GuideJuly 11, 20267 min read

Just-in-Time Awareness: Teaching at the Moment of the Click

The single most effective moment to teach someone about phishing is right after they almost fall for it. Here is how just-in-time awareness pages work, and why they outperform annual training.

Why Annual Training Loses to the Forgetting Curve

Traditional annual security awareness training is scheduled around the compliance calendar, not around when an employee is actually vulnerable. By the time the next real or simulated phishing email arrives, months may have passed since the last training session, and the specific red flags taught in that session have faded into general, hard-to-recall advice like "be careful with links." Cognitive science on the forgetting curve is unambiguous: without reinforcement, most of what people learn in a single session is gone within weeks, not months.

Annual training also teaches in the abstract. Employees learn about phishing as a category, not about the specific email that will eventually land in their inbox, and the gap between abstract knowledge and applied recognition is exactly where attacks succeed. A person who scored well on an annual quiz about phishing indicators can still click a well-crafted email months later, because the quiz tested recall, not real-time judgment under the mild social pressure of an urgent-looking message from HR or IT.

The fix is not more annual training, it is training that arrives at the moment the skill is actually needed: immediately after someone clicks a simulated phishing link, while the specific email, its sender, its urgency cues, and its request are still fresh in their mind. This is the premise behind just-in-time, or JIT, awareness, and it is one of the most consistently effective levers available to a security team.

How Just-in-Time Awareness Works

When an employee clicks a tracked link in a simulated phishing email, the click is logged and the employee is redirected, in real time, to a short awareness page tailored to the specific attack type they just fell for, rather than to a generic failure page or the real destination the attacker would have used. The page loads within the same browsing session, in the same language the employee works in day to day, so the connection between the click and the lesson is immediate and unmistakable.

The content on that page is deliberately narrow: it shows the exact email the employee just clicked, annotated with the specific red flags present in that message, a mismatched sender domain, an urgency cue, a request that bypasses normal process, rather than a generic list of phishing indicators unrelated to what just happened. This specificity is what separates JIT awareness from a training video; the employee is not being asked to generalize from an example, they are looking at the actual artifact that fooled them.

Because the trigger is behavioral, a click, rather than calendar-based, an assigned module due date, JIT awareness reaches exactly the population that needs it most, at the exact moment their attention and receptivity are highest. An employee who never clicks anything never sees a JIT page and is not interrupted with training they do not need; an employee who clicks repeatedly sees the lesson every time, which is precisely the reinforcement pattern the forgetting curve requires.

Designing an Effective JIT Page

Tone matters as much as content. A JIT page framed as a scolding, essentially telling someone "you failed this test," triggers defensiveness and shame rather than learning, and employees who feel punished are measurably less likely to report the next suspicious email because reporting now carries a risk of being flagged as a repeat offender. The most effective pages open with a calm, factual statement, this was a simulated exercise, here is what to notice next time, and treat the click as a training opportunity rather than a disciplinary event.

Keep the page short enough to read in under sixty seconds: the specific red flags in the email that was clicked, one clear action for next time, report suspicious emails through the built-in button, verify sender addresses before clicking, and nothing else. Long-form training content belongs in the assigned micro-module that follows, not in the JIT page itself, which exists purely to close the loop between action and lesson while the moment is still fresh.

Localization is not optional for an Indonesian workforce. The page should render in Bahasa Indonesia by default for employees who work in Indonesian day to day, with attack-type-specific red flags translated naturally rather than literally, since a literal translation of English phishing terminology often reads as awkward or unclear to a non-native English speaker under time pressure. Rendering correctly on a mobile browser matters too, since a meaningful share of employees, particularly in branch and field roles, will open the simulation email on a phone.

Measuring JIT Impact

The most direct measure is repeat-click rate for employees who have seen a JIT page for a given attack type, compared against their click rate on the next simulation using the same attack type. A well-designed JIT program should show a meaningful drop in repeat clicks within the same attack category over two to three subsequent simulations; if the drop does not appear, the page content or tone likely needs revision rather than the underlying JIT mechanism.

View rate and time-on-page are secondary but useful signals: an employee who is redirected to the JIT page but closes the tab within two seconds is not absorbing the lesson, regardless of how well the content is written. Correlate JIT page engagement with subsequent reporting behavior too, since one goal of JIT content is to convert a click into a habit of reporting on future encounters, not just to prevent the specific click from recurring.

Track JIT effectiveness by attack type separately, because a JIT page that successfully reduces repeat clicks on credential-harvest templates may not transfer to reducing clicks on invoice-fraud or urgent-executive-request templates, which exploit different psychological triggers. Segmenting this data by department is equally important, since finance staff repeatedly clicking invoice-themed simulations after seeing JIT content point to a process gap, such as no verification step for payment requests, that awareness content alone cannot fully close.

Where JIT Fits in a Broader Program

JIT awareness is not a replacement for structured training, it is the fast-response layer that sits between the moment of risk and the next scheduled learning intervention. It works best when it is one stage in an escalation model: JIT page on first click, a short targeted micro-module if the pattern repeats, and a coaching conversation for a genuine repeat clicker whose behavior has not shifted despite both.

Claro's JIT queue delivers these pages the moment a tracked click is recorded, decoupled from the main tracking pipeline so a slow awareness-page render never delays the click redirect the employee actually experiences, and every view is logged as an event that feeds directly into the same risk scoring and reporting-rate metrics used for board and compliance reporting. That integration is what turns JIT from a nice training gimmick into a measurable, auditable part of the security culture program.

Start by instrumenting JIT pages for your highest-volume attack types, credential harvest and urgent-action requests are usually the majority of clicks in an Indonesian financial services context, measure repeat-click reduction over the following quarter, and expand coverage to less common attack types once the pattern is proven. A JIT program that tries to cover every possible scenario on day one usually ships generic, unhelpful content; narrow and specific beats broad and vague.

Key takeaways

  • Annual training loses to the forgetting curve; the lesson has to arrive at the moment the skill is needed.
  • Effective JIT pages show the exact email that was clicked, annotated with its specific red flags, not generic phishing tips.
  • Tone matters: factual and coaching-oriented JIT content keeps reporting rates high; punitive framing suppresses future reporting.
  • Measure JIT impact through repeat-click reduction by attack type, not just page view counts.
  • JIT is the fast-response layer of a broader program, not a substitute for targeted micro-modules and coaching.

Build a program that sticks

Claro helps you run simulation, training, and reporting in one place.

Request a demo