Phishing simulations are cruel and they don't work. They are weak administrative controls that IT should replace with strong technical controls, namely FIDO authentication. Stop blaming users for dangerous software products and unsafe configurations.

https://www.wsj.com/tech/cybersecurity/no-you-arent-getting-a-bonus-your-company-is-just-testing-you-2155c3c?st=bozizyn3vya2fp8&reflink=desktopwebshare_permalink

No, You Aren’t Getting a Bonus. Your Company Is Just Testing You.

Companies are getting creative with phishing tests. Employees are getting annoyed.

WSJ
@boblord I'm not sure they are cruel but this one is. If you are going to throw out the bonus phishing simulation it had better be preceded by a bunch of other more gentle simulations, training and positive reinforcements. Ultimately social engineering works and attackers will keep using it it in some form. I think it is ridiculous for companies to punish users for clicking on a phishing simulation. That will never help your users come forward when they click on a real message. I had to learn that the hard way when I first got into this field. Something that seemed so obvious to me in retrospect was not to an employee just trying to do their job.