Phishing Tests: Are They Becoming Too Harsh?
Phishing tests are designed to strengthen cybersecurity by assessing employee awareness. However, many organizations are now facing backlash for the way these tests are conducted. Are phishing simulations becoming unnecessarily harsh, and what impact do they have on workplace morale and security?
The Rise of Phishing Tests
Organizations use phishing tests to evaluate employee susceptibility to cyber threats. In 2020 alone, KnowBe4 sent over 9.5 million phishing test emails to more than four million users across 17,000 companies. The goal is to identify vulnerabilities and provide targeted training to improve security defenses.
The Downside: Fear, Distrust, and Stress
Despite good intentions, phishing tests often have unintended negative effects. Some companies employ manipulative tactics—such as fake bonuses or urgent alerts—that can create frustration and erode trust.
A notable example is GoDaddy’s 2020 phishing test, which promised employees a $650 holiday bonus. When workers discovered it was a test, the backlash was swift, with many feeling misled and demoralized. Such strategies can breed resentment and create a rift between employees and security teams.
Additionally, punitive measures—such as public shaming or penalties for failing phishing tests—can discourage employees from reporting real threats. Instead of fostering a proactive cybersecurity culture, these tests may generate fear and reluctance to engage.
Overconfidence and Ineffectiveness
Research suggests that phishing tests don’t always achieve their intended results. Employees who consistently spot fake phishing emails may develop overconfidence, assuming that real cyber threats will be just as easy to detect. In some cases, phishing simulations have even led to increased click rates over time, proving counterproductive.
A More Effective Approach
To improve cybersecurity without harming morale, companies should focus on collaboration rather than punishment. Effective strategies include:
- Encouraging teamwork instead of isolating individuals.
- Rewarding employees for correctly identifying phishing attempts.
- Providing education through positive reinforcement rather than fear tactics.
Conclusion
Phishing tests are valuable tools for cybersecurity, but their execution matters. When handled poorly, they can damage employee trust and morale, ultimately weakening an organization’s security posture. By shifting to more constructive, transparent, and educational methods, businesses can foster a culture of vigilance and collaboration—one that genuinely protects against cyber threats.
References:
WSJ: “Why Companies Shouldn’t Try to Catch Employees With Fake Phishing Emails”
HBR: “Phishing Tests Are Necessary. But They Don’t Need to Be Evil.”
WSJ: “The Power of Storytelling in Cybersecurity Training”
Living Security: “Phishing Simulations: More Harmful Than Helpful?”
WSJ Podcast: “Phishing Tests Are Getting Downright Mean”
CyberHoot: “Fake Email Phishing: More Harmful than Helpful”
YouTube: “Does phishing training make employees WORSE at falling for real phishing?”
-MalwareTech: “It might Be Time to Rethink Phishing Awareness”
-Mirage Security: “The Dark Side of Phishing Simulations: New Study Reveals Unexpected Risks”
CyberPilot: “Does phishing training work? Yes! Here’s proof”
