The sysadmin who called phishing 'free training' changed how I run drills
I was setting up a simulated phishing campaign at a small credit union in Des Moines and one older sysadmin, maybe 58, refused to click the test link. When I asked why, he said "every click you track is just someone learning the hard way, and that's worth more than any report you generate." He then showed me his own folder of real attack emails he'd collected since 2016, each one annotated with what the user did wrong and how he explained it to them. So which side are you on, do you punish clicks to build fear or use them as teachable moments without any blame attached? Has anyone else run into a veteran who treats phishing tests completely differently than the compliance folks expect?