GuideJuly 15, 20269 min read

Reducing Repeat Clickers: A Behaviour-Change Playbook

A small group of habitual clickers usually drives most of an organization's phishing risk. Here is a fair, evidence-based way to identify them and move them toward safer behaviour.

Defining a Repeat Clicker Fairly

A repeat clicker is not simply anyone who has clicked a phishing simulation more than once ever; that definition is too broad and will sweep in employees who made a single lapse months apart under unrelated circumstances. A more defensible definition uses a rolling window, for example two or more clicks within a trailing twelve months, weighted by attack difficulty, so a click on a genuinely sophisticated executive-impersonation email counts differently than a click on a template with an obvious spoofed domain.

Fairness also means separating a repeat clicker from a repeat non-reporter; these are related but distinct behaviors, and conflating them leads to unfair targeting. Someone who clicks once but always reports afterward is showing good instincts once burned; someone who neither clicks nor reports is invisible in click-based metrics but may simply be deleting suspicious emails without engaging the organization's defenses at all, which is its own gap worth understanding.

Before labeling anyone, check for confounding factors: role-based exposure, since a procurement officer who handles genuine urgent vendor emails all day faces a harder discrimination task than most, recent onboarding, since new hires have not yet built organizational pattern recognition, and simulation difficulty calibration, since a campaign using an unusually convincing internal-brand template will naturally produce more clicks across the board, not just among people who are otherwise careless.

Understanding Root Causes Before Intervening

Not all repeat clicking has the same cause, and a single intervention applied uniformly will underperform against a tailored one. Some repeat clickers genuinely lack awareness of what to look for and respond well to education; others understand the concept perfectly well but operate under time pressure and high message volume that makes careful verification feel impractical, particularly in customer-facing or high-volume transactional roles.

A third group understands the risk and has the time to verify but has never been given a clear, low-friction way to do so, meaning the gap is procedural rather than educational: no easy reporting button, an unclear escalation path for something that looks odd but is not certain, or a culture where asking whether a message is real is seen as slowing down urgent work. A fourth, smaller group shows a pattern that correlates with genuine disengagement or performance issues broader than security awareness, which is a management conversation, not a training one.

Distinguishing between these groups requires looking past the click data itself: pair repeat-click records with role, tenure, recent survey responses if available, and manager input before deciding on an intervention. Treating a time-pressured, high-volume transaction processor the same as a genuinely unaware new hire wastes effort on both and risks the time-pressured employee feeling unfairly targeted for a structural problem that is not really theirs to fix alone.

The Intervention Ladder

Start with the lightest-touch intervention and escalate only if the pattern persists, rather than jumping straight to a formal conversation on the first repeat. The first rung is the just-in-time awareness page shown immediately after each click, which is often sufficient on its own for employees whose repeat clicking stems from a genuine, correctable awareness gap rather than a structural or motivational issue.

If clicking continues after two JIT exposures for the same attack type, the second rung is a short, targeted micro-module, five minutes or less, assigned automatically, focused specifically on the attack pattern the employee keeps falling for rather than a generic phishing overview they have likely already completed. The third rung, reserved for a genuine, persistent pattern across multiple campaigns and attack types, is a brief coaching conversation with the employee's manager or the security team, framed around understanding the barrier, whether time pressure, unclear process, or a genuine gap, rather than delivering a verdict.

The top rung, reserved for a small number of cases where coaching has not shifted behavior over one to two quarters, may involve workflow or technical controls rather than more training: additional email authentication warnings for that user's inbox, a mandatory verification step added to their specific workflow, or role-based access adjustments if the risk that individual's clicking represents is disproportionate to their function. Escalating to this level should be rare and always paired with a documented rationale, since it shifts from behavior coaching into a more consequential intervention.

Coaching Over Punishment

Punitive framing, mandatory retraining presented as discipline, manager notification framed as a warning, public leaderboards of worst clickers, reliably backfires by suppressing the one behavior the organization needs most: reporting. An employee who fears being labeled a repeat offender for reporting a suspicious email they already clicked will simply stay quiet, which converts a recoverable incident into an unreported one that can escalate unnoticed.

Coaching conversations work better when they start from curiosity rather than judgment: asking what made the email convincing, what would have made it easier to spot, and whether the employee felt they had time to verify, surfaces real structural problems, such as unclear escalation paths or unrealistic workload, that punishment never reveals. This approach also aligns with how Indonesian workplace culture generally responds to authority-framed feedback; a conversation that preserves an employee's standing with peers and management produces more honest engagement than one that feels like public correction.

This does not mean consequences never apply. Where investigation shows willful policy violation, such as knowingly sharing credentials after being coached, or repeated disregard for a documented mandatory process, formal HR involvement is appropriate. The distinction is between behavior stemming from a fixable gap, which is the large majority of cases, and deliberate disregard for a known, reasonable control, which is rare and warrants a different track entirely.

Measuring the Reduction

Track the size of the repeat-clicker cohort itself as a headline metric, not just the aggregate click rate, since the whole point of this playbook is to shrink that specific population over time. A declining repeat-clicker count across consecutive quarters, even if overall click rate on any single campaign fluctuates with difficulty, is the clearest evidence the intervention ladder is working.

Measure transition rates between rungs of the ladder: what percentage of employees who received a JIT page never click that attack type again, what percentage need the micro-module, and what percentage require a coaching conversation. A healthy program shows the majority resolving at the lightest rung, with coaching reserved for a genuinely small minority; if a large share of employees needs escalation, the earlier rungs likely need redesign rather than more enforcement.

Report this cohort data alongside reporting-rate trends for the same population, since the ultimate goal is not just fewer clicks but more employees who catch themselves and report before or immediately after clicking. A repeat-clicker program that reduces clicks while reporting rate among that same cohort stays flat has changed avoidance behavior, not necessarily security judgment, and the distinction matters when a real attack eventually gets through the simulation-trained defenses.

Key takeaways

  • Define repeat clickers with a rolling window and attack-difficulty weighting, not a lifetime click count.
  • Root causes differ, awareness gap, time pressure, process gap, disengagement; diagnose before intervening.
  • Use an escalation ladder: JIT page, then targeted micro-module, then coaching, then workflow controls, in that order.
  • Punitive framing suppresses reporting; coaching conversations that start with curiosity surface real structural fixes.
  • Track the size of the repeat-clicker cohort over time, and pair it with reporting-rate trends for the same group.

Build a program that sticks

Claro helps you run simulation, training, and reporting in one place.

Request a demo