This simulation models a real corporate security-awareness program: a 3D office floor of 180 employees, each with a hidden phishing-susceptibility score, gets hit by periodic simulated phishing campaigns. Anyone who clicks the lure flashes and receives immediate just-in-time training that cuts their susceptibility; between campaigns that benefit decays back toward baseline along an exponential forgetting curve, exactly as the Ebbinghaus memory-decay research predicts. Tune campaign frequency, training strength and attacker sophistication to see why security teams run phishing simulations on a cadence rather than once — and watch the organization-wide click rate, cumulative incident count and weeks-elapsed clock track the program's real effectiveness live.