Instead of making it generic for each failed phishing test, one thing that would be nice would be to customize it to each phishing template. The recovery training would go into each template and call out what was wrong and how a user could've identified how it was fake.