forumNew topic

We ran a phishing test on our employees, results were worse than expected

GGamzeMember
Job title
HR Specialist
Organization type
120-person company
Joined
Jul 2024
Message
104
#1

As HR, we ran a phishing drill with the security team. An email designed to look like an internal announcement was prepared, containing a link.

Result: a significant portion of the team clicked the link, and some entered their credentials into a fake login screen.

I have two questions now. First, is this result normal? Second, what should we do next — how do we proceed without shaming anyone?

SSerkan G***Expert
Job title
Penetration testing specialist
Organization type
a company within a holding
Joined
Nov 2023
Message
154
Most Helpful#2

The result is normal. In fact, in a well-prepared drill mimicking an internal announcement, a high click-through rate is expected. This isn't an intelligence test, it's an attention and context test.

Let me add my skeptical side too: you can't interpret the result without knowing the difficulty of the drill. An email with typos from an unknown address is not the same as an email that perfectly matches company templates and uses correct names. If your report doesn't state the drill's difficulty level, the rate alone means nothing.

Most important advice for going forward: don't expose anyone, don't publish name lists. In organizations that do this, nobody reports the next real incident because they're ashamed. An unreported incident is a late-detected incident.

The key metric you should measure isn't the click-through rate: it's the reporting rate. How many people found it suspicious and notified the security team, and how many minutes did it take for the first report? Make this your target for the next drill.

GGamzeMember
Job title
HR Specialist
Organization type
120-person company
Joined
Jul 2024
Message
104
#3

The reporting rate idea was really useful, thanks. Only three people reported it in our case, and two of them were from the same team.

One more question: what do you recommend to make reporting easier? Right now people have to email the security team at a separate address and i doubt anyone bothers.

DDefneMember
Job title
SOC Analyst
Organization type
a company within a holding
Joined
Feb 2024
Message
146
#4

That's exactly where you're losing them. The longer the reporting path, the fewer reports you get.

The technical fix is simple: add a one-click "report suspicious" button to the email client. Most corporate email systems have this as a plugin. User hits the button, message goes to the security team and disappears from the user's inbox.

The process side matters too: always follow up with the person who reported. The sentence "Reviewed, it was harmless, but thanks for reporting" is what gets the next report. An unanswered report is the last report.

Also, never scold a false alarm. A hundred false alarms are cheaper than one missed real incident.

PPerihanMember
Job title
Corporate communications
Organization type
regional distributor
Joined
Dec 2023
Message
118
#5

I'd like to add a point from corporate comms, because if the communication around these drills is mishandled, it can damage trust in the organization.

I'd recommend sticking to three principles when announcing drill results. Results should be shared company-wide, not by department or individual. The language should be explanatory, not accusatory; instead of "X people clicked," explain "what features of this email made it convincing." Finally, concretely show what to do if the same email were sent by a real attacker.

When we applied these three, participation went up and defensiveness went down.

RRecepNew member
Job title
Plumber
Organization type
20-person company
Joined
Dec 2024
Message
22
#6

Hey guys, i'm a plumber, these topics are way out of my league but let me share something that might help. Last month i got a message like that too, i was expecting a package that exact day and almost clicked the link.

What saved me was this: the courier company's name was correct but the address in the message was totally different, it caught my eye. Then i called the company and turns out it had nothing to do with my shipment.

So what i'm saying is, i haven't had any training but because i was expecting something, i almost got caught. I bet your employees were the same, it's not their fault.

DDoki destekDoki team
Job title
Technical Support
Sector
Cybersecurity and digital
Organization type
Doki
Joined
Mar 2023
Message
428
#7

The situation Recep described sums it up perfectly: phishing exploits expectation more than carelessness.

Here's a practical order for those planning awareness campaigns:

First, set up the reporting channel. Before training, have one single path where you can tell people "if you're suspicious, hit this."

Then do short and frequent training. Fifteen minutes every three months yields much better results than two hours once a year.

Next, repeat the drill and track the reporting rate and time-to-first-report instead of the click rate.

Finally, don't forget technical measures: awareness alone isn't enough. When 2FA is enabled, a stolen password is useless on its own. You can't zero out human error, but you can neutralize its impact.

If you want to discuss in detail, feel free to open a support thread, we'll help.

TTaner Y***Expert
Job title
Regional Manager
Sector
Electrical-electronics
Organization type
cooperative
Joined
Sep 2025
Message
3

Doki · Vulnerability scanning · 2025

#8

you're right.

LLale A***Member
Job title
Production Manager
Sector
Plastic
Organization type
20-person company
Joined
Sep 2025
Message
36

Doki · KVKK compliance consulting · 2024

#9

We need to take it step by step. tbh when we decide without measuring, we always end up in the same place.

EEmre G***Member
Job title
Sales Manager
Sector
Security services
Organization type
medium-sized business
Joined
Feb 2025
Message
68
#10

Let me summarize the topic, since several different answers were given. The biggest time-waster for us was not knowing who had the final say.

Forgotten test environments are more often the entry point than live systems. If I were you, I'd go this route.

RRecep S***ExpertCommunity member
Joined
Mar 2024
Message
243
#11

Same here.

JJülide S***Expert
Job title
Data Analyst
Sector
Retail
Organization type
early-stage startup
Joined
Feb 2022
Message
176
#12

Id appreciate it if you shared the outcome.

ZZübeyde S***MemberCommunity member
Joined
Jan 2026
Message
206
#13

Timely topic.

GGökhan C***MemberCommunity member
Joined
Apr 2024
Message
336
#14

I agree.

SSinan Z***Member
Job title
Studio Founder
Sector
Media and publishing
Organization type
early-stage startup
Joined
Feb 2023
Message
165
#15

I was thinking the same thing. Don't hesitate to ask; those who don't ask always pay more.

When you try to change everything at once nothing settles. If you have questions, write them; I'll answer as best I can.

RRabia G***VeteranCommunity member
Joined
Sep 2025
Message
75
#16

I'd appreciate it if you shared the outcome. Payment information changes are never verified through the channel they came from.

If you don't write this down from the start, it leads to arguments later.

OOkyanusMember
Job title
Embedded software
Organization type
regional distributor
Joined
Apr 2024
Message
96
#17

I have a question, don't want to go off-topic though. If you don't write this down from the start, it leads to arguments later.

Proven by experience.

YYağmur E***Member
Job title
General coordinator
Sector
Paper
Organization type
a company within a holding
Joined
Aug 2025
Message
197

Doki · SEO consulting · 2026

#18

Exactly like that. Trying to do this alone is the most expensive way.

NNeslihan T***Member
Job title
Intern
Sector
Automotive aftermarket
Organization type
early-stage startup
Joined
Mar 2024
Message
321
#19

Yes, that's exactly how it is with phishing. Start with a small trial; don't commit to everything at once.

OOkan E***Expert
Job title
QA Tester
Sector
Law
Organization type
early-stage startup
Joined
Feb 2022
Message
11
#20

My question might sound amateurish, sorry about that. tbh an untested backup is not a backup.

If you post the result here it will help others too.

Reply