Why phishing simulation-based training fails to improve employees' real-world resilience
Simulation-based training has a structural flaw: it only ever reaches the people who fail. More than 90% of employees never receive meaningful training from it, so most of your workforce stays exactly as exposed as the day you started.
Phishing simulation-based training sends employees fake phishing emails and trains the ones who click. The logic feels sound: find the people who fail, teach them, get safer. But only the people who fail a simulation get trained, and most employees never fail one. So most of your workforce learns nothing, and real-world resilience barely moves.
The problem: most employees never get trained
Run a simulation across the company and the result is lopsided. A small group clicks and gets a short lesson. Everyone else, the majority who hesitated, deleted the email, or ignored it, gets nothing, because the lesson is only triggered by failure. That leaves more than 90% of employees outside the training loop. As one practitioner put it, "90% of the people who fail simulations never receive any real guidance." And even the few who are served training rarely engage: independent research shows only a small fraction fully complete or absorb it.

Why it matters: a trained 3% is not a resilient organization
Resilience is organization-wide. An attacker needs only one person to click, and that person is far more likely to come from the untrained majority than the small group who already failed a test and got coached. This is the silent majority problem: employees who are unsure about an email but neither click nor report it. In a simulation-only model they are invisible, they never trigger a failure, so they never trigger a lesson. They carry real risk and get zero guidance, year after year.
It also explains a familiar frustration. You run more simulations, tighten the lures, push the click rate down a point, and resilience still does not improve. That is not a sign you are running simulations badly. By design, the method was only ever going to reach a fraction of your people.

How we designed the platform to close the gap
If training only reaches the people who fail, the fix is to make guidance available to everyone at the moment they are unsure. Reporting turns safe behavior into training: every time an employee reports a suspicious email they get immediate feedback, and that reaches the people who did the right thing, not just those who failed. It is the only scalable way to train everyone, because it does not depend on a click.
The Phished Assistant trains the silent majority. When an employee is unsure about an email or link, they open it in an isolated digital silo, a separated environment where they can safely explore it, with nothing able to reach your IT infrastructure even if the link is malicious. AI analyzes the content and coaches them in context. It works for any channel, a link or attachment in Teams, a QR code, an SMS, because real attacks do not stop at email. Alongside this, the Phished Academy builds knowledge progressively for the whole workforce, tracked in the Behavioral Risk Score (BRS) so resilience becomes measurable across everyone, not just a click rate for the few.
Simulations still surface risk and create realistic practice. But on their own they were never going to build resilience, because they were never going to reach most of your people. Reaching everyone, at the moment of doubt, is what does.
Frequently asked questions
Does phishing training actually work?
Not in the form most companies run it. Traditional phishing training only teaches the employees who fail a simulation, and most never fail one, so the majority get no training at all. By Phished's internal estimates, simulation-based training reaches only around 2-3% of the phishing attack surface. Training does work when it reaches everyone at the moment of risk: immediate feedback when an employee reports, in-the-moment guidance for the unsure, and structured learning that builds knowledge across the whole workforce, not just the few who clicked.
Why does phishing simulation-based training fail to improve resilience?
Because it only trains the employees who fail a simulation, and most never fail one. More than 90% of the workforce receives no meaningful training, so organization-wide resilience barely changes. By Phished's internal estimates, simulations alone reach only around 2-3% of the phishing attack surface.
Who is the silent majority in phishing training?
Employees who are unsure about a suspicious email but do not click and do not report it. They carry real risk, but in a simulation-only model they never trigger a lesson, so they get no guidance.
Should we stop running simulations?
No. They are useful for surfacing risk and creating realistic practice. The problem is relying on them as the whole program. They work best alongside reporting-based training and in-the-moment guidance that reach the employees simulations never touch.
Train the 90% simulations miss
See how reporting-based training and the Phished Assistant reach every employee, not just the ones who fail a test.