Certain individuals, despite working at the same organisation and having been exposed to the same training, are found through longitudinal phishing simulations to continuously click on, and fail to report, phishing emails. This study attempts to investigate the factors that contribute to phishing susceptibility and non-reporting within an organisation, including understanding the barriers to reporting. 14 participants were identified from one year of phishing simulation data and were selected based on either exhibiting ideal or non-ideal reporting behaviours. Participants performed an email identification task as well as a semi-structured follow-up interview. A grounded theory approach was leveraged to identify five key themes that may indicate phishing susceptibility: reportingawareness, technological capabilities, organisational factors, message processing, and cognitive factors. Findings indicate that employees who are on external contracts as well as have shorter tenures are likely to be more susceptible to phishing, primarily due to a lack of awareness of appropriate reporting processes. Further, participants were found to be unaware of methods on how to leverage message cues, such as the “link hover” function. This indicates the need for consistent education within an organisation pertaining to these topics.