By combining training, simulations, feedback, and appropriate technical controls, organizations can reduce phishing risk while building a stronger security culture.
Remedial Approaches for Repeat Clickers
Additional training
Consistent and tailored remedial training is essential for reducing the incidence of repeat clickers. Some organizations provide personalized, high-quality training that is engaging and interactive.
This training might include more in-depth explainer materials and game modules to ensure employees understand the risks and how to avoid them.
Escalation process
A structured escalation process can address repeated phishing simulation failures with progressively targeted training, coaching, and safeguards. The goal should be to improve behavior and reduce risk, not punish employees for making mistakes.
After the first simulation failure:
- Direct the employee to an immediate feedback page that explains the warning signs they missed.
- Assign a short remediation course focused on identifying and reporting suspicious messages.
After the second simulation failure:
- Provide immediate feedback and additional role-relevant training.
- Ask the employee’s manager to discuss the importance of slowing down, verifying unusual requests, and reporting potential threats.
- Document the coaching conversation and establish clear expectations for improvement.
After the third simulation failure:
- Assign instructor-led training or one-on-one security coaching.
- Involve HR, IT, or security leadership according to organizational policy.
- Consider additional technical safeguards based on the employee’s role and risk level, such as restricting access to high-risk applications or requiring stronger authentication.
- Create a documented improvement plan with specific actions, support resources, and follow-up assessments.
Escalation criteria should be transparent, consistently applied, and aligned with HR policies and the employee’s level of access. Organizations should also recognize positive behavior, such as improved simulation results or correctly reported phishing attempts. A simple acknowledgment from a manager or security leader can reinforce progress and encourage employees to remain engaged.
When to involve HR
If targeted training, coaching, and other remediation efforts do not improve an employee’s behavior, it may be appropriate to involve HR. HR can document the steps taken, reinforce expectations, and determine whether a formal improvement plan is necessary based on company policy and the employee’s level of risk.
Keep these conversations constructive and focused on improvement. Clearly explain the security risks associated with repeated phishing failures, acknowledge the support already provided, and outline the actions the employee can take to improve.
HR involvement and remediation procedures should be defined at the start of the security
Reduce Phishing Risk by Supporting Repeat Clickers
Managing repeat clickers requires a targeted, supportive approach. Consistent communication, engaging training, realistic phishing simulations, and timely coaching can address risky behaviors and reinforce more secure decision-making.
Fortra Security Awareness Training combines personalized learning, phishing simulations, and actionable reporting to reduce human risk and build lasting cybersecurity habits. Explore Fortra Security Awareness Training to strengthen your workforce’s ability to recognize and respond to phishing threats.