Does Phishing Training Actually Change Anything?

Yes, and it is worth being exact about what. Phishing training changes how fast a suspicious email gets reported, and how often the same person is caught twice. It does not change the fact that a well-written phishing email will eventually get past somebody. The Australian Signals Directorate (ASD) recorded phishing in 60 per cent of the incidents reported to its Australian Cyber Security Centre in 2024-25, and still lists being alert to phishing alongside multi-factor authentication and regular backups as a basic, not a cure.

If you are asking the question, you have probably already paid for something. A platform, a quarterly video, a chart showing the click rate going down. Then somebody paid a fake invoice, or very nearly did, and the chart started to look like the thing you bought rather than the thing you needed. That is a fair reaction, and it is not a reason to stop training people.

The phishing that works reads well. ASD says social engineering techniques can be highly convincing, and notes that criminals use generative AI to produce spearphishing emails that present them as legitimate with relatively minimal effort. The two most common cybercrime types Australian businesses reported to ASD last year were email compromise with no financial loss, at 19 per cent, and business email compromise fraud with a loss, at 15 per cent.

So this is a piece about what training can honestly be asked to do. Five questions, answered plainly: whether it reduces clicks, what to measure instead of the click rate, why one campaign for everybody teaches so little, what ASD actually asks of a business, and where training stops and the controls take over. Security awareness training sits on an inSUPPORT quote as a separate line item rather than inside the support fee, so it is worth knowing what you are buying.

TL;DR: What to remember

  • ✅ Training reduces how often people click, and it never gets the number to zero. Judge it by what it changes, not by whether it ends phishing.
  • ✅ Measure reporting, not clicking. The people who report a simulated email are your early warning system. A click rate on its own tells you what the email looked like that month.
  • ✅ One campaign for everybody trains the people who did not need it and skips the ones who did. Simulations that adjust to each person's results are the version worth paying for.
  • ✅ ASD asks for annual awareness training for all personnel, tailored content for the groups that need more, a training register, and a way to report. That is the standard, and no certificate is involved.
  • ✅ The controls behind the training are what stop the money moving: multi-factor authentication that holds, a phone call before any bank detail changes, and an alert when a mailbox rule appears.

Contents

Does phishing training actually reduce how often people click?

It does, and the reduction is real without being total. Someone who has seen twenty simulated phishing emails and been shown, each time, exactly what gave the last one away is harder to catch than someone who has seen none. That is the whole and honest case for it. What training cannot do is make a person reliably spot an email that carries nothing to spot: a real supplier's real mailbox, an existing invoice thread, ordinary wording, and one changed bank account number. That email is built to defeat attention, and often it does.

The number worth keeping in your head is ASD's. Phishing was recorded in 60 per cent of the incidents reported to its Australian Cyber Security Centre in 2024-25. Read that as phishing being present in the incident rather than as the way every attacker got in, because in the incidents where data was encrypted for impact ASD names already compromised credentials and legitimate external-facing services as the most common means of initial access. It describes the environment your training runs in, not a verdict on the training. ASD's own list of basics puts being alert to phishing messages alongside strong multi-factor authentication, unique passphrases, updated software and regular backups, and none of the five is offered as a guarantee.

A useful way to hold it is that training moves the odds on any single email and buys time on the rest. A person who does not click has done one useful thing. A person who does not click and reports the email has done two, and the second one protects the colleague who was about to open the same message ten minutes later. The lure does not always arrive as an email either, so keep the reporting path wider than the inbox: ASD notes that info stealers are commonly distributed through SMS or email phishing, through online advertisements carrying malicious links, and through downloads with malicious code hidden in them. It is worth understanding how much of the attack happens before anyone is asked to click anything, which is set out in why your spam filter did not stop the fake invoice.

What should you measure, if not the click rate?

Measure the reporting rate first, then how long the first report takes to arrive, then the number of people caught by consecutive simulations. The click rate comes last, and it comes with a caveat. Microsoft's documentation for its attack simulation tool defines the actual compromise rate as the share of people who received the simulation and were compromised, and pairs it with a predicted compromise rate drawn from historical data across Microsoft 365. That prediction exists because a hard simulation and an easy one produce different results from the same people. A falling click rate can mean the training worked. It can also mean this month's email was easier.

The reporting rate does not have that problem. It counts the people who saw something wrong and told somebody, and that behaviour is the one that matters when a real email lands, because a reported email can be pulled from every other inbox before the next person opens it. Microsoft's simulation report shows compromised users and users who reported the message side by side, and its export records when each person reported. The same report carries a first and average instance section covering the first link clicked and the average, which tells you how long a real campaign would have to run before it found somebody.

