Why telling staff off makes your security worse

Published 2026-07-27 by Woodruff Training

The employee who clicks a phishing link is not your biggest problem. The one who clicks it, realises something is wrong, and says nothing for three days is. That gap is where the damage happens, and the way you handle the first mistake decides how long the gap will be next time.

Fear buys you silence

Hardly any owner sets out to run security by telling people off. It creeps in anyway. Someone falls for a convincing email, there is an awkward meeting about it, word gets round the office, and the lesson everybody quietly takes away is that owning up is expensive.

So the next person who clicks something odd sits on it. They hope it was nothing, wait to see whether anything happens, then get on with their afternoon. Meanwhile the criminal has a free run: reading the mailbox, learning who pays the invoices, and setting up a rule that hides their own replies from the person whose account it is.

Phishing simulations run as a trap do the same damage. Once the results turn into a list of names, staff stop treating the test as practice and start tipping each other off. You end up with a flattering number that tells you nothing about how the team would cope with the real thing.

Measure reporting, not clicking

Click rate is the figure everyone reaches for. Reporting rate is the one worth watching, because it tells you how fast you would hear about a genuine attack, and speed is what limits the damage.

A team where a third of people click but everyone reports within ten minutes is in better shape than a team where nobody clicks and nobody speaks up either. Push the reporting number up. The clicking number usually falls on its own once people are paying attention.

What works instead

  • Thank people for reporting, out loud, including the false alarms. Someone forwarding a real invoice just in case is doing exactly what you want them to do.
  • Make reporting take one click. A button in Outlook, or one address everybody knows. If it needs a written explanation, most people will not bother.
  • Keep individual results private. Share the team's overall figures, and coach anyone who is struggling quietly, without an audience.
  • Train during work hours and keep sessions short. Asking staff to do security learning in their own evening tells them precisely what you think it is worth.
  • Go first yourself. When the owner admits they nearly fell for something last month, it stops being a test of competence and becomes a normal part of the job.

None of this is soft. A business where people put their hand up early gets an incident closed in an afternoon instead of a fortnight, and the difference shows up in what it costs you.

The other half of this is knowing what happens next. We have put that on a one-page first hour incident card you can print and keep by the phone. If you cannot fill in the "who to call" lines today, that is worth half an hour of somebody's time this week.

If you want a hand building that habit, our course for managers and owners is built around exactly this. Get in touch and we'll talk it through.