What a phishing simulation is, how one runs end to end, what the results actually tell you, and the ethics of testing your own colleagues.
A phishing simulation is a fire drill for your inbox. You send your own employees a realistic but harmless phishing email, then measure what they do with it — before a real attacker runs the same test without asking.
The point is not to catch people out. It is to let them meet the attack for the first time in a situation where being wrong costs nothing.
How one runs, end to end
- Scope and authorisation. Leadership and HR sign off, and the helpdesk is told, so a sharp employee's report does not trigger a real incident response.
- The lure. A realistic message goes out — a password reset, a delivery notice, a shared document — matched to what that audience genuinely receives.
- The response. Some people ignore it, some report it, some click, and some go on to enter credentials on the landing page. Those last two are different failures and worth separating.
- The teachable moment. Anyone who clicks lands on a short page explaining the two or three signals they missed, immediately, while the mistake is fresh.
- The read-out. The numbers go back to the programme owner and set what gets taught next.
What the results actually tell you
Click rate is the obvious number and the easiest to distort — an obvious lure produces a flattering result and teaches nobody anything. It only means something alongside the difficulty of the message.
Reporting rate is the better indicator. It shows people not just avoiding the trap but actively warning security.
Time to report matters most of all. A real campaign is a race, and whether the first report arrives in minutes or hours decides whether it gets contained or cleaned up after.
Repeat clicking identifies the small group that carries most of the exposure — usually where targeted help pays off far more than retraining everybody.
Watch for the trap in the combination: low clicks and low reports is not success. It usually means people ignored the email rather than recognised it. You want clicks falling while reports rise. See how click rates come down over a sustained programme.
Doing it ethically
Simulations involve deceiving colleagues, which earns a few obligations.
Never publish who clicked. Fear of exposure suppresses reporting, and reporting is the behaviour you most want. Avoid lures that exploit genuinely sensitive subjects — bonuses, redundancies, bereavement — which produce impressive numbers and lasting resentment. And frame results as organisational learning rather than individual failure.
A programme that people trust gets honest reporting. One they resent gets silence, which is worse than no programme at all.
Simulation is half the job
Testing measures behaviour; it does not teach it. Simulation without training measures a problem it never fixes, and training without simulation builds skills nobody verifies — the distinction is set out in phishing simulation vs. security awareness training. The aim throughout is a culture of reporting, where employees act as an early warning system.
On cadence, how often should you run them — consistency matters more than intensity.
Related Learning
- How to run a phishing simulation
- Phishing click rate benchmarks by industry
- Phishing simulation vs. security awareness training
- Phishing simulation software for small business
Related PhishSkill Capabilities
- AI-Powered Phishing Awareness Training — generate realistic, context-aware phishing simulations in seconds
- WhatsApp Phishing Awareness Training — extend simulation to the channel attackers use beyond email
More Learning Resources
View all learning resourcesBusiness Email Compromise (BEC) Explained
Learn what Business Email Compromise (BEC) is, how these sophisticated financial scams work, and the strategies organizations can use to defend against them.
Quick Guide: Phishing Resilience Score
What a phishing resilience score measures, why click rate alone misleads, and how to move the number without gaming it.
Quick Guide: Phishing Statistics
What the headline phishing numbers mean, how to read a benchmark without fooling yourself, and which of your own metrics actually predict risk.
Ready to stop phishing attacks?
Run realistic phishing simulations and high-impact security awareness training with PhishSkill's automated platform.