Back to Learning Hub

How to Run a Phishing Simulation

Last updated: 2026-08-133 min read

A practical guide to running a phishing simulation — scoping it, choosing a fair pretext, teaching at the click, and reading the numbers after.

A phishing simulation is a fire drill. You send your own people a realistic but harmless phishing email, watch what happens, and use the result to teach — safely, before an attacker runs the same test without your permission.

Here is how to run one properly.


Before you send anything

Get it authorised. A simulation sends deceptive email to your own staff, so it needs sign-off from whoever owns the decision — usually leadership plus HR. Doing this quietly is how a programme loses trust permanently.

Decide what you are measuring. "How many people click" is a start, but the more useful question is how many report, and how fast. Write the goal down before you send, or you will read the numbers to suit whatever happened.

Run a baseline first. Your first campaign should go out before any training, to establish the numbers every later one is compared against. Without it you cannot tell improvement from a lucky month.

Step 1: Pick a fair, realistic pretext

Use something your team genuinely sees — a password reset, an HR policy update, a failed delivery, a shared document. Match it to the audience: finance responds to invoices, everyone responds to payroll.

Avoid the two extremes. A lure with obvious spelling errors teaches nothing because nobody falls for it. A lure exploiting something genuinely sensitive — a bonus announcement, a redundancy notice, a bereavement — produces great click numbers and lasting resentment. The goal is practice, not a trophy.

Step 2: Set scope and timing

Start with a department rather than the whole company, so problems stay small and fixable. Send during normal working hours: a campaign landing at 3am tells you about people's sleep patterns, not their judgement.

Tell your IT and helpdesk teams it is happening. If you do not, the first sharp employee who reports it will trigger a genuine incident response, and you will have run an expensive drill on the wrong team.

Step 3: Send and observe

Watch two numbers, not one:

  • Clicks — who followed the link, and who went on to enter credentials. These are different failures and worth separating.
  • Reports — who flagged it, and how long the first report took. This is the number that predicts whether a real campaign gets contained.

A low click rate with a low report rate is not a win. It usually means people ignored the email rather than recognised it.

Step 4: Teach at the moment of the click

Anyone who clicks should land immediately on a short page explaining what they missed, in a supportive tone. One minute, two or three specific signals, no scolding. The correction lands because the mistake is still fresh.

Never publish a list of who clicked. Employees who fear exposure stop reporting their own mistakes, and self-reporting is the single most valuable behaviour you are trying to build.

Step 5: Review, then repeat

Compare against your baseline. Look at whether reports rose, whether time-to-report fell, and who clicked repeatedly — a small group usually carries a disproportionate share of the risk and deserves targeted help rather than blanket retraining.

Then do it again. One simulation a year changes nothing; consistent campaigns are what reduce click rates over time, and monthly or quarterly is the range most teams settle on.


The three mistakes that undo a programme

Punishing clickers, which buys silence instead of vigilance. Running once a year, which builds no habit. And making simulations easier than real attacks, which produces flattering numbers and unprepared people.


Related Learning

Ready to stop phishing attacks?

Run realistic phishing simulations and high-impact security awareness training with PhishSkill's automated platform.