Is Your Phishing Strategy Built on Science or Suspensions?

A triumphant businesswoman cheering at her laptop in a bright office, representing a positive security culture and the success of a proactive phishing strategy.

I have spent a lot of time over the years talking to our teams about security. Across all those discussions, there has been one consistent thread: awareness is only half the battle. The other half is security culture. While we have previously discussed the importance of training for contractors to ensure every part of the business is covered, the way we deliver that training determines whether it actually sticks.

Why the “Stick” Approach Fails to Change Behaviour

Lately, I have noticed more companies leaning heavily on the “stick.” You might have seen the coverage in SC Magazine UK about firms suspending staff for failing cyber tests. It is an extreme approach that treats employees like a liability to be managed through HR sanctions.

We have always believed that “punishing” your way to a safer network simply doesn’t work. This isn’t just a hunch. A study from Carnegie Mellon University (Singh et al., 2024) titled “Does Penalty Help People Learn to Detect Phishing Emails?” found that imposing penalties for incorrect decisions didn’t significantly improve a person’s ability to catch a phish in the long run. When security is treated like a speed trap, people stop learning and start resentfully checking boxes.

Our Philosophy: More Carrots and Fewer Sticks

This is why we have long championed the more carrots and fewer sticks philosophy. Our approach has always been to move away from “test-and-punish” logic and toward a proactive model where security is a standard, non-threatening part of the daily routine. We even tested our own team using this mindset, and the results confirmed that transparency beats trickery every time you are trying to foster a positive security culture.

Operationalising a Proactive Security Culture

Our strategy relies on a Strategic Group Architecture that we have refined to automate the "carrot" side of the equation. Instead of treating everyone like a potential offender, our systems are set up to find the Security Champions.Our strategy relies on a Strategic Group Architecture that we have refined to automate the “carrot” side of the equation. Instead of treating everyone like a potential offender, our systems are set up to find the Security Champions. These are the people actively reporting threats. We make it a priority to recognise them because they are the ones building our collective defence.

We also take a different path with the learning itself. Rather than waiting for a failure to trigger “remedial” sessions, we provide regular 5-minute micro-learning modules to keep baseline knowledge sharp. This is a proactive way to stay ahead of new threats, particularly cyber threats that don’t arrive by email, such as SMS phishing or AI deepfakes, before they reach a device.

Turning Mistakes into Teachable Moments

When someone does click a simulated link, we don’t view it as a delinquency. We use a Point of Failure landing page to show exactly what was missed in that moment. It turns a mistake into a quiet, effective teaching moment, which is much more valuable than a public “gotcha.”

The goal has always been to foster a security culture where people report threats because they want to protect the company, not because they are afraid of the IT department. I have spent years documenting and refining the automated workflows and Smart Groups that make this possible. It is the same blueprint we use to help our customers move from reactive policing to genuine culture building.

If you are ready to move away from “gotcha” tactics and want to discuss how we can help you foster a culture where your team wants to protect the company, let’s have a chat.

KnowBe4 Security Awareness Training Brochure | Contact us
Sign up for our newsletter | KnowBe4