ForgeAwareness
YOYour Security Team · Content Library

Manager Toolkit for Repeat Phishing Clickers

Supportive coaching scripts, templates, and guides for managers coaching repeat phishing clickers.

Campaign Overview

Help managers at [Your Company] coach employees who repeatedly click phishing simulations into security advocates. This is a behavior change toolkit, not a punishment. The goal is supportive coaching that drives lasting improvement.

0
Posters
0
Videos
8
Emails
10
Slack/Teams
0
Lessons
0
Scenarios
10
Quiz Qs
5
Job Aids

Usage analytics

Placeholder
Assets viewed
Assets copied
Completion rate

Connect your analytics to track engagement across the campaign.

Campaign name options

  • Transform Clickers into Champions
  • The Phishing Coach Toolkit
  • Manager Coaching for Security Awareness
  • Build Secure Habits Through Coaching
  • From Clicks to Clicks No More

Recommended length: Immediate coaching upon click, with 30-day follow-up and ongoing support. Integrates with your phishing simulation program.

Weekly themes

  1. Week 1: First Conversation

    Warm, educational coaching for first clicks. Build psychological safety.

  2. Week 2: Repeat Click Coaching

    Escalate support and coaching for 2nd/3rd incidents. Add structure.

  3. Week 3: Credential Submission

    High-risk intervention for credential exposure. Immediate training.

  4. Week 4: Ongoing Support

    30-day follow-up, progress tracking, and positive reinforcement.

Target behaviors

  • Managers coach employees immediately after phishing clicks (within 48 hours).
  • Employees understand why phishing matters and what the red flags are.
  • Employees report suspicious emails to Security Team instead of clicking.
  • Managers track progress and celebrate improvement.
  • HR and security escalate only when coaching isn't working.
  • Coaching conversations are documented for compliance and improvement.

Success metrics

  • Manager adoption: % of managers trained and using the toolkit
  • Repeat click reduction: 40-60% decrease in repeated incidents per employee
  • Training completion: 90%+ of coached employees complete assigned training
  • Time to remediation: 50% faster from incident to completion
  • Reporting improvement: 2-3x increase in employees reporting phishing
  • Manager confidence: Pre/post confidence assessment (target 80%+ confident)

Launch checklist

  • Get HR and Legal review of the Security_Policy_Language document.
  • Customize escalation thresholds for your organization's risk profile.
  • Schedule manager training using the included 2-hour training agenda.
  • Distribute the Manager Toolkit Overview to all managers.
  • Distribute the Manager Quick Reference Card for manager desks.
  • Brief your executive sponsor on the coaching-focused approach.
  • Set up your incident tracking using the completion_tracking_template.
  • Brief your security team on when to escalate vs. when to let managers handle.
  • Customize emails and templates with company name and team contacts.
  • Measure baseline repeat-click rate so you can show improvement.