One Phishing Test a Year Is a Compliance Artifact, Not a Security Control

One Phishing Test a Year Is a Compliance Artifact, Not a Security Control

Why cadence beats the annual checkbox.

Most organizations run a phishing simulation once a year. It gets scheduled around the annual security awareness training, the results get screenshotted into a board deck, and the click rate gets compared to last year’s number. If it went down, everyone agrees the program is working.

That process satisfies an auditor. It does almost nothing to change what happens when a real credential harvesting campaign hits your organization on a Thursday afternoon in the middle of quarter close.

Here’s why cadence matters more than the test itself.

A single test measures a single day

An annual simulation gives you one data point; a snapshot, taken under conditions your organization will never see again.. Not a trend.

The problem is that the thing you’re trying to measure isn’t static. Susceptibility to phishing is a behavior, and behaviors decay without reinforcement. Organizations that run one campaign, deliver remediation training, and then go quiet typically watch their improvement erode inside a quarter. By month nine, you’re roughly back where you started, but your board slide still says 14%.

You didn’t build a control. You captured a moment.

Your workforce is not the same workforce

Between annual tests, a typical mid-market organization turns over a meaningful slice of its headcount and reshuffles a good deal of the rest. New hires arrive with no baseline at all. People move into roles with materially different risk exposure; an engineer who moves into a finance-adjacent function now has approval authority over wire transfers and has never once been tested against invoice fraud.

Meanwhile the org adopts new SaaS platforms, onboards new vendors, changes payroll providers, and stands up new internal tooling. Every one of those is a fresh, legitimate-looking pretext an attacker can borrow. Your last simulation tested none of them, because none of them existed yet.

Attackers iterate faster than your annual cycle

The tradecraft moves. In the last two years the practical phishing landscape has shifted toward:

  • Adversary-in-the-middle kits that proxy the real login page and capture session tokens, defeating most MFA implementations outright
  • MFA fatigue and push bombing, which trains on user annoyance rather than user credulity
  • QR-based lures (“quishing”) that move the malicious link onto a personal mobile device, outside your email security stack and outside your EDR
  • Callback phishing, where the email contains no link at all; just a phone number and a fabricated invoice
  • AI-assisted personalization built on OSINT, which strips out the grammatical tells your awareness training taught people to look for

An annual campaign built on last year’s template tests your people against a threat model that has already been retired.

The falling click rate can be a lie

This is the part most programs miss. A declining click rate has several possible causes, and only one of them is good:

  1. Your people genuinely got better at recognizing social engineering.
  2. Your people recognized your test; same sender conventions, same timing, same tells. The pattern-matched on the simulation rather than the tactic.
  3. Word spread. Someone posted in Slack. The population self-inoculated for 30 days.
  4. Your pretexts got easier, or your platform’s default templates got more obvious.

With one data point a year, you cannot distinguish between these. With a running cycle that varies pretext, difficulty, timing, and segment, you can; because a genuine behavioral improvement holds up when you change the variables, and a false one collapses the moment you do.

The metric that actually maps to incident response

Click rate is the number everyone reports and the number that matters least.

When a real campaign lands, your exposure is a function of dwell time. The clock that matters starts when the first employee reports the message and your team begins pulling it from other inboxes, resetting sessions, and hunting for successful authentications. Every hour before that first report is an hour an attacker spends inside a live session.

So the numbers worth trending are:

  • Report rate — what percentage of recipients flagged it, including the ones who never clicked
  • Time to first report — the single strongest predictor of real-world containment speed
  • Credential submission rate — meaningfully worse than a click, and often 3–5x lower, which means click rate systematically overstates your exposure
  • Repeat-clicker cohort — the small population driving most of your risk, which you can only identify across multiple campaigns
  • Reporting pipeline health — does the report button actually work, does a human triage it, and how long does that take at 4:50 PM on a Friday

Four of those five require more than one campaign to even calculate. That’s the argument for cadence in a sentence.

What a real cycle looks like

You don’t need to phish your entire organization every month. That produces fatigue, resentment, and inbox noise without producing better data.

A workable structure:

  • Monthly campaigns against rotating segments. Finance and AP, executive assistants, IT helpdesk, new hires in their first 30 days, and anyone with privileged access get tested more often than the general population, because they’re targeted more often in reality.
  • Full-organization campaigns quarterly. This is your trend line.
  • Rotating pretexts. Never repeat a template inside twelve months. Cycle through internal IT, vendor invoice, HR/benefits, MFA push, shared document, and QR-based lures.
  • Escalating difficulty. As a segment’s report rate climbs, tighten the lure. A program where everyone passes has stopped measuring anything.
  • Just-in-time remediation. Training delivered within seconds of a click lands. Training queued for the annual compliance window does not.
  • New-hire enrollment by default. Every new employee gets a baseline campaign inside their first month, automatically.

Two things to avoid

Don’t punish clickers. The fastest way to destroy your report rate is to make failure embarrassing. If people believe reporting draws attention to their own near-miss, they stop reporting and you’ve traded your most valuable detection signal for a slightly better click number.

Don’t use cruel pretexts. Fake bonus announcements, fake layoff notices, fake benefit terminations. They generate impressive click rates and permanent organizational resentment, and they’re the reason a meaningful number of awareness programs get shut down by HR.

The bottom line

An annual phishing test tells you how one population responded to one message on one day, under conditions that will never recur. A running cycle tells you whether your organization is measurably harder to compromise than it was last quarter and gives you the reporting metrics that determine how fast you contain the campaign that eventually gets through.

One is a compliance artifact. The other is a control.

Run one and find out where you actually stand Brackish Security will run a free phishing campaign against your organization; real pretexts, real tradecraft, real reporting metrics. No template library, no vanity click rate. You’ll see exactly how your people respond and how fast your reporting pipeline moves.
Start here →  https://brackish.io/contact