Every phishing program I run follows the same arc: wave one humbles everyone, wave two teaches, wave three proves the training stuck. On a recent retail engagement, the first lure — a fake parcel redelivery notice — caught 31% of recipients. By wave three, a far more convincing payroll lure caught just 9%. Here's what made the difference.
Wave one: measure honestly
The first campaign is a baseline, not a trap. I use a plausible, mid-sophistication lure, track opens, clicks, credential submits, and — most importantly — reports. A 31% click rate with a 4% report rate told me the real story: staff weren't careless, they simply had no fast way to flag suspicious mail.
Wave two: train in the moment
Everyone who clicked landed on a coaching page within seconds: what gave the mail away, spelled out in two sentences. No shame, no all-staff naming. Meanwhile IT got a one-click report button in the mail client — removing the friction that kept report rates near zero.
Wave three: prove it stuck
The final lure impersonated the payroll provider during benefits season — harder than wave one by every measure. Clicks fell to 9% while reports climbed past 40%. That's the metric executives should ask for: not who failed, but how fast the organization now senses and signals.
Takeaways for your team
Punishing clickers backfires; people hide mistakes instead of reporting them. Celebrate reporters, make flagging effortless, and repeat the cycle quarterly — attackers only need one tired afternoon, so the muscle has to stay warm.

