Most security awareness training gets treated like a compliance chore: an annual video, a quiz nobody remembers, a checkbox for an auditor. That version of training doesn’t change behavior, and behavior is the entire point. Here’s what actually moves the needle.

Key Takeaways

  • AI-written phishing emails now get a 54% click-through rate, compared to 12% for old-fashioned scam emails — a 4.5x jump in effectiveness.
  • One annual training video changes almost nothing. Ongoing, realistic simulation does.
  • The goal isn’t zero clicks forever — it’s a team that reports suspicious emails instead of hiding a mistake.
  • Managed SAT is one of three layers in Humacentric Guardian, alongside Managed EDR and ITDR.

Why Phishing Got Harder to Spot

The old advice — watch for typos, bad grammar, generic greetings — assumed attackers were writing quickly and clumsily. AI-generated phishing removed that tell almost entirely. Recent research from CrowdStrike’s 2025 Global Threat Report found that AI-written phishing emails achieved a 54% click-through rate, versus 12% for human-written, old-style scams — more than four times as effective. Your employees aren’t getting careless. The emails are getting better.

What Doesn’t Work: The Annual Video

A once-a-year training video satisfies a compliance requirement and does almost nothing for actual behavior change. People forget it within weeks, and it does nothing to prepare someone for the specific, current tactics being used against businesses like yours right now. If your training program consists of one video and a quiz, you don’t have a training program — you have documentation.

What Actually Works

  • Realistic, ongoing phishing simulations — not a single test, but a continuous, varied program that reflects current tactics
  • Short, frequent lessons instead of one long annual session — five minutes a month beats fifty minutes once a year
  • Immediate, specific feedback when someone clicks a simulated phishing email, delivered as coaching, not punishment
  • Progress tracking so you can see whether click rates are actually improving over time, by person and company-wide

The Real Goal Isn’t Zero Clicks

No training program gets a large team to zero clicks forever — a good enough fake will eventually fool almost anyone on a bad day. The actual goal is building a culture where the person who clicks reports it immediately instead of quietly hoping nothing happens. A fast report can mean the difference between an isolated incident and a full breach. That culture only comes from training that treats mistakes as normal and reportable, not as something to hide.

Compliance and Cyber Insurance Are Catching Up to This

Documented, ongoing security awareness training is increasingly a stated requirement for cyber insurance coverage, not an optional extra. Insurers want to see records of training completion and phishing simulation results, not just a policy statement that training “occurs.” A program built for actual behavior change happens to also produce exactly the documentation an underwriter or auditor asks for.

FAQ

Will this feel like a lot of extra work for our team?

Well-designed SAT is intentionally lightweight — short modules, occasional simulated emails, a few minutes a month. The goal is habit-building, not a time-consuming program.

What happens when someone clicks a simulated phishing email?

They get immediate, specific feedback on what gave it away, plus optional short remedial training — never public callouts or punishment.

Is SAT sold on its own?

It’s available as an add-on to Guardian Essentials, and included by default in Guardian Complete. See the full Guardian stack.

Book a free risk assessment and we’ll show you what a realistic phishing simulation looks like before you commit to anything.