How does the Applicant handle repeat offenders/clickers in phishing simulations?
A small group of people click every time. What you do about that group is the difference between a simulation programme and a risk control.
What the carrier is actually asking
The carrier is asking whether repeated failure has consequences: additional training, manager involvement, tightened technical controls, or escalation. It is a question about whether the programme changes anything.
Why it is underwritten
Susceptibility concentrates. A small proportion of any workforce clicks repeatedly, and that group is where a real campaign will succeed. Carriers ask because a programme that measures without acting leaves the concentrated risk exactly where it was.
Where the answer lives in Microsoft 365, Entra ID, and Azure
This is a process question about your programme, so it is attested. Some of the technical escalations available are visible in the tenant.
| Platform | Where the setting lives | What has to be true |
|---|---|---|
| Simulation platform | Repeat-clicker identification and escalation workflow | A defined path, with training assignment and manager notification. Attested |
| Training platform | Completion tracking for remedial training | Assigned training is completed rather than assigned and forgotten |
| Microsoft 365 | Tightened protection for high-risk users | Stricter policy for identified users, such as more aggressive link handling or restricted attachment types |
| Entra ID | Conditional Access adjustments for high-risk populations | Shorter sign-in frequency or stronger factor requirements for the group most likely to be phished successfully |
| Programme records | Evidence that escalation happens | A record showing repeat clickers identified and acted on, rather than a policy describing what would happen |
Punitive approaches suppress reporting, which costs more than the clicks prevented. Applying stricter technical controls to the population that demonstrably needs them addresses the risk without teaching people to hide mistakes.
What a defensible yes requires
- Repeat failure is defined, so identification is automatic rather than anecdotal.
- Escalation includes both training and a technical adjustment.
- Managers are involved for persistent cases, with support rather than sanction as the framing.
- The path avoids penalties that would discourage reporting genuine incidents.
- Evidence exists that escalation actually occurred.
How this answer goes wrong
The policy describes escalation and nothing runs it. Repeat clickers are identified in a report that goes to a mailbox, no training is assigned, and the same names appear in the next quarter's report. The other failure is a punitive programme that makes people afraid to admit a real click, which delays every genuine incident.
Frequently asked
Should repeat clicking affect employment?
Almost never, and framing it that way damages your reporting culture. Carriers are looking for an escalation path, not a disciplinary one.
What technical escalations work?
Stricter link and attachment handling, shorter session lifetimes, stronger authentication factors, and removal of local administrator rights. All are targeted and none are punitive.
How do we define repeat?
Two or three failures within a rolling period is common. Define it so identification is automatic and consistent.
Does this apply to executives?
Especially, and it is where escalation is most often skipped. An executive who repeatedly clicks is the highest-value exposure in the organisation.
Related questions
Stop answering this from memory
Connect Microsoft 365, Entra ID, and Azure read-only. Insurance Posture reads the live configuration behind each application answer and shows you which ones you can prove before you sign.
Assess your posture