The situation Recep described sums it up perfectly: phishing exploits expectation more than carelessness.
Here's a practical order for those planning awareness campaigns:
First, set up the reporting channel. Before training, have one single path where you can tell people "if you're suspicious, hit this."
Then do short and frequent training. Fifteen minutes every three months yields much better results than two hours once a year.
Next, repeat the drill and track the reporting rate and time-to-first-report instead of the click rate.
Finally, don't forget technical measures: awareness alone isn't enough. When 2FA is enabled, a stolen password is useless on its own. You can't zero out human error, but you can neutralize its impact.
If you want to discuss in detail, feel free to open a support thread, we'll help.