Security awareness
Practise recognising and reporting phishing
Give your team relevant practice with suspicious messages, clear reporting routes and constructive feedback. Use campaign results to improve the programme alongside technical defences.
- Based on Verizon DBIR & APWG data
- Ethical, evidence-based
- Updated 2026
What is phishing simulation
A fire drill for your inbox
A phishing simulation is an authorised exercise using imitation phishing messages to practise recognition, reporting and response.
A phishing simulation uses controlled messages without malicious payloads to rehearse suspicious-message handling. Authorisation, fair scenarios and limited data collection matter: deceptive exercises can still cause distress or undermine trust if badly designed.
Relevant practice and feedback can support learning. A campaign measures behaviour under its particular conditions; repeated results need context and do not prove that staff will detect every real attack.
Done well, it is positive and blame-free. Done badly – as a "gotcha" that shames people – it erodes trust and teaches staff to hide mistakes. This guide covers how to do it well.
Why simulate
What a simulation actually builds
Four objectives a well-designed programme can support alongside technical controls.
- HUMAN
Supports message handling
Simulations help staff practise verification and reporting when suspicious messages reach them. Identity controls, filtering, detection and response share the defensive work.
- PRACTICE
Controlled rehearsal
Relevant scenarios let staff practise without a malicious payload. Fair lures, constructive feedback and clear data-handling rules help protect trust.
- METRICS
Measurable progress
Click-rate and report-rate turn "awareness" into numbers you can track over time and show to leadership and auditors.
- CULTURE
A reporting reflex
The real win is staff who report suspicious email quickly. That turns every employee into a sensor and shrinks an attacker’s window.
Do it right
The mistakes that make simulations backfire
A badly run programme is worse than none – it damages trust and teaches people to hide clicks. Avoid these.
- Worst
Punishing people who click
Naming, shaming or disciplining clickers kills the reporting culture you’re trying to build. People hide mistakes instead of flagging them.
Do instead: Make it blame-free; reward reporting, coach clicking
- Harmful
Cruel "gotcha" lures
Fake bonus or bereavement emails may boost click stats but destroy trust in the security team and the exercise.
Do instead: Use realistic, fair scenarios – not emotional traps
- Ineffective
One-and-done testing
A single annual test is a compliance tick, not training. Behaviour only shifts with sustained, spaced repetition.
Do instead: Run a continuous programme, not a yearly event
- Incomplete
Only tracking click-rate
Clicks alone do not measure reporting or response. Check whether useful reports reach the right team and lead to timely action.
Do instead: Measure report-rate and reporting speed too
Programme loop
The loop, stage by stage
Six stages, in order. Pick one to see what to do and what to write down.
Interactive mode is not available. You can read the full reference content below. No answers are assessed and no result is calculated.
Baseline
Agree purpose, authorisation, data access and fair scenarios. Record delivery, reporting and interaction measures before choosing a training focus.
What you record: Click, submission and report rates by department, time to first report, and the difficulty, audience and exclusions you agreed.
First campaign
Use a relevant scenario and a safe reporting path. Exclude automated scanner activity and provide constructive feedback without collecting real passwords.
What you record: Theme, difficulty and sending domain; delivery timestamps and bounces; who was genuinely reachable.
Review and coach
Discuss what made the message difficult. Practise independent verification and reporting, and fix technical or procedural obstacles.
What you record: Whether the coaching page was reached, follow-up training completion and date, and the obstacles people named.
Repeat with context
Vary scenarios and record their difficulty. Compare similar audiences and conditions; a lower click rate alone does not prove lower real-world risk.
What you record: The same fields again, difficulty and audience included, so two campaigns can be compared like for like.
Test the response
Check whether reports reach the right team, are triaged promptly and lead to action. Review missed reports as well as clicks.
What you record: Time to first report, time to triage, and what the reporting queue actually did with each report.
Review the programme
Summarise trends, limitations and improvements with leadership. Choose the next cycle from observed needs instead of promising a target click rate.
What you record: Rates, coverage and movement since the last cycle – aggregated, never individual names.
Stage 6 sets up the next stage 1.
What to do at this stage
Agree purpose, authorisation, data access and fair scenarios. Record delivery, reporting and interaction measures before choosing a training focus.
What you recordClick, submission and report rates by department, time to first report, and the difficulty, audience and exclusions you agreed.
Use a relevant scenario and a safe reporting path. Exclude automated scanner activity and provide constructive feedback without collecting real passwords.
