Explaining behavior-based remediation to clients
When a client asks “what’s the point of these phishing tests if people still fail them?” — this article is what you read before that conversation. The client-facing one-pager is what you hand to the client. This is what makes the explanation sound smart.
The loop
Section titled “The loop”Human risk runs on a loop: test → measure → remediate → reinforce → re-test.
- We test with a realistic phishing simulation, tagged with the one defensive habit it exercises.
- We measure what happened: who clicked, on what, exhibiting what weakness.
- We remediate in the moment — the click opens a three-minute module tied to the specific habit they missed.
- We reinforce the next day with a follow-up email if they didn’t finish, and again every time they re-enter the rotation.
- We re-test with the next simulation — and now you can see whether the habit took.
Per-user risk scoring closes the loop. You see who’s improving, who’s repeat-failing on the same habit, and where to spend coaching time. That’s what makes the program measurable instead of a one-off blast — the test surfaces a specific failure, and the next test verifies the specific fix.
This is structurally the same loop our dark web feature closes between an exposed credential and its resolution. Two signals, one shape — see Explaining Dark Web Monitoring to clients for the partner-side language on that one.
Why in-the-moment, behavior-specific coaching
Section titled “Why in-the-moment, behavior-specific coaching”Traditional awareness training works the wrong muscle. It asks the user to scrutinize every email — slow down, hover every link, read every subject line skeptically. That’s a request to run slow, effortful, deliberate analysis on the dozens or hundreds of emails that hit an inbox each day. It’s unsustainable. Vigilance decays. Under time pressure or cognitive load, people stop doing it — and that’s exactly when the bad email arrives.
Phishing is engineered for autopilot. Familiar logos, urgency cues, executive sender names, plausible subject lines — they all trigger fast, automatic, intuitive judgment, the mode that’s always running underneath. The attacker doesn’t need to fool deliberate analysis; they need to never let it wake up.
The fix isn’t try harder to be deliberate. It’s to install a small set of reflexes that fire automatically — simple rules that make the safe response easier than the unsafe one.
Two design choices follow:
- In the moment of failure. Coaching delivered at the click — when the consequence is concrete and the context is fresh — sticks. The same coaching delivered weeks later in a generic mandatory video doesn’t.
- One specific behavior at a time. A single installable habit beats a generic “be more careful.” We tag each test with the one defensive habit it exercises, and the lesson teaches that exact habit — nothing else.
Reinforcement — the day-after reminder, the next test, the test after that — is what turns a taught habit into a reflex.
We use Daniel Kahneman’s System 1 / System 2 model from Thinking, Fast and Slow as the design lens for this — System 1 the automatic mode, System 2 the deliberate mode, awareness training that targets System 2 alone failing to scale. It’s a design rationale, not a neuroscience claim. The goal isn’t to rewire anyone’s brain; it’s to make the safe move automatic.
Keep that framing here, in the partner guide. Clients don’t need it — what they need is the three-minute lesson and the calm leave-behind. The conceptual model is what gives you the language to defend the design when the client asks why.
The four defensive habits
Section titled “The four defensive habits”Each habit is engineered as an installable rule — a heuristic that removes the need for case-by-case analysis when the email arrives.
Go direct
Section titled “Go direct”The habit: Open the company’s site or app yourself instead of clicking a “log in” or “verify” link in an email.
Why it works as a reflex: It removes link trust from the decision entirely. There’s nothing to analyze. If the email says “log in to your bank,” you go to the bank’s site yourself. The fuzzy “is this link safe?” judgment becomes a fixed action.
Verify the sender
Section titled “Verify the sender”The habit: Check the actual sending address, not the display name.
Why it works as a reflex: It converts a vague “this feels legit” feeling into one concrete, repeatable check. Display names lie cheaply; the underlying address doesn’t.
Verify out-of-band
Section titled “Verify out-of-band”The habit: Confirm money, gift card, or credential requests by phone or in person.
Why it works as a reflex: A fixed rule for the highest-loss category of attack, independent of how convincing the email is. Even a perfectly-crafted CEO impersonation fails the rule.
Skip unexpected attachments
Section titled “Skip unexpected attachments”The habit: Don’t open attachments you weren’t expecting, even from known contacts.
Why it works as a reflex: A bright-line default that doesn’t depend on judging the sender. The known-contact trust factor — what makes attachment-based attacks work — is taken out of the decision.
What you do vs. what’s automated
Section titled “What you do vs. what’s automated”The MSP work here is oversight, not chasing. The per-user follow-up runs itself.
| What we handle | What you handle |
|---|---|
| Selecting tests and tagging them with the defensive habit each one exercises | Watching trends and repeat-risk users on the dashboard |
| Delivering the in-flow lesson the moment a click happens | Optionally using results to target future tests at a group or person |
| Sending the day-after reminder if the lesson isn’t done | (That’s it) |
| Tracking status, completion, and per-user risk |
The client’s admin gets the same dashboard visibility you do — they can see who’s improving without you having to package it up. End users take the three-minute lesson when it appears and apply the habit in their real inbox. No ticket queue lands on your team to drive remediation.
How to position it to clients
Section titled “How to position it to clients”A few framings that land in conversation:
The non-punitive pitch. “It’s coaching, not blame. The lesson never names the specific test someone fell for — it teaches the habit they missed. There’s no shame moment to dread, so people actually do it.”
The time pitch. “Three minutes, in the moment, tied to one habit. Not a quarterly hour-long video.”
The durability pitch. “It builds an automatic reflex, not a memory of one bad click. The point is to make the safe move easier than the unsafe one every time the next email lands.”
How it pairs with the rest of the platform. “The phishing tests are the engine — they surface who’s vulnerable to what. Behavior remediation is the teaching half. Dark web monitoring is a separate signal entirely — credentials in the wild rather than behavior. The through-line is the loop: test, measure, fix, reinforce, re-test.”
Quick answers
Section titled “Quick answers”Does this add work for our team? No. We deliver the lesson and the day-after reminder automatically. Your admins watch trends on the dashboard; nothing lands in a ticket queue.
What if someone doesn’t finish the lesson at the click? A day-after email links them back. The lesson doesn’t expire — they can complete it whenever.
Does it expose or punish the person who clicked? No. The lesson never names the test they fell for. It teaches the habit they missed. You and the client admin see the data on the dashboard; the user sees only a coaching moment.
How is this different from generic security awareness training? Generic training asks people to be vigilant on every email — to run deliberate analysis all day. That doesn’t last. Behavior remediation installs specific reflexes in the moments they’re most teachable: right after a real-feeling failure. We coach the habit, not the alertness.
What if I send a phishing test on demand outside the rotation? On-demand tests are tagged the same way and trigger the same lesson if the recipient fails. The remediation loop isn’t tied to the automatic rotation — it’s tied to the test’s behavior tag.
Can a client turn it off? Yes — there’s a per-client override. We turn it on by default for new clients because it’s the better experience; partners with a specific reason to keep the generic post-click page can flip it off in Tailor → Phishing. See Behavior-based remediation for the toggle locations.
Hand-off
Section titled “Hand-off”- Behavior-Based Remediation — Turning Phishing Clicks into Defensive Habits — the one-pager to leave with a client.
- Behavior-based remediation — the in-product task article: where the toggle lives, how the per-client override works, and what the four reporting cards on Settings → Phishing show you.