Doppel Email Security is now generally available
The agentic email security solution that empowers you to fight back against social engineering attacks. Detection isn't enough. Disruption is the difference.
See why artificially low click rates in security awareness training create dangerous overconfidence and expose enterprises to AI vibe-phishing attacks.

Every quarter, security awareness leads present executive slide decks featuring a clean, satisfying downward slope: employee simulation click rates dropping to 2%, 1%, or even near 0%.
To CISOs, board members, and compliance auditors, this metric looks like victory. It suggests an attentive workforce, a mature security culture, and a hardened human perimeter.
In reality, these artificially low click rates often represent a dangerous operational illusion: the "false negative" psychological trap.
When security awareness training (SAT) platforms rely on generic, easily spotted email templates (complete with obvious typos, mismatched domain extensions, or clumsy "urgent invoice" tropes), they’re not training employees to resist actual adversaries. They’re training employees to spot bad fake emails.
When employees routinely pass these easy tests, they develop a dangerous sense of security. They begin to believe that any message lacking obvious compliance-testing flags is safe. This cognitive bias leaves them exposed to modern, hyper-personalized, multi-channel attacks engineered by adversaries using AI-native deception.
Read on to learn about the mechanics of the false negative trap, explore how vibe phishing bypasses traditional human awareness, and see how security leaders can transition from vanity compliance metrics to threat-informed human resilience.
Enterprise security programs have spent years attempting to quantify human risk (opens in new tab) using a single, flawed metric: the simulation click rate. Legacy vendors built business models around driving this number as close to zero as possible to satisfy SOC 2, ISO 27001, and PCI-DSS audit checkmarks.
To deliver low click rates, legacy platforms provide static, out-of-date template libraries. The resulting dynamic creates a feedback loop that actively degrades enterprise defense:
Identity-related initial access vectors, including phishing, credential abuse, and pretexting, continue to drive over 30% of enterprise breaches (opens in new tab). Meanwhile, median employees remain significantly more susceptible to multi-channel or realistic lures than standard inbox tests suggest.
When a security team optimizes for vanity click rates, they’re burying risk, not reducing it.
While traditional SAT platforms continue testing employees on 2015-era email templates, adversary tactics have evolved dramatically. Generative AI (opens in new tab) has dropped the cost of executing personalized social engineering attacks by 95% while increasing volume by more than 1,000%.
The current frontier of social engineering is vibe phishing (opens in new tab): hyper-personalized, context-aware campaigns built using AI agents that evaluate a target’s digital footprint, corporate hierarchy, and communication style.

Modern threat actors don’t stay within the inbox. A typical campaign might begin with a LinkedIn connection request, escalate to a Microsoft Teams or Zoom message, and follow up with a deepfake voice call or an SMS lure (smishing).
Legacy SAT tools test only the inbox, leaving 41% (opens in new tab) of modern non-email social engineering vectors completely unmonitored.
Adversaries use autonomous agents to scrape corporate filings, recent press releases, and executive social profiles. Rather than sending a generic "gift card offer," a vibe-phishing attack mimics an active vendor invoice update or an urgent request from the IT helpdesk during a system migration.
Traditional simulations expect a single click on a link. Modern AI attackers engage in back-and-forth dialogue. They build rapport, answer employee questions, and provide realistic context over multiple exchanges before introducing a malicious payload or credential harvest link.
When an employee conditioned by easy SAT tests encounters an AI-generated vibe-phishing attempt, their trained phishing filter fails. The message feels right. It has the right tone, context, and visual presentation. T
The false sense of confidence built by passing low-grade simulations leads directly to authorization of wire transfers, granting of OAuth permissions, or disclosure of login credentials.
To break out of the false negative trap, security leaders must retire click rates as a primary measure of human risk (opens in new tab). A low click rate on an easy test provides zero mathematical proof of security posture.
Transitioning from passive compliance to active resilience requires four operational shifts.
Testing shouldn’t be disconnected from the actual threat environment. If your digital risk protection (DRP) or threat intelligence tools detect an active executive impersonation campaign or a lookalike domain registered outside your perimeter on Monday, that exact scenario should inform employee simulations by Tuesday (opens in new tab).
Testing employees against active adversary tactics, techniques, and procedures (TTPs) ensures training reflects real-world exposure.
Real attacks are interactive. Effective simulations should evaluate how employees respond to multi-channel, multi-step pressure:
Testing conversational interaction reveals structural gaps in business processes that single-click tests completely miss.
Not every click carries the same risk profile. An entry-level employee clicking a simulated link carries a vastly different risk profile than a system administrator or finance manager granting access to internal codebases or wire transfer portals.
Risk modeling must evaluate user privilege, access levels, and historical susceptibility rather than applying uniform, low-grade tests across the entire organization.
Instead of penalizing clicks on complex lures, organizations should measure time-to-report (opens in new tab). When employees report suspicious communications directly from their inbox or messaging tools, they act as active sensors for the security operations center (SOC). High reporting rates and fast triage times provide a more accurate indicator of security culture than artificially suppressed click metrics.
The goal of human risk management is to ensure that when a sophisticated, AI-driven attack reaches your workforce, your people and technical controls respond effectively.
By combining real-time external threat intelligence, multi-channel simulations across email, voice, and messaging, and dynamic risk modeling, security teams can eliminate the false negative trap and build verifiable human resilience.
Request a demo with Doppel (opens in new tab) to see how agentic AI and threat graph intelligence can transform your human risk management strategy.