Behavior-based remediation
When a user clicks a phishing test, what they see after the click matters as much as the test itself. With behavior-based remediation on, the landing page and the day-after follow-up email both point the user at a short training module built around the specific defensive habit they missed — go direct to the source, verify the sender, verify out-of-band, or skip an unexpected attachment. The 3-minute module replaces the generic “you clicked a phish” page.
It’s on by default for every client. You’d only turn it off for a client whose users haven’t been onboarded to the new format yet, or for one that explicitly prefers the generic post-click page.
You’ll need
Section titled “You’ll need”Nothing. The feature ships on. You only need to act if you want to turn it off for a specific client.
Set the partner-wide default
Section titled “Set the partner-wide default”-
Open Settings → Phishing. The first card is Behavior-Based Remediation.
-
Confirm the toggle is on. A short description sits under the toggle explaining what changes when on.
-
Save. Your default applies to every client whose per-client override is set to Inherit (the default for new clients).
Override for one client
Section titled “Override for one client”-
Open the client → Tailor → Phishing. The Behavior-Based Remediation card is at the top of the page.
-
Set the override. The card shows your partner default with an Inheriting from your organization’s default [on/off] label, plus a toggle to set this client explicitly. Use the toggle to opt this client in or out independently of your default.
-
Save. Use Clear override (inherit) later if you want this client to follow your partner default again.
The four defensive behaviors
Section titled “The four defensive behaviors”We tag phishing tests with the one habit a user needed to catch the test. Four habits cover the vast majority of failures:
- Go direct — open the company’s site or app yourself instead of clicking a link in an email asking you to “log in” or “verify.”
- Verify the sender — check the actual sending address (not just the display name) before trusting any request.
- Verify out-of-band — when an email asks for money, gift cards, or credentials, confirm by phone or in person.
- Skip unexpected attachments — don’t open attachments you weren’t expecting, even from people you know.
A user who fails a tagged test is routed to that habit’s short module. Untagged tests keep the generic landing page regardless of the toggle.
Behavior reporting
Section titled “Behavior reporting”Settings → Phishing also surfaces four reporting cards summarising the last 90 days across all your clients. They appear whenever the master toggle is on.
- Behavior coverage — which defensive habit gets failed most often. A flat distribution tells you all four are getting tested; a lopsided one tells you the rotation skews to a single habit.
- Remediation completion — of the users we routed into a training module, how many finished it in-flow (on the landing page), how many finished it later from the day-after email, and how many haven’t finished at all.
- Urgency exploitation — what share of failures came from tests that lean on urgency pressure. A high number is a coaching opportunity in that group’s quarterly review.
- Sender pretext distribution — what type of sender the failed tests were impersonating (a service notification, an executive, an IT request, and so on).
Untagged failures are excluded from these cards — the cards describe the tagged test population only.
You’ll know it worked when
Section titled “You’ll know it worked when”- The Settings → Phishing card reads Behavior-based remediation is on.
- A client’s Tailor → Phishing card shows either Inheriting from your organization’s default on or your explicit override.
- After a user fails a tagged test, their result detail page (Risk → User → click the result) shows a Defensive behavior tested field.
- The four reporting cards on Settings → Phishing populate with numbers as new failures land.
Frequently asked
Section titled “Frequently asked”Is this on automatically for clients I’ve already onboarded? Yes. As of the rollout it’s on for every existing client; new clients you onboard from here on also come up with it on.
Will users notice a change overnight? Only at the moment they fail a phishing test. The user-visible difference is what they see after a click — a short module instead of a generic page — plus a follow-up email the next day if they didn’t finish the module on the landing page.
What if the phishing test doesn’t have a defensive behavior tagged? The user gets the generic post-click landing page and the standard follow-up. The toggle has no effect on untagged tests.
Does turning it off stop training reminders? No. Standard training reminders for assigned courses are unaffected. The toggle only changes the post-click landing page and the day-after email tied to a phishing failure.
Can I see behavior breakdowns for one specific client? Today the reporting cards on Settings → Phishing roll up across all your clients. For per-client behavior data, open the client’s Risk → Phishing activity and drill into individual results — each tagged result shows the defensive behavior tested on its detail page.
A user’s result shows “Verify the sender” but the test was a fake invoice attachment — is that wrong? Each test is tagged with the primary defensive habit a user needed to catch it. Some tests cover more than one (an invoice attachment from a spoofed vendor exercises both skip unexpected attachments and verify the sender); we pick the one we think the test most strongly trains and surface that. The training module covers the broader habit, not just the literal step.
Does this affect the user’s risk score? No differently than before. Clicking, submitting credentials, or opening an attachment still drive the score the same way. The remediation module’s completion isn’t part of the score today.
Related
Section titled “Related”- Phishing templates — the rotation behavior remediation routes from.
- Read phishing activity — the per-result detail page where defensive behavior shows up.
- Partner-level settings — the master toggle’s hub.