What you recordTheme, difficulty and sending domain; delivery timestamps and bounces; who was genuinely reachable.
Discuss what made the message difficult. Practise independent verification and reporting, and fix technical or procedural obstacles.
What you recordWhether the coaching page was reached, follow-up training completion and date, and the obstacles people named.
Vary scenarios and record their difficulty. Compare similar audiences and conditions; a lower click rate alone does not prove lower real-world risk.
What you recordThe same fields again, difficulty and audience included, so two campaigns can be compared like for like.
Check whether reports reach the right team, are triaged promptly and lead to action. Review missed reports as well as clicks.
What you recordTime to first report, time to triage, and what the reporting queue actually did with each report.
Summarise trends, limitations and improvements with leadership. Choose the next cycle from observed needs instead of promising a target click rate.
What you recordRates, coverage and movement since the last cycle – aggregated, never individual names.
These are programme stages, not predicted results or a fixed schedule. Phishing simulation supports wider awareness training and technical defences; it does not establish compliance on its own.
The numbers
Why the human layer matters
Phishing remains one of the most common and fastest-moving routes into an organisation.
Each figure links to its primary source. Numbers are approximate and updated as new reports are published; all four sources were last checked on 13 September 2026.
For security teams
Awareness training is now a governance requirement
Under the EU NIS2 Directive, cyber-hygiene and staff awareness aren’t optional extras – they’re part of the security measures management is accountable for.
The measures referred to in paragraph 1 … shall include at least the following: … (g) basic cyber hygiene practices and cybersecurity training.
-
Baseline, then improve
Start with a fair baseline simulation to measure where you are, then run a continuous programme and watch the trend – not a single score.
-
Blame-free by design
Coach people who click and celebrate people who report. A safe culture is what produces fast reporting when a real attack lands.
-
Realistic, relevant lures
Effective scenarios mirror the phishing your people actually face – supplier invoices, HR notices, MFA prompts – not unfair emotional traps.
-
Measure what matters
Track click-rate, report-rate and reporting speed together. A fast-reporting team shrinks an attacker’s window even when someone clicks.
Guides
Go deeper
Plain-English guides to planning, running and measuring a phishing-simulation programme.
-
How to run a phishing simulation: a step-by-step programme
A practical, ethical way to plan, send, measure and follow up a phishing simulation – and turn it into a programme that supports reporting and practical follow-up.
Read guide -
Ethical phishing simulations: how to test without breaking trust
A phishing simulation can build a security culture – or destroy it. The difference is ethics: blame-free, fair lures, and coaching over shaming.
Read guide -
Measuring phishing simulations: the metrics that matter
Click-rate is only half the story. Report-rate and reporting speed tell you whether your people are becoming a real defence.
Read guide
Frequently asked questions
Short, clear answers
What is a phishing simulation?
A phishing simulation is an authorised exercise using imitation messages without malicious payloads. It can support recognition, reporting and response practice. Fair scenarios and careful data handling are part of planning the programme.
Are phishing simulations effective?
They can support learning and reporting when combined with relevant training and technical controls. Results depend on programme design and context; compare similar scenarios and measure reporting and response, not clicks alone.
Are phishing simulations ethical?
They can be, and should be. Ethical programmes are blame-free, use realistic rather than cruel lures, coach people who click, and never punish or shame.
What should we measure?
Track clicks, reports, reporting speed and the response to useful reports. Compare similar scenarios and filter automated activity. Faster reporting helps only if it reaches a team able to investigate and act; no single metric establishes lower breach risk.
How often should we run simulations?
Regularly – monthly or quarterly is common – rather than once a year. Spaced repetition is what changes behaviour. Vary the scenarios so people learn the patterns, not one specific email.
Should employees know simulations happen?
Announce the programme in general (that simulations occur and why), without warning people of specific campaigns. Transparency about the programme builds trust; surprise on the individual email preserves realism.
Does NIS2 require security-awareness training?
Article 21(2)(g) of the EU NIS2 Directive lists "basic cyber hygiene practices and cybersecurity training" among the risk-management measures in-scope entities must take, and Article 20 makes management bodies approve and oversee those measures. Phishing simulation can support that training; a simulation alone does not satisfy all NIS2 duties.
Do simulations replace technical email security?
No. Filtering, domain authentication, phishing-resistant MFA, detection and response address different parts of the attack. SPF, DKIM and DMARC help with domain impersonation but do not stop all deceptive messages. Simulations can support staff practice alongside those controls.
Disagree with an answer, or found an error? Corrections and challenges go to support@offseq.com.