It's easy to frame repeated phishing clicks as a people problem: someone wasn't paying attention, someone didn't follow the training. In practice, that framing gets the causality backwards more often than not.
Security awareness training that consists of an annual slide deck and a quiz was never designed to hold up against a well-crafted, urgent, personalised phishing email arriving on a busy Tuesday. Blaming the employee for a training gap doesn't close the gap.
The more productive question isn't who clicked: it's why the training didn't prepare them for that moment, and what would. That's a design problem, and it has a design solution.
See how goDeep turns thinking like this into training your team will actually remember.