phishsim

Security awareness

Turn a risky click into reflexive caution

Phishing targets people, not firewalls — so people need safe practice. A well-run phishing-simulation programme rehearses your team against realistic lures until spotting them becomes second nature.

  • Based on Verizon DBIR & APWG data
  • Ethical, evidence-based
  • Updated 2026

What is phishing simulation

A fire drill for your inbox

A phishing simulation is a safe, authorised fake phishing email sent to your own people to teach them to recognise the real thing.

A phishing simulation (or simulated phishing test) is a controlled exercise in which an organisation sends its own staff realistic — but harmless — phishing emails. Nobody is tricked into real harm: the goal is to practise, measure awareness, and teach at the moment someone clicks.

It works because phishing exploits human behaviour, and behaviour changes through repetition and feedback, not a one-off slideshow. A single test is a snapshot; a sustained programme builds a reflex.

Done well, it is positive and blame-free. Done badly — as a "gotcha" that shames people — it erodes trust and teaches staff to hide mistakes. This guide covers how to do it well.

Why simulate

What a simulation actually builds

Four things a phishing-simulation programme delivers that technical controls can’t.

  1. HUMAN

    Covers the human layer

    Filters stop most phishing, but some always gets through. Simulations train the last line of defence — the person deciding whether to click.

  2. PRACTICE

    Safe rehearsal

    People learn by doing. A simulation lets staff experience a realistic lure and make the mistake harmlessly, so the real one feels familiar.

  3. METRICS

    Measurable progress

    Click-rate and report-rate turn "awareness" into numbers you can track over time and show to leadership and auditors.

  4. CULTURE

    A reporting reflex

    The real win is staff who report suspicious email quickly. That turns every employee into a sensor and shrinks an attacker’s window.

Do it right

The mistakes that make simulations backfire

A badly run programme is worse than none — it damages trust and teaches people to hide clicks. Avoid these.

  • Worst

    Punishing people who click

    Naming, shaming or disciplining clickers kills the reporting culture you’re trying to build. People hide mistakes instead of flagging them.

    Do instead: Make it blame-free; reward reporting, coach clicking

  • Harmful

    Cruel "gotcha" lures

    Fake bonus or bereavement emails may boost click stats but destroy trust in the security team and the exercise.

    Do instead: Use realistic, fair scenarios — not emotional traps

  • Ineffective

    One-and-done testing

    A single annual test is a compliance tick, not training. Behaviour only shifts with sustained, spaced repetition.

    Do instead: Run a continuous programme, not a yearly event

  • Incomplete

    Only tracking click-rate

    Click-rate alone misses the point. A team that reports fast is safer than one that just clicks less.

    Do instead: Measure report-rate and reporting speed too

The simulation effect

Why one test isn’t enough

Behaviour change compounds. Drag through the rounds to see how a sustained programme lowers the projected click-rate over a year.

Projected click-rate

5%

After 12 months

Drag to see how repeated simulations change behaviour over time.

Run a programme with OffSeq

Illustrative figures based on published industry ranges — real results vary with your baseline, audience and programme quality. The shape, not the exact number, is the point: repetition compounds.

The numbers

Why the human layer matters

Phishing remains one of the most common and fastest-moving routes into an organisation.

68%
of breaches involved a non-malicious human element — the exact thing awareness training targets.
Source: Verizon DBIR, 2024
< 60 sec
median time for a user to click a phishing link and then submit their data after opening it.
Source: Verizon DBIR, 2024
~5M
phishing attacks were recorded in 2023 — among the highest totals APWG has ever observed.
Source: APWG, 2023
$4.88M
was the average cost of a data breach in 2024 — the payoff for reducing successful phishing is large.
Source: IBM Cost of a Data Breach, 2024

Each figure links to its primary source. Numbers are approximate and updated as new reports are published.

For security teams

Awareness training is now a governance requirement

Under the EU NIS2 Directive, cyber-hygiene and staff awareness aren’t optional extras — they’re part of the security measures management is accountable for.

The EU NIS2 Directive requires essential and important entities to adopt basic cyber-hygiene practices and security-awareness training as part of their risk-management measures, with management bodies accountable for oversight.
NIS2 Directive (EU) 2022/2555 · EUR-Lex
  • Baseline, then improve

    Start with a fair baseline simulation to measure where you are, then run a continuous programme and watch the trend — not a single score.

  • Blame-free by design

    Coach people who click and celebrate people who report. A safe culture is what produces fast reporting when a real attack lands.

  • Realistic, relevant lures

    Effective scenarios mirror the phishing your people actually face — supplier invoices, HR notices, MFA prompts — not unfair emotional traps.

  • Measure what matters

    Track click-rate, report-rate and reporting speed together. A fast-reporting team shrinks an attacker’s window even when someone clicks.

Frequently asked questions

Short, clear answers

What is a phishing simulation?

A phishing simulation is a controlled, authorised exercise where an organisation sends its own staff realistic but harmless fake phishing emails, to measure awareness and teach people to recognise real attacks. See how to run one →

Are phishing simulations effective?

Yes, when run as a sustained programme rather than a one-off. Repetition and in-the-moment feedback lower click-rates and — more importantly — build a fast reporting reflex over time. A single annual test does little.

Are phishing simulations ethical?

They can be, and should be. Ethical programmes are blame-free, use realistic rather than cruel lures, coach people who click, and never punish or shame. Read the ethics guide →

What should we measure?

Track click-rate, but also report-rate and reporting speed. A team that reports suspicious email quickly is safer than one that merely clicks less, because fast reporting shrinks the attacker’s window.

How often should we run simulations?

Regularly — monthly or quarterly is common — rather than once a year. Spaced repetition is what changes behaviour. Vary the scenarios so people learn the patterns, not one specific email.

Should employees know simulations happen?

Announce the programme in general (that simulations occur and why), without warning people of specific campaigns. Transparency about the programme builds trust; surprise on the individual email preserves realism.

Does NIS2 require security-awareness training?

The EU NIS2 Directive requires in-scope organisations to include cyber-hygiene and awareness training in their risk-management measures, with management accountable. Phishing simulation is a common, measurable way to meet that.

Do simulations replace technical email security?

No — they complement it. Filtering and authentication (SPF, DKIM, DMARC, MFA) stop most phishing; simulations train people for what gets through. You need both layers.