A practical guide to running a phishing simulation — scoping it, choosing a fair pretext, teaching at the click, and reading the numbers after.
A phishing simulation is a fire drill. You send your own people a realistic but harmless phishing email, watch what happens, and use the result to teach — safely, before an attacker runs the same test without your permission.
Here is how to run one properly.
Before you send anything
Get it authorised. A simulation sends deceptive email to your own staff, so it needs sign-off from whoever owns the decision — usually leadership plus HR. Doing this quietly is how a programme loses trust permanently.
Decide what you are measuring. "How many people click" is a start, but the more useful question is how many report, and how fast. Write the goal down before you send, or you will read the numbers to suit whatever happened.
Run a baseline first. Your first campaign should go out before any training, to establish the numbers every later one is compared against. Without it you cannot tell improvement from a lucky month.
Step 1: Pick a fair, realistic pretext
Use something your team genuinely sees — a password reset, an HR policy update, a failed delivery, a shared document. Match it to the audience: finance responds to invoices, everyone responds to payroll.
Avoid the two extremes. A lure with obvious spelling errors teaches nothing because nobody falls for it. A lure exploiting something genuinely sensitive — a bonus announcement, a redundancy notice, a bereavement — produces great click numbers and lasting resentment. The goal is practice, not a trophy.
Step 2: Set scope and timing
Start with a department rather than the whole company, so problems stay small and fixable. Send during normal working hours: a campaign landing at 3am tells you about people's sleep patterns, not their judgement.
Tell your IT and helpdesk teams it is happening. If you do not, the first sharp employee who reports it will trigger a genuine incident response, and you will have run an expensive drill on the wrong team.
Step 3: Send and observe
Watch two numbers, not one:
- Clicks — who followed the link, and who went on to enter credentials. These are different failures and worth separating.
- Reports — who flagged it, and how long the first report took. This is the number that predicts whether a real campaign gets contained.
A low click rate with a low report rate is not a win. It usually means people ignored the email rather than recognised it.
Step 4: Teach at the moment of the click
Anyone who clicks should land immediately on a short page explaining what they missed, in a supportive tone. One minute, two or three specific signals, no scolding. The correction lands because the mistake is still fresh.
Never publish a list of who clicked. Employees who fear exposure stop reporting their own mistakes, and self-reporting is the single most valuable behaviour you are trying to build.
Step 5: Review, then repeat
Compare against your baseline. Look at whether reports rose, whether time-to-report fell, and who clicked repeatedly — a small group usually carries a disproportionate share of the risk and deserves targeted help rather than blanket retraining.
Then do it again. One simulation a year changes nothing; consistent campaigns are what reduce click rates over time, and monthly or quarterly is the range most teams settle on.
The three mistakes that undo a programme
Punishing clickers, which buys silence instead of vigilance. Running once a year, which builds no habit. And making simulations easier than real attacks, which produces flattering numbers and unprepared people.
Related Learning
More Learning Resources
View all learning resourcesBusiness Email Compromise (BEC) Explained
Learn what Business Email Compromise (BEC) is, how these sophisticated financial scams work, and the strategies organizations can use to defend against them.
Quick Guide: Deepfake Phishing
Deepfake phishing uses AI-cloned voices and video to impersonate executives. Learn how it works and the verification habits that stop it.
What Is Smishing? SMS, WhatsApp, and Mobile Phishing Explained
Smishing is phishing delivered through text messages. Learn how SMS attacks work, why they bypass email defences, and how to train employees to spot them.
Ready to stop phishing attacks?
Run realistic phishing simulations and high-impact security awareness training with PhishSkill's automated platform.