Back to the glossary
    Human risk & behaviorCybersecurity glossary

    Retest

    A new simulation of the same attack category, weeks after a failure and with a different template, to verify the person actually changed their behavior.

    Full definition

    A retest is a new phishing simulation sent weeks after a person fell for a simulated attack and completed their training, using the same category and sophistication as the original lure but a different template. Its purpose is to verify that the person learned the lesson, not that they memorized an email.

    It is the direct answer to the central problem of awareness: peer-reviewed evidence shows that completing courses does not by itself predict fewer real failures. What demonstrates change is testing the behavior again under equivalent conditions. Passing the retest is the proof; failing it means the risk is still active and should be reflected in the person's profile.

    In a mature program, the retest closes the cycle of simulation, training and validation, turning the question of whether training worked into a verifiable data point instead of a hope.

    Related reading on the blogGo deeper into this topic

    Related terms

    From definition to data: measure your company's human risk

    Fensivo detects leaked credentials, simulates real attacks and validates with retests that behavior changed.