The strongest programmes use both, but they do not treat them as substitutes. Posters, videos, and newsletters reinforce key messages and keep cyber risk visible. Simulated phishing and computer-based training build measurable skill and behaviour change. Organisations should reserve passive content for reinforcement, then pair it with repeatable practice that exposes susceptibility, measures progress, and improves retention over time.
Why the best programmes combine awareness with practice
Passive awareness materials and hands-on phishing practice solve different problems. Posters, videos, and newsletters work best as reinforcement: they keep risk visible, anchor terminology, and prime employees to notice suspicious messages. Simulated phishing and short computer-based exercises test whether people can actually recognise cues, slow down, and respond correctly under pressure.
The mistake is treating awareness as a substitute for behaviour change. A workforce can remember the message without showing the skill. Training improves when teams use passive content to set the context, then use practice to confirm whether the lesson survives real inbox noise, competing priorities, and repeated exposure.
How the two formats reinforce each other
Awareness content is strongest when it creates familiarity before the test. If employees have recently seen examples of suspicious links, impersonation tactics, or reporting steps, they are more likely to recognise those patterns during a simulation. Practice then turns recognition into habit by forcing a decision: report, delete, verify, or proceed.
That sequence matters because phishing resistance is not just knowledge, it is repeated judgment. For that reason, organisations should reserve passive materials for broad reinforcement and use practice for the moments that reveal whether the message has become operational behaviour. When those moments are well designed, they also show where people need coaching rather than generic reminders.
Well-run programmes also use the two formats to support different audiences. Some employees need simple reminders and low-friction reinforcement; others need scenario-specific practice because they handle payment requests, HR changes, executive communications, or vendor workflows. The training mix should reflect exposure and role, not a one-size-fits-all calendar.
What good measurement looks like in a phishing programme
Hands-on exercises are valuable because they create measurable signals. Teams can track click rates, report rates, time-to-report, repeat susceptibility, and whether people complete follow-up learning after an error. Those measures are more useful than attendance alone because they show whether behaviour is changing, not just whether a message was delivered.
Passive content still has a role in measurement, but mainly as a support signal. If simulation results improve after a reinforcement campaign, that suggests the reminder worked. If results do not move, the issue is usually not the existence of awareness content, but the design of the practice, the realism of the scenarios, or the absence of timely feedback after mistakes.
For teams that want a structured practice baseline, the broader training and response ecosystem described in SANS Security Resources is a useful reference point for operational follow-through after user action. On the identity side, phishing-resistant authentication guidance in NIST SP 800-63 Digital Identity Guidelines helps teams separate user education from the stronger control that reduces the impact of stolen credentials.
Risk and Threat Considerations
Phishing programmes fail when they overinvest in passive awareness and underinvest in realistic practice. The result is a workforce that can recognise familiar advice but still falls for urgency, impersonation, or credential-harvesting prompts when the message is timed to stress, distraction, or routine approval behaviour.
Failure mechanism: Passive material creates recognition without tested response, so employees know the warning signs in theory but have never rehearsed the decision path under inbox pressure. Attackers exploit that gap by using believable lures that bypass memory and trigger fast, unexamined clicks or credential entry.
Impact: The organisation gets a false sense of readiness, while actual exposure remains tied to user behaviour, reporting speed, and the ability to stop a bad interaction before credentials or sessions are compromised.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | AT-2 — Security Awareness Training | Phishing training and awareness are core awareness-and-practice controls. |
| AT-3 — Role-Based Security Training | Different job roles face different phishing exposure and response needs. | |
| AU-6 — Audit Review, Analysis, and Reporting | Measuring reports and response quality requires review of training and incident data. | |
| Recommendation — Include phishing simulations and recurring awareness exercises in the security training program. Tailor phishing training scenarios to the duties and exposure of each role. Review phishing report and simulation metrics to identify improvement gaps. | ||
| NIST CSF 2.0 | PR.AT-01 — Knowledge and Skills Are Identified and Trained | This subject is fundamentally about building user knowledge and skills against phishing. |
| DE.CM-08 — Vulnerabilities Are Managed | Simulation results expose behavioral weaknesses that should be remediated over time. | |
| Recommendation — Provide targeted phishing training that builds user knowledge and skill. Use phishing exercise results to drive remediation of recurring user weaknesses. | ||
Practitioner Guidance
What to prioritise: Use passive content to support repetition and vocabulary, but make practice the primary proof of effectiveness. If you cannot observe improvement in reporting, click reduction, or recovery speed, the programme is not yet training behaviour.
Decision rule: If the issue is general awareness, reinforcement content is fine; if the issue is susceptibility, response quality, or repeat errors, move immediately to simulations, coaching, and follow-up scenarios that match real job tasks.
What to measure: Track both exposure and response, especially report rate and time-to-report, because those tell you whether employees are merely informed or actually intervention-ready.
Practitioner takeaway: The best balance is not “more awareness” versus “more simulation”, it is passive reinforcement for memory and repeated practice for behaviour, with the latter carrying the real assurance value.
Related resources from NHI Mgmt Group
- What do security teams get wrong about phishing awareness training?
- How should security teams reduce phishing risk without relying only on awareness training?
- How should security teams use nudges in phishing and awareness programmes?
- How should security teams run vishing awareness training so it changes employee behavior instead of just improving completion rates?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 27, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org