The third number is repeat offenders. Microsoft defines one as a user compromised by consecutive simulations, two by default, and charts them by simulation type: credential harvest, malware attachment, link in attachments, link to malware, drive-by URL. That list is your training plan. It names the people the generic content is not reaching and the kind of lure that catches them, which is far more useful than an organisation-wide percentage. One thing to check before trusting any dashboard: Microsoft notes that simulation messages reported through non-Microsoft tools are not captured in its reports, so the platform counting the reports has to be the one your people report to. The same documentation notes that a QR code can take the place of the phishing link as the payload, and that scanning it is tracked as a click, which is worth asking about if your simulations only ever test a link in the body of an email.

Why does one campaign for everybody teach so little?

Because it is aimed at nobody in particular. A single simulated email sent to the whole business on the same morning tests the people who would never have clicked it, irritates the ones who spotted it in the preview pane, and delivers the same follow-up module to the person in accounts who has now clicked three in a row. Everybody gets the training. Almost nobody gets the training they needed. ASD's Information Security Manual says the content of awareness training should be tailored to the needs of specific groups of personnel, and names general personnel, different classes of high-risk personnel, and privileged users as groups that need different things.

The version that changes behaviour adjusts to the person. inSUPPORT's security awareness extra is described on its pricing page as a phishing platform that tailors simulated attacks to each individual user based on their results from fortnightly online classes. Read that as a loop rather than a product: a short class every fortnight, a simulation shaped by how that person did in it, and the next class shaped by whether they clicked. The person who has the pattern down is left alone. The person who does not gets the practice, on the lure that actually catches them, until the reporting starts.

That loop is also what makes the numbers in the previous section mean something. A repeat-offender list only helps if somebody acts on it, and the action is not a stern email. It is a harder, more specific simulation for that person and an easier path to the report button. High-risk roles deserve their own lures too. The people who pay invoices should see fake invoices. The people who reset passwords should see the help desk attack, which is the request to reset a password, change a phone number or temporarily disable multi-factor authentication that ASD's manual names as a possible social engineering attempt in its own right.

What does ASD actually ask a business to do?

Four things, and none of them is a certificate. ASD's Information Security Manual, in its guidelines for personnel security, asks that cyber security awareness training is undertaken annually by all personnel and covers the purpose of the training, security appointments and contacts, authorised use of systems, protection of systems, and the reporting of incidents and suspected compromises. It asks that people with privileged access undertake tailored privileged user training annually. It asks that a training register is developed, implemented and maintained, so who was trained and when is a record rather than a memory. And it asks that personnel are advised what suspicious contact looks like and how to report it.

The manual is specific about money as well. Its business email compromise control asks that people dealing with banking details and payment requests are advised what the attack is and how to manage and report it, and it lists the warning signs: an unexpected request for a change of banking details, an urgent payment request or threats if payment is not made, unexpected payment requests from a person in a position of authority, and an email from an address that does not match an organisation's name. A newer control adds that voice or video alone is no longer enough, because synthetic voice and video can impersonate an executive convincingly. The requestor has to be positively identified through a pre-established method or an independent trusted channel.

Notice what that does to the question in the title. Training is not something a business completes. It is a standing control with an annual cadence, a register, a set of people who need more than the baseline, and a defined way to report. Whether your provider's platform meets it is checkable in an afternoon: ask for the register, ask which groups get tailored content, ask where the report button goes and who reads what arrives. ASD updates the manual regularly, so treat the controls above as current at September 2026 and check them again at your next review.

Where does training stop, and what has to stand behind it?

Training stops at the point where a decision is made by a busy person under time pressure, which is exactly the point the attack was built to reach. The controls behind it are the ones that do not need that person to notice anything. Multi-factor authentication that holds up against a prepared attacker, so a stolen password is not enough on its own. A standing rule that no change to bank details is actioned without a call to a number you already held. An alert the day a mailbox forwarding or deletion rule appears, because that rule is how a compromised account hides the real conversation. Fewer people with elevated access, so one caught person opens fewer doors.

Read those next to ASD's warning signs and the same shape appears. The manual's guidance is that personnel should have clear guidance to verify bank account details, think critically before actioning unusual payment requests, and have a process to report pressure for secrecy or requests to go around normal business processes. The process is the control. The person's judgement is the trigger. That ordering matters most when the money has already moved, which is why the first 48 hours after a fake invoice is paid belong to the bank and the mailbox rather than to whoever clicked. The sequence is in what to do in the first 48 hours after someone pays a fake invoice.

