Highlights
A CISO who runs phishing tests told us this week that he wishes the industry had never had.
Most simulations test the wrong person: the mechanic, not the controller who wires money.
A click is a control failure first and an employee failure a distant second.
Security awareness has a settled belief at its center: the phishing simulation measures human risk. You send the lure, you count the clicks, you report the rate to the board. The number goes down, the program is working. Every compliance framework asks for it, every platform in the category sells it, and every CISO runs it.
In a conversation this week with the CISO of an AI company, he told me he wishes the industry did not do phishing at all. He does not think it is effective. He runs it anyway, because the frameworks require it. Then he said the thing that has been rattling around my head since: a phishing test feels like a prank. Everyone loves watching a prank. Nobody likes being the subject of one.
Here is my claim. He is right about the prank, and the reason he is right is not that testing people is wrong. It is that we test the wrong people, for the wrong failure, and then hand them the blame.
The mechanic and the controller
He told a story that has been circulating in security circles for years: a company fired a mechanic for failing a phishing test. His reaction was simple. That is not his job. A mechanic fixes cars. If clicking a link on his account could hurt the company, someone gave him access he never needed, and that someone is not him.
Contrast the controller. She receives an invoice that looks real, from a vendor that is not, and pays it. Twenty thousand dollars gone. Is that an insider risk? He does not think so. She was doing her job and was not careful enough about one specific, learnable thing: knowing who the real vendors are. That knowledge is squarely inside her role. Nobody else in the company can pay an invoice, so nobody else needs that training.
That distinction does a lot of work. Human risk is not evenly distributed across a headcount, and it is not primarily about who will click. It is about who can act: who can move money, who can grant access, who can ship code, who can talk to the customer. The mechanic can do none of those things. The controller can do one of them very well.
Whose failure is it
The second thing he said cuts deeper. Punishing a click treats the employee as the last line of defense, when the click is more a failure of every other control than of the person. His analogy: you bring your car to the mechanic because something broke, and the mechanic berates you for breaking it. Nobody expects the driver to be the engineer. The whole point of the system is that safety lives in the machine, not in the operator's vigilance.
Security has quietly inverted that. We built inadequate controls, then made the outcome the individual's responsibility. Phishing simulations, run as gotchas, are the ritual that makes the inversion feel legitimate. Blame is a moat around the security team, and the employee is on the far side of it.
A narrower, harder test
None of this argues for stopping. It argues for aiming. A simulation earns its place when it is scoped to a role's real authority and a real attacker's real path: the controller gets the fake invoice, the engineer gets the fake package, the executive assistant gets the fake wire request. Everyone else gets left alone, or gets a reminder rather than a trap.
And when someone does fail, the response is the same as the mechanic's: fix the system, tell the driver what happened, move on. No leaderboard. No gift card. No prank.
That is how Cimento thinks about the phishing simulation now: less a census of who clicks, more a targeted probe of who can hurt you and how. The click rate was never the risk. The authority behind the click was.
Key Takeways
Map simulations to who can act, not who can click: money, access, code, customer.
Treat a failed test as a control gap first and route the fix to the system owner.
Retire gotcha campaigns for roles with no meaningful authority; use reminders instead.
Kill the leaderboard; gamification did not move behavior in the program described here.
Report risk to the board by authority tier, not as a single company-wide click rate.




