Security awareness
Turn a risky click into reflexive caution
Phishing targets people, not firewalls — so people need safe practice. A well-run phishing-simulation programme rehearses your team against realistic lures until spotting them becomes second nature.
- Based on Verizon DBIR & APWG data
- Ethical, evidence-based
- Updated 2026
What is phishing simulation
A fire drill for your inbox
A phishing simulation is a safe, authorised fake phishing email sent to your own people to teach them to recognise the real thing.
A phishing simulation (or simulated phishing test) is a controlled exercise in which an organisation sends its own staff realistic — but harmless — phishing emails. Nobody is tricked into real harm: the goal is to practise, measure awareness, and teach at the moment someone clicks.
It works because phishing exploits human behaviour, and behaviour changes through repetition and feedback, not a one-off slideshow. A single test is a snapshot; a sustained programme builds a reflex.
Done well, it is positive and blame-free. Done badly — as a "gotcha" that shames people — it erodes trust and teaches staff to hide mistakes. This guide covers how to do it well.
Why simulate
What a simulation actually builds
Four things a phishing-simulation programme delivers that technical controls can’t.
- HUMAN
Covers the human layer
Filters stop most phishing, but some always gets through. Simulations train the last line of defence — the person deciding whether to click.
- PRACTICE
Safe rehearsal
People learn by doing. A simulation lets staff experience a realistic lure and make the mistake harmlessly, so the real one feels familiar.
- METRICS
Measurable progress
Click-rate and report-rate turn "awareness" into numbers you can track over time and show to leadership and auditors.
- CULTURE
A reporting reflex
The real win is staff who report suspicious email quickly. That turns every employee into a sensor and shrinks an attacker’s window.
Do it right
The mistakes that make simulations backfire
A badly run programme is worse than none — it damages trust and teaches people to hide clicks. Avoid these.
- Worst
Punishing people who click
Naming, shaming or disciplining clickers kills the reporting culture you’re trying to build. People hide mistakes instead of flagging them.
Do instead: Make it blame-free; reward reporting, coach clicking
- Harmful
Cruel "gotcha" lures
Fake bonus or bereavement emails may boost click stats but destroy trust in the security team and the exercise.
Do instead: Use realistic, fair scenarios — not emotional traps
- Ineffective
One-and-done testing
A single annual test is a compliance tick, not training. Behaviour only shifts with sustained, spaced repetition.
Do instead: Run a continuous programme, not a yearly event
- Incomplete
Only tracking click-rate
Click-rate alone misses the point. A team that reports fast is safer than one that just clicks less.
Do instead: Measure report-rate and reporting speed too
The simulation effect
Why one test isn’t enough
Behaviour change compounds. Drag through the rounds to see how a sustained programme lowers the projected click-rate over a year.
Projected click-rate
5%
After 12 months
Drag to see how repeated simulations change behaviour over time.
Illustrative figures based on published industry ranges — real results vary with your baseline, audience and programme quality. The shape, not the exact number, is the point: repetition compounds.
The numbers
Why the human layer matters
Phishing remains one of the most common and fastest-moving routes into an organisation.
Each figure links to its primary source. Numbers are approximate and updated as new reports are published.
For security teams
Awareness training is now a governance requirement
Under the EU NIS2 Directive, cyber-hygiene and staff awareness aren’t optional extras — they’re part of the security measures management is accountable for.
The EU NIS2 Directive requires essential and important entities to adopt basic cyber-hygiene practices and security-awareness training as part of their risk-management measures, with management bodies accountable for oversight.
-
Baseline, then improve
Start with a fair baseline simulation to measure where you are, then run a continuous programme and watch the trend — not a single score.
-
Blame-free by design
Coach people who click and celebrate people who report. A safe culture is what produces fast reporting when a real attack lands.
-
Realistic, relevant lures
Effective scenarios mirror the phishing your people actually face — supplier invoices, HR notices, MFA prompts — not unfair emotional traps.
-
Measure what matters
Track click-rate, report-rate and reporting speed together. A fast-reporting team shrinks an attacker’s window even when someone clicks.
Guides
Go deeper
Plain-English guides to planning, running and measuring a phishing-simulation programme.
-
How to run a phishing simulation: a step-by-step programme
A practical, ethical way to plan, send, measure and follow up a phishing simulation — and turn it into a programme that changes behaviour.
Read guide -
Ethical phishing simulations: how to test without breaking trust
A phishing simulation can build a security culture — or destroy it. The difference is ethics: blame-free, fair lures, and coaching over shaming.
Read guide -
Measuring phishing simulations: the metrics that matter
Click-rate is only half the story. Report-rate and reporting speed tell you whether your people are becoming a real defence.
Read guide
Frequently asked questions
Short, clear answers
What is a phishing simulation?
A phishing simulation is a controlled, authorised exercise where an organisation sends its own staff realistic but harmless fake phishing emails, to measure awareness and teach people to recognise real attacks. See how to run one →
Are phishing simulations effective?
Yes, when run as a sustained programme rather than a one-off. Repetition and in-the-moment feedback lower click-rates and — more importantly — build a fast reporting reflex over time. A single annual test does little.
Are phishing simulations ethical?
They can be, and should be. Ethical programmes are blame-free, use realistic rather than cruel lures, coach people who click, and never punish or shame. Read the ethics guide →
What should we measure?
Track click-rate, but also report-rate and reporting speed. A team that reports suspicious email quickly is safer than one that merely clicks less, because fast reporting shrinks the attacker’s window.
How often should we run simulations?
Regularly — monthly or quarterly is common — rather than once a year. Spaced repetition is what changes behaviour. Vary the scenarios so people learn the patterns, not one specific email.
Should employees know simulations happen?
Announce the programme in general (that simulations occur and why), without warning people of specific campaigns. Transparency about the programme builds trust; surprise on the individual email preserves realism.
Does NIS2 require security-awareness training?
The EU NIS2 Directive requires in-scope organisations to include cyber-hygiene and awareness training in their risk-management measures, with management accountable. Phishing simulation is a common, measurable way to meet that.
Do simulations replace technical email security?
No — they complement it. Filtering and authentication (SPF, DKIM, DMARC, MFA) stop most phishing; simulations train people for what gets through. You need both layers.