Of all the behaviors an HRM program can cultivate, getting employees to actively report suspicious emails and texts may be the single most impactful. Clicking "report phishing" instead of "delete" doesn't just protect that individual; it removes a live threat from the environment and gives your security team the signal they need to act before anyone else in the organization is targeted.
The math matters here. A phishing campaign that reaches 500 employees but gets reported by the first person to receive it can be neutralized in minutes. The same campaign, silently deleted or ignored, may linger until someone less vigilant encounters it days later. Fast, consistent reporting is one of the highest-leverage behaviors in your entire security posture.
Yet most organizations dramatically underinvest in building this habit. Employees aren't sure what counts as suspicious, they don't know where or how to report it, they worry about wasting IT's time, or they simply assume someone else will handle it. HRM programs need to directly address each of these barriers:
Make reporting effortless - A one-click report button in the email client removes friction entirely. The lower the barrier, the higher the uptake.
Define what "suspicious" looks like - Training should give employees a practical mental model such as unusual sender addresses, unexpected urgency, requests for credentials or payments, mismatched URLs to give them the confidence to flag something rather than second-guess themselves.
Acknowledge every report - Even if a flagged email turns out to be legitimate, the employee who reported it did the right thing. Automated confirmation messages ("Thanks, we've reviewed this and it's safe") reinforce the behavior without burdening the security team.
Celebrate reporting, not just avoidance - Click rates get tracked; reporting rates should too. An employee who reports five suspicious emails in a quarter is actively protecting the organization and deserves recognition, not silence.
The goal is to shift the employee's mental model from passive recipient to active defender. When reporting becomes habitual, something people do automatically, your human layer becomes a detection system, not just a vulnerability. That's a fundamentally different security posture, and it's only achievable through deliberate HRM program design.