What action do you take when a user fails a simulated phishing test?

No action taken6%

Extra training required by user 95%

Permissions revoked5%

Disciplinary action taken against user3%

80 PARTICIPANTS
3k viewscircle icon1 Upvotecircle icon4 Comments
Sort by:
Principal Cybersecurity Specialist - SaaS Security5 months ago

It depends on what type of phishing test and which user group/persona failed it. Like, if was a accounts payable or HR payroll team, then more stringent action needs to be taken. 

Information Security Manager in Banking6 months ago

Not enough options for this. We provide a teachable moment and give them resources to read on their own. If it's a second or third failure we provide the teachable moment and assign a quick remedial online training. We also inform supervisors so they can address the behavior at their level if they need it. At the beginning of every year, everyone has a clean slate.

IT Operations Manager in Constructiona year ago

Follow-up question, for those opting for disciplinary action, do you think it is effective? 

Engineering Managera year ago

The best action is to provide additional training the the user(s) to increase awareness and knowledge. None of the other options in this poll are viable in the long-term. 

Lightbulb on2

Content you might like

Yes75%

No25%

Yes, we’re pausing 9%

Yes, we’re scaling back53%

Yes, we’re scaling up23%

No, we’re not changing our approach14%

N/A, we have no current projects

View Results