This is where a provider's operating model shows. Awareness training sold as the fix leaves the process controls to whoever remembers to set them. inSUPPORT runs the training as one layer inside managed IT support, with the controls behind it maintained as part of the same model and the remediation an audit finds included in the support fee rather than quoted back as a project. The honest position is ASD's own. Train people, because it helps and because the manual asks for it. Then build the environment so the one email that beats the training does not beat the business.

Questions owners ask about phishing training

Is security awareness training worth it for a small business?

Yes, when it is measured and tailored, and it is not the first dollar to spend. ASD lists being alert to phishing among the basics for every business, next to multi-factor authentication, unique passphrases, updates and backups, and the average self-reported cost of cybercrime per report for a small business was $56,600 in 2024-25, up 14 per cent on the year before. Phishing training earns its place once those basics are in and the training is judged by the reporting rate rather than by whether anyone clicked this month.

Should our IT provider run the simulations, or should we?

Whoever runs them has to be able to act on the results, which usually means the same people who manage your email, your identity controls and your report button. Simulations that produce a repeat-offender list nobody follows up are a dashboard, not a control. Ask a provider who reads the reports, what changes for a person who is caught twice, and whether the report button reaches somebody who can pull the real email out of every other inbox.

How long before phishing training shows a result?

Judge it in cycles rather than weeks. A fortnightly class and simulation loop gives you a reporting rate and a repeat-offender count every fortnight, and the trend across several cycles is the result: reports arriving sooner, first clicks arriving later, and fewer names on the repeat list. A single campaign's click rate says more about that email than about your people. Set the reporting rate as the target at the start, so the platform is measuring the behaviour you actually want.

Where do we start if we have never run any of this?

Start with what stands behind the training, because a simulation that finds a person who clicks only helps if the account they would have handed over is protected. A Cyber Strength Audit assesses identity and access, email and endpoint security and the payment process controls against what is actually configured, and returns a costed list. Once the environment is known, awareness training can be scoped to the people and the roles that need it rather than sent to everybody and hoped for.

Find out what is standing behind your training

If your phishing training reports a click rate and nothing else, the number you are missing is what happens after the click. A Cyber Strength Audit looks at the controls that decide that: multi-factor authentication, who holds elevated access, alerting on mailbox rules, and whether a change of bank details can be actioned on an email alone. inSUPPORT works with Australian businesses of roughly 30 to 300 users, has run more than 1,500 cyber audits, and includes the remediation an audit finds in the support fee rather than billing it back as a project. We would rather show you the gap than let an email find it.

Book a Cyber Strength Audit →

Citations

  • "Guidelines for personnel security, Information Security Manual", Australian Signals Directorate. The awareness training controls used above: annual training for all personnel and what it covers (ISM-0252), tailoring to groups and annual privileged user training (ISM-1565), the training register (ISM-2022), the business email compromise warning signs and reporting (ISM-1740), the help desk attack (ISM-2071) and the synthetic impersonation control (ISM-2126). Controls on the page carry updates to September 2026. cyber.gov.au
  • "Annual Cyber Threat Report 2024-2025", Australian Signals Directorate. Phishing recorded in 60 per cent of the incidents reported to ASD's ACSC, the top self-reported cybercrime types for business (email compromise 19 per cent, business email compromise fraud 15 per cent), the $56,600 average self-reported cost per report for small business, up 14 per cent, and the basics list. Published 14 October 2025. cyber.gov.au
  • "Reports for Attack simulation training, Microsoft Defender for Office 365", Microsoft Learn. The definitions of actual and predicted compromise rate, compromised users shown beside users who reported, repeat offenders as users compromised by consecutive simulations with a default of two, the first and average instance timings, and the note that simulation messages reported by non-Microsoft tools are not captured. Updated 23 April 2026. learn.microsoft.com
Kane Nawrocki, Founder and CEO of inSUPPORT

About the author: Kane Nawrocki is the founder and CEO of inSUPPORT. He has spent more than 25 years in IT and built inSUPPORT to give Australian businesses managed IT, security and compliance as one model, with the remediation an audit finds included in the support fee rather than billed back as a surprise project.

Content reviewed by Probably Genius for accuracy and relevance.

Want to discuss this topic more?
CLICK HERE