Skip to content

Explaining behavior-based remediation to clients

When a client asks “what’s the point of these phishing tests if people still fail them?” — this article is what you read before that conversation. The client-facing one-pager is what you hand to the client. This is what makes the explanation sound smart.

Human risk runs on a loop: test → measure → remediate → reinforce → re-test.

  • We test with a realistic phishing simulation, tagged with the one defensive habit it exercises.
  • We measure what happened: who clicked, on what, exhibiting what weakness.
  • We remediate in the moment — the click opens a three-minute module tied to the specific habit they missed.
  • We reinforce the next day with a follow-up email if they didn’t finish, and again every time they re-enter the rotation.
  • We re-test with the next simulation — and now you can see whether the habit took.

Per-user risk scoring closes the loop. You see who’s improving, who’s repeat-failing on the same habit, and where to spend coaching time. That’s what makes the program measurable instead of a one-off blast — the test surfaces a specific failure, and the next test verifies the specific fix.

This is structurally the same loop our dark web feature closes between an exposed credential and its resolution. Two signals, one shape — see Explaining Dark Web Monitoring to clients for the partner-side language on that one.

Why in-the-moment, behavior-specific coaching

Section titled “Why in-the-moment, behavior-specific coaching”

Traditional awareness training works the wrong muscle. It asks the user to scrutinize every email — slow down, hover every link, read every subject line skeptically. That’s a request to run slow, effortful, deliberate analysis on the dozens or hundreds of emails that hit an inbox each day. It’s unsustainable. Vigilance decays. Under time pressure or cognitive load, people stop doing it — and that’s exactly when the bad email arrives.

Phishing is engineered for autopilot. Familiar logos, urgency cues, executive sender names, plausible subject lines — they all trigger fast, automatic, intuitive judgment, the mode that’s always running underneath. The attacker doesn’t need to fool deliberate analysis; they need to never let it wake up.

The fix isn’t try harder to be deliberate. It’s to install a small set of reflexes that fire automatically — simple rules that make the safe response easier than the unsafe one.

Two design choices follow:

  1. In the moment of failure. Coaching delivered at the click — when the consequence is concrete and the context is fresh — sticks. The same coaching delivered weeks later in a generic mandatory video doesn’t.
  2. One specific behavior at a time. A single installable habit beats a generic “be more careful.” We tag each test with the one defensive habit it exercises, and the lesson teaches that exact habit — nothing else.

Reinforcement — the day-after reminder, the next test, the test after that — is what turns a taught habit into a reflex.

We use Daniel Kahneman’s System 1 / System 2 model from Thinking, Fast and Slow as the design lens for this — System 1 the automatic mode, System 2 the deliberate mode, awareness training that targets System 2 alone failing to scale. It’s a design rationale, not a neuroscience claim. The goal isn’t to rewire anyone’s brain; it’s to make the safe move automatic.

Keep that framing here, in the partner guide. Clients don’t need it — what they need is the three-minute lesson and the calm leave-behind. The conceptual model is what gives you the language to defend the design when the client asks why.

Each habit is engineered as an installable rule — a heuristic that removes the need for case-by-case analysis when the email arrives.

The habit: Open the company’s site or app yourself instead of clicking a “log in” or “verify” link in an email.

Why it works as a reflex: It removes link trust from the decision entirely. There’s nothing to analyze. If the email says “log in to your bank,” you go to the bank’s site yourself. The fuzzy “is this link safe?” judgment becomes a fixed action.

The habit: Check the actual sending address, not the display name.

Why it works as a reflex: It converts a vague “this feels legit” feeling into one concrete, repeatable check. Display names lie cheaply; the underlying address doesn’t.

The habit: Confirm money, gift card, or credential requests by phone or in person.

Why it works as a reflex: A fixed rule for the highest-loss category of attack, independent of how convincing the email is. Even a perfectly-crafted CEO impersonation fails the rule.

The habit: Don’t open attachments you weren’t expecting, even from known contacts.

Why it works as a reflex: A bright-line default that doesn’t depend on judging the sender. The known-contact trust factor — what makes attachment-based attacks work — is taken out of the decision.

The MSP work here is oversight, not chasing. The per-user follow-up runs itself.

What we handleWhat you handle
Selecting tests and tagging them with the defensive habit each one exercisesWatching trends and repeat-risk users on the dashboard
Delivering the in-flow lesson the moment a click happensOptionally using results to target future tests at a group or person
Sending the day-after reminder if the lesson isn’t done(That’s it)
Tracking status, completion, and per-user risk

The client’s admin gets the same dashboard visibility you do — they can see who’s improving without you having to package it up. End users take the three-minute lesson when it appears and apply the habit in their real inbox. No ticket queue lands on your team to drive remediation.

A few framings that land in conversation:

The non-punitive pitch. “It’s coaching, not blame. The lesson never names the specific test someone fell for — it teaches the habit they missed. There’s no shame moment to dread, so people actually do it.”

The time pitch. “Three minutes, in the moment, tied to one habit. Not a quarterly hour-long video.”

The durability pitch. “It builds an automatic reflex, not a memory of one bad click. The point is to make the safe move easier than the unsafe one every time the next email lands.”

How it pairs with the rest of the platform. “The phishing tests are the engine — they surface who’s vulnerable to what. Behavior remediation is the teaching half. Dark web monitoring is a separate signal entirely — credentials in the wild rather than behavior. The through-line is the loop: test, measure, fix, reinforce, re-test.”

Does this add work for our team? No. We deliver the lesson and the day-after reminder automatically. Your admins watch trends on the dashboard; nothing lands in a ticket queue.

What if someone doesn’t finish the lesson at the click? A day-after email links them back. The lesson doesn’t expire — they can complete it whenever.

Does it expose or punish the person who clicked? No. The lesson never names the test they fell for. It teaches the habit they missed. You and the client admin see the data on the dashboard; the user sees only a coaching moment.

How is this different from generic security awareness training? Generic training asks people to be vigilant on every email — to run deliberate analysis all day. That doesn’t last. Behavior remediation installs specific reflexes in the moments they’re most teachable: right after a real-feeling failure. We coach the habit, not the alertness.

What if I send a phishing test on demand outside the rotation? On-demand tests are tagged the same way and trigger the same lesson if the recipient fails. The remediation loop isn’t tied to the automatic rotation — it’s tied to the test’s behavior tag.

Can a client turn it off? Yes — there’s a per-client override. We turn it on by default for new clients because it’s the better experience; partners with a specific reason to keep the generic post-click page can flip it off in Tailor → Phishing. See Behavior-based remediation for the toggle locations.