Why Punishing Phishing Clicks Backfires
By Armando J. Perez-Carreno / Featuring Craig Taylor
I talked with Craig Taylor, co-founder of CyberHoot, about why punishing employees for phishing clicks backfires, and how to teach people to spot a phishing email instead.
Punishing employees who click on fake phishing emails doesn't make your company safer. Craig Taylor, co-founder of CyberHoot, has spent 30 years in cybersecurity, and he says the shame and punishment approach most of the industry uses makes people stop paying attention. What works is teaching people the warning signs and rewarding them when they get it right, because rewarded behaviors get repeated.
In this episode, I talked with Craig Taylor, co-founder of CyberHoot, a platform that teaches cyber literacy to companies and individuals. Craig got into security before the world wide web existed, back when email was plain text and you hit R to reply. His degree is in psychology, and that background shapes how CyberHoot teaches.
Here's how phishing training works at a lot of companies. IT sends a fake phishing email to see who clicks. Fail once and you meet with your boss. Fail twice and you meet with HR, and at some companies a third miss gets you fired. Craig pointed out that psychologists have known for about 75 years that punishment only holds a behavior down for a while. People learn to resent IT, and many stop engaging after their first mistake. He told me about someone with a PhD who failed two of these tests and gave up. Now that person forwards anything unfamiliar to IT and waits, which means real work sits in the inbox until someone answers.
CyberHoot turns that around. Their phishing exercise walks you through an email and asks questions as you go. Is the sender legitimate, or is the domain off by a letter or two? Is the message urgent, emotional, authoritative, or asking you to keep it quiet? Craig says those four signs show up in almost every phishing email. He's done dozens of forensic investigations, and he can't think of one person who clicked and didn't say afterward that they would have caught it if they'd stopped to think for a minute.
That habit of stopping matters more now because AI has made phishing emails much better. There are no spelling mistakes, the greeting uses your name, and the message may look like it came from your CEO telling you to skip the usual process just this once. A few years ago, spear phishing meant a hacker spent hours researching one person. Now attackers can do that research for everyone at a company at the same time.
It can happen to anyone. I told Craig about the day AWS pushed a billing bug and I got an alert saying I owed something like $108 million, right as I was walking into the airport for a 10-hour flight. The alert turned out to be real, but my first thought was that it was phishing, and in that state of mind it would have been easy to click and type in my credentials. Craig admitted he clicked a phishing link himself about seven or eight years ago. He'd just come back from two weeks of vacation and saw a fake LinkedIn recommendation from an old friend. What saved him was his password manager. It refused to fill in his login because the page was on a .it domain in Italy.
People sometimes tell Craig it's only their email, so there's nothing worth stealing. The problem is where your computer sits. It's connected to your company's network, shared drives, and accounts. Within seconds of getting into an inbox, attackers search for Social Security numbers, card numbers, and password reset emails, and then they use those resets to get into other accounts.
His practical advice starts with a password manager. He's looked at every way people manage passwords, and a password manager comes out ahead of all of them. Protect it with a long, unique password and multifactor authentication. Then turn on MFA for every account that matters, starting with email, and switch to passkeys wherever you can, since a stolen passkey won't work anywhere else. For business owners, he recommends paying for a company password manager. When someone leaves, their accounts can move to the person replacing them instead of being reset one at a time.
My takeaway is that security depends on people as much as software. You can't block every bad email, so you need a team that knows what to look for and feels comfortable asking when something seems off. As Craig put it, this isn't rocket science. If you want to try his approach yourself, CyberHoot is free for individuals at cyberhoot.com/individuals.