Skip to main content

Human risk management

Phishing simulation and security awareness training that changes behavior

In short

How a 12-month phishing simulation and awareness program runs quarter by quarter, the lures aimed at Indonesian staff, and the metrics that prove it works.

Human risk and security awareness

Most successful attacks do not start with a clever exploit. They start with a person: a convincing email, a fake login page, a message that looks like it came from a manager or a bank. The Verizon 2025 Data Breach Investigations Report found a human element in roughly 60 percent of breaches, and the 2024 edition measured how fast the moment passes: a median of 21 seconds to click a phishing link and another 28 seconds to hand over data. Under a minute, end to end. You cannot patch people the way you patch a server, but you can change how they react inside that minute. The catch is that the way most companies try, a slide deck once a year, does almost nothing.

Why one-off training does not stick

People forget. A single session in January is a distant memory by March, and the lures that fooled nobody last year have already been rewritten. Worse, a one-off has no feedback loop: nobody finds out whether the training actually changed what people do when a real email lands. Behavior moves when three things are present: repetition, realistic practice, and progress people can see.

What an effective program looks like

A working program is a loop, not an event. You establish a baseline, train against the gaps, simulate real attacks, measure what changed, and coach the people and teams who need it, then go around again.

BaselineTrainSimulateMeasureCoach

Each turn of the loop makes the next simulation a little harder and the click rate a little lower. The goal is not a perfect score on a quiz. It is a workforce that pauses on the right emails and reports them quickly.

How a 12-month program runs, quarter by quarter

The details flex to each organization, but a full-year program has a recognizable shape.

Quarter 1: set the baseline

An unannounced simulation before any training, so the click rate is honest. Then the first short modules, and a clear message from management that nobody is punished for clicking.

Quarter 2: build the habit

Campaigns roughly monthly, each slightly harder. The report button is introduced, reporting is praised publicly, and departments with weak numbers get targeted follow-up.

Quarter 3: raise the pressure

Role-specific lures: finance sees invoice fraud, HR sees loaded attachments, executives see targeted approaches. Repeat clickers get short one-on-one coaching, not a warning letter.

Quarter 4: prove it and reset

A year-over-year report for the board: click rate, report rate, and time to report by department. Targets are set for the next cycle, and the loop starts again, harder.

Lures that work on Indonesian staff

Generic templates about parcels from couriers nobody uses teach nothing. The simulations that change behavior mirror what actually lands in Indonesian inboxes and chat apps. A few patterns we model, described in outline only: a WhatsApp message carrying an APK file dressed up as a wedding invitation or a delivery notice, the pattern behind repeated waves of Android banking fraud here. A fake invoice or purchase order from a known supplier, identical to the real one except for the bank account number. An urgent OTP or account-verification request impersonating a bank or marketplace, engineered to make the target act before thinking. A notice styled as a regulator or tax-office letter, timed to reporting season.

The simulations copy the pressure and the shape of these lures, never the payload. There is no malware involved, and the landing pages record only the click and the report. The point is a safe rehearsal of the exact moment that matters: the few seconds between opening a message and deciding what to do with it.

The metrics that matter

Three numbers tell you whether the program is working. The click rate is the obvious one: the share of recipients who clicked. It should fall over the year, and across our 12-month programs we target a 60 to 70 percent drop from baseline. But click rate alone can flatter you, because it also falls when lures get easier or when people simply stop reading email.

The report rate is the better long-term signal: the share of recipients who actively reported the message as suspicious. A rising report rate means people are not just avoiding the trap but warning you about it, and a single early report can burn a campaign that would otherwise have caught fifty colleagues.

Time to report decides how useful those reports are. If the first report reaches the security team three minutes after a campaign lands, the message can be pulled from every mailbox before most people open it. Three hours later, the damage is done. This is the number that connects awareness training to actual incident response.

60-70%

lower phishing click rate over a 12-month program

28

training modules natively in Bahasa Indonesia

~3 mo

to measurable baseline improvement

Claro, the platform we run it on

We run this program on Claro, our own platform built for Indonesian enterprises. The phishing simulations copy tactics actually used against organizations here, training is delivered in Bahasa Indonesia, and every click, report, and lesson feeds a risk score you can see by department.

Bahasa Indonesia modulesLocal-tactic simulationsDepartment risk scoresBoard-ready reportsRepeating campaigns

How this feeds human risk management

Simulation results are an input, not the end product. Every click, report, and completed lesson feeds a per-department risk score, and that score drives decisions beyond training: which teams get stricter email controls, who gets phishing-resistant MFA first, and where a business email compromise attempt is most likely to land. Reported messages also become a live detection signal. When an employee reports a real phish, our managed SOC treats it as telemetry and hunts for the same message across the rest of the company.

That is the difference between awareness training as a compliance checkbox and awareness training as part of human risk management. The first produces certificates. The second produces a measurable, sustained drop in the risk your people carry.

If you want to see what a program would look like for your workforce, that is the first conversation to have.

References

  1. 1.Verizon. 2025 Data Breach Investigations Report. Verizon Business, 2025.
  2. 2.Verizon. 2024 Data Breach Investigations Report. Verizon Business, 2024.

Reviewed by Mirna Indriasari, Security Program Manager

Frequently asked questions

Yes, when it is continuous rather than a one-off. A program that combines regular phishing simulations with short, relevant training changes how people react over time. Across our 12-month programs we target a 60 to 70 percent drop in the phishing click rate.

Related

Ready to strengthen your security posture?

Talk to our Jakarta-based team about your requirements.

Jakarta-based team. We reply within one business day.