Back to Blog
    Gloved hand near laptop showing phishing email icon with hook and warning badge, dark server room background

    What to Do When an Employee Refuses a Phishing Test

    cybersecurity
    phishing
    security awareness
    business it
    employee training
    Author: Fix My PC Store Editorial TeamPublished: 10/9/2026Last Updated: 10/9/2026

    TL;DR: An employee refusing a phishing test is almost never about the test itself. It's usually a policy gap, a communication failure, or a trust problem. Fixing it means addressing all three, not just repeating the test.

    What Happened

    Phishing simulations, where IT or a security vendor sends fake phishing emails to staff and tracks who clicks, are a standard part of business cybersecurity programs. They're uncomfortable by design. The point is to find out who needs more training before a real attacker does.

    Sometimes an employee refuses to participate. That refusal can look a few different ways:

    • They forward the simulation email to IT before clicking, then object to being "tricked."
    • They flag it as harassment or a violation of trust.
    • They simply ignore the exercise and don't engage with follow-up training.
    • They escalate to HR or a manager, arguing the test was deceptive.

    None of these responses are irrational. They're signals. The question is what they're signaling.

    Why It Matters

    Phishing is consistently one of the top vectors for business breaches. The FBI's 2023 Internet Crime Report put phishing at the top of reported cybercrime categories by victim count. One employee who won't engage with security training is a genuine exposure.

    But the way you respond to refusal matters almost as much as the refusal itself. Punishing someone publicly for failing a test, or doubling down on "gotcha" simulations without context, makes the whole program adversarial. That damages the security culture you're trying to build.

    The goal of phishing testing is behavior change, not a compliance checkbox.

    Why Employees Refuse

    Understanding the reason behind the refusal shapes the right response. Common causes:

    Reason for Refusal What It Usually Means
    "You tricked me" objection No prior communication that simulations would occur
    Privacy or HR concern Employee feels monitored without consent
    Ignores follow-up training Disengagement, workload pressure, or unclear expectations
    Escalates to management No written policy backing the program

    Worried your business is one click from a breach? Get a security review

    Man in dark office sits at desk, hand on chin, staring skeptically at monitor showing an open envelope with warning icon
    Phishing simulations are designed to be uncomfortable — how you respond to employee pushback shapes your entire security culture.

    What We Don't Know Yet

    A few things vary by organization that will affect how you handle this:

    Whether a written policy covers phishing simulations. If your acceptable-use policy or security policy doesn't explicitly mention simulation testing, you're on shakier ground when an employee objects. Most employment attorneys recommend including it.

    Whether employees were told simulations would happen. There's a meaningful difference between "we run security awareness exercises" disclosed at onboarding versus completely unannounced tests with no context.

    Whether this is a one-time refusal or a pattern. One frustrated employee after a surprise simulation is different from a team that collectively resists. The latter is a management and culture issue that HR needs to be part of.

    Jurisdiction and employment law. In some states or for some roles, how monitoring and testing is handled has legal dimensions. That's outside IT's lane. If the refusal involves formal complaints, loop in HR and legal counsel early.

    What to Do About It

    Step 1: Don't escalate immediately. A conversation beats a write-up. Ask the employee directly what their concern is. Listen. You may learn something about how the program was communicated, or wasn't.

    Step 2: Check your policy documentation. Does your security policy explicitly authorize phishing simulations? If not, fix that before running another test. A managed IT partner can help you build policy documentation that holds up.

    Step 3: Communicate the program clearly to all staff. Employees should know that phishing simulations are part of your security program, even if they don't know when a specific test will run. Frame it as a shared benefit, not surveillance.

    Step 4: Separate the test from the consequences. Clicking a simulated phishing link should trigger training, not punishment. Make that explicit. Employees who feel punished for being human will resent the program and resist future participation.

    Step 5: Loop in HR if the refusal is formal. If an employee files a complaint or refuses a direct instruction to complete follow-up training, that's an HR and management issue, not an IT issue. Document your process and hand it off appropriately.

    Step 6: Revisit the simulation design. Some vendors run simulations that feel genuinely manipulative, mimicking HR emails about pay changes or IT alerts about account termination. Those approaches get results on click rates but damage trust. A more balanced approach uses realistic but lower-stakes lures.

    If you don't have a formal cybersecurity awareness program in place yet, or your current one isn't working, that's worth a real conversation. Fix My PC Store's business cybersecurity services cover security policy, staff training structure, and ongoing protection for South Florida businesses. You can also reach out directly at /contact to talk through where your program has gaps.

    Phishing simulations work when employees understand why they exist. The refusal is feedback. Use it.


    Worried your business is one click from a breach?

    Get a straight-talk security review from a local team that has cleaned up the aftermath more times than we'd like.

    Get a security review

    Frequently Asked Questions

    Can an employee be disciplined for refusing to complete phishing simulation training?
    It depends on your written policies. If your acceptable-use or security policy explicitly requires participation in security awareness training, refusal to complete follow-up training after a simulation could be a disciplinary matter. If no such policy exists, you're on much weaker ground. Get HR and legal counsel involved before taking formal action.
    Should employees be told in advance that phishing simulations will occur?
    Best practice is to disclose that simulations are part of your security program, without revealing the specific timing or format of individual tests. This satisfies most transparency concerns and reduces backlash, while still making the exercise realistic enough to be useful.
    What's the difference between a phishing simulation and real employee monitoring?
    A phishing simulation tests whether employees recognize and report suspicious emails. It measures behavior in a specific scenario. Broad employee monitoring, such as logging all email content or keystrokes, is a separate practice with different legal and policy considerations. Keeping these concepts distinct in your communications helps reduce employee suspicion about simulation programs.
    How often should businesses run phishing simulations?
    Most security frameworks recommend at least quarterly simulations, with monthly being common for higher-risk environments. Frequency matters less than consistency and follow-through. A simulation that leads to no training or feedback teaches employees nothing and wastes goodwill.

    Share this article