
What to Do When an Employee Refuses a Phishing Test
TL;DR: An employee refusing a phishing test is almost never about the test itself. It's usually a policy gap, a communication failure, or a trust problem. Fixing it means addressing all three, not just repeating the test.
What Happened
Phishing simulations, where IT or a security vendor sends fake phishing emails to staff and tracks who clicks, are a standard part of business cybersecurity programs. They're uncomfortable by design. The point is to find out who needs more training before a real attacker does.
Sometimes an employee refuses to participate. That refusal can look a few different ways:
- They forward the simulation email to IT before clicking, then object to being "tricked."
- They flag it as harassment or a violation of trust.
- They simply ignore the exercise and don't engage with follow-up training.
- They escalate to HR or a manager, arguing the test was deceptive.
None of these responses are irrational. They're signals. The question is what they're signaling.
Why It Matters
Phishing is consistently one of the top vectors for business breaches. The FBI's 2023 Internet Crime Report put phishing at the top of reported cybercrime categories by victim count. One employee who won't engage with security training is a genuine exposure.
But the way you respond to refusal matters almost as much as the refusal itself. Punishing someone publicly for failing a test, or doubling down on "gotcha" simulations without context, makes the whole program adversarial. That damages the security culture you're trying to build.
The goal of phishing testing is behavior change, not a compliance checkbox.
Why Employees Refuse
Understanding the reason behind the refusal shapes the right response. Common causes:
| Reason for Refusal | What It Usually Means |
|---|---|
| "You tricked me" objection | No prior communication that simulations would occur |
| Privacy or HR concern | Employee feels monitored without consent |
| Ignores follow-up training | Disengagement, workload pressure, or unclear expectations |
| Escalates to management | No written policy backing the program |
Worried your business is one click from a breach? Get a security review
What We Don't Know Yet
A few things vary by organization that will affect how you handle this:
Whether a written policy covers phishing simulations. If your acceptable-use policy or security policy doesn't explicitly mention simulation testing, you're on shakier ground when an employee objects. Most employment attorneys recommend including it.
Whether employees were told simulations would happen. There's a meaningful difference between "we run security awareness exercises" disclosed at onboarding versus completely unannounced tests with no context.
Whether this is a one-time refusal or a pattern. One frustrated employee after a surprise simulation is different from a team that collectively resists. The latter is a management and culture issue that HR needs to be part of.
Jurisdiction and employment law. In some states or for some roles, how monitoring and testing is handled has legal dimensions. That's outside IT's lane. If the refusal involves formal complaints, loop in HR and legal counsel early.
What to Do About It
Step 1: Don't escalate immediately. A conversation beats a write-up. Ask the employee directly what their concern is. Listen. You may learn something about how the program was communicated, or wasn't.
Step 2: Check your policy documentation. Does your security policy explicitly authorize phishing simulations? If not, fix that before running another test. A managed IT partner can help you build policy documentation that holds up.
Step 3: Communicate the program clearly to all staff. Employees should know that phishing simulations are part of your security program, even if they don't know when a specific test will run. Frame it as a shared benefit, not surveillance.
Step 4: Separate the test from the consequences. Clicking a simulated phishing link should trigger training, not punishment. Make that explicit. Employees who feel punished for being human will resent the program and resist future participation.
Step 5: Loop in HR if the refusal is formal. If an employee files a complaint or refuses a direct instruction to complete follow-up training, that's an HR and management issue, not an IT issue. Document your process and hand it off appropriately.
Step 6: Revisit the simulation design. Some vendors run simulations that feel genuinely manipulative, mimicking HR emails about pay changes or IT alerts about account termination. Those approaches get results on click rates but damage trust. A more balanced approach uses realistic but lower-stakes lures.
If you don't have a formal cybersecurity awareness program in place yet, or your current one isn't working, that's worth a real conversation. Fix My PC Store's business cybersecurity services cover security policy, staff training structure, and ongoing protection for South Florida businesses. You can also reach out directly at /contact to talk through where your program has gaps.
Phishing simulations work when employees understand why they exist. The refusal is feedback. Use it.
Worried your business is one click from a breach?
Get a straight-talk security review from a local team that has cleaned up the aftermath more times than we'd like.



