Home / Blog / Awareness & Training

Phishing Simulations: Turning Failed Clicks Into a Stronger Security Culture

Phishing Simulations: Turning Failed Clicks Into a Stronger Security Culture

When a Nairobi-based SACCO ran its first phishing simulation last year, 41% of staff clicked a fake M-PESA reconciliation email within four hours. Leadership's first instinct was to reprimand. That would have been the wrong move. Phishing simulations only build a stronger security culture when failed clicks are treated as data, not misconduct.

This matters because phishing remains the dominant initial access vector for attacks on East African banks, telcos, and government agencies. Threat groups like SilverTerrier and regional business email compromise (BEC) operators specifically craft lures around mobile money, KRA notices, and supplier invoices. If your workforce cannot spot these in a controlled test, they will not spot them in a real attack.

Why Most Phishing Programs Fail to Change Behaviour

Running a quarterly simulation and emailing a scorecard to HR is not a security awareness program. It is a compliance checkbox. Real behaviour change requires three things most East African enterprises skip:

  • Lures that reflect the local threat landscape — generic "DHL package" templates from a global vendor do not test what your staff actually face. Test with fake KRA iTax notices, NHIF updates, M-PESA business till alerts, and internal HR emails.
  • Immediate, non-punitive coaching — the teachable moment is the 30 seconds after someone clicks. Redirect them to a short, plain-language explainer, not a shaming page.
  • Metrics that track improvement over time — the click rate on your fifth simulation matters more than the click rate on your first. If it is not dropping, your program is broken.

Designing Simulations That Actually Test Your People

Start with a baseline. Run an unannounced simulation before any training so you know where you actually stand. Then design a 12-month campaign that escalates in sophistication.

Tier 1: Obvious Lures (Months 1–3)

Spelling errors, mismatched sender domains, generic greetings. If more than 20% of staff click these, you have a foundational problem. Focus training on the basics: hover before you click, verify the sender domain, question urgency.

Tier 2: Contextual Lures (Months 4–8)

Emails that reference real internal systems — a fake Microsoft 365 password expiry, a spoofed message from a real supplier, a fake IT ticket. This is where most East African organisations sit in reality, because attackers do their homework on LinkedIn and company websites.

Tier 3: Targeted Spear Phishing (Months 9–12)

Simulate BEC attacks against finance staff and executive assistants. Use real names, real project references, and pretexts that mirror what has actually been seen in Kenyan banking fraud cases. This is the level attackers are operating at right now.

Expert tip: Never run a simulation during a high-stress business period like month-end close or year-end audit. You will get inflated click rates that do not reflect true awareness gaps, and you will damage trust in the program.

Turning a Failed Click Into a Learning Moment

The worst thing you can do after a failed click is nothing. The second worst is public shaming. The Kenya Data Protection Act imposes obligations around workforce training, and Section 41 makes clear that data controllers must implement appropriate organisational measures — that includes competent, trained staff.

Here is what works:

  • 30-second micro-learning immediately after the click — a short page explaining the specific red flags in the email they just clicked.
  • Mandatory 5-minute follow-up training within 24 hours — reinforcement while the memory is fresh.
  • Repeat offenders get one-on-one coaching, not punishment — three failed clicks in six months usually signals a role-based risk (finance, procurement, executive assistants) that needs targeted intervention.
  • Celebrate the reporters — the staff who report suspicious emails are your early warning system. Recognise them publicly. This shifts culture faster than any training module.

Security Awareness Training Service Page

Measuring What Matters

Click rate is the vanity metric. The real metrics for a mature program are:

  • Report rate — what percentage of staff actively report the simulated phish? Target above 40% within 12 months.
  • Time to first report — how quickly does someone flag it? Under 10 minutes indicates a healthy security culture.
  • Repeat click rate — the percentage of staff who click a second time after training. This should trend toward zero.
  • Department-level risk profile — which teams need targeted intervention?

A well-run phishing simulation program cuts successful phishing incidents by 60–80% within a year, based on what we see across our client base. It also generates board-ready evidence for ISO 27001 Annex A.6.3 and SOC 2 CC1.4 controls.

ISO 27001 Compliance Consulting

The Bottom Line

Every failed click is a free preview of a real attack. Treat it that way. Build a program that tests realistically, coaches immediately, and measures what matters — and your workforce becomes the strongest layer of your defence, not the weakest.

Our team delivers security awareness training tailored to the African threat landscape. Reach out today.