Phishing Simulation Campaigns: How to Test and Train Your Team
A phishing simulation is a controlled, authorized exercise that sends realistic but harmless fake phishing emails to employees, measuring who clicks, who enters credentials, and who correctly reports the attempt. It provides objective data on real-world security awareness rather than assumed knowledge.
If you ran one phishing simulation last year and do not know whether your team has actually improved, or an employee felt humiliated after failing your last simulation and you worry it damaged trust in the programme, this guide covers exactly how to design, launch, measure, and follow up on simulations the right way.
What Is a Phishing Simulation?
A phishing simulation is a controlled, authorized exercise where an organization sends realistic but harmless fake phishing emails to its own employees to measure and improve their ability to recognise and respond to real attacks.
Simulations exist separately from training content because reading about phishing and recognizing a live attempt in the middle of a busy workday are very different skills. A simulation tests the latter under realistic conditions. The platform sends a crafted email designed to mimic real phishing tactics, urgency, impersonation, malicious links or attachment prompts, then tracks who clicks, who enters credentials on a landing page, who opens attachments, and who reports the email correctly.
Unlike a real attack, simulations are run with full internal authorization, contain no actual malicious payload, and are designed specifically to educate rather than punish.
Why Run Simulated Phishing Attacks Against Your Own Employees?
Running simulated phishing attacks provides objective, measurable data on real-world susceptibility rather than relying on assumptions about how well training has worked. It identifies specific individuals and departments needing additional, targeted support before a real attacker finds them first.
Simulations reinforce training content at the moment it matters most, when an employee is actually presented with a realistic decision to make. They build organizational muscle memory for the reporting process, ensuring employees know exactly what to do when they encounter something suspicious. They also provide evidence of due diligence for compliance, audit, and cyber insurance purposes, demonstrating an active security awareness programme rather than a passive one. See Email Security Awareness Training: Building a Human Firewall for how simulation fits the broader programme.
What Types of Phishing Simulation Campaigns Should You Run?
| Simulation Type | What It Tests | Who It Should Target | Risk Level if Failed |
| Generic mass phishing | Baseline recognition | All staff | Low to moderate |
| Spear phishing | Personalised recognition skills | Higher-value employees | Moderate |
| BEC/CEO fraud | Executive impersonation response | Finance, accounts payable | High |
| Credential harvesting | Login credential entry | All staff | High |
| Attachment-based | Malicious file handling | All staff | Moderate to high |
| Quishing | QR code scanning caution | All staff, mobile-heavy roles | Moderate to high |
Generic mass phishing simulations use broad, low-sophistication templates testing baseline recognition across the entire organization, useful as a starting benchmark. Spear phishing simulations use personalized templates referencing department-specific details. BEC and CEO fraud simulations specifically test finance and accounts payable staff with simulated executive impersonation requests, given the disproportionate financial risk this category represents. Credential harvesting simulations test the most consequential failure outcome. Vishing and multi-channel programmes extend testing beyond email into simulated phone-based social engineering.
Quishing simulation is a frequently overlooked but increasingly necessary campaign type, and most legacy simulation programmes simply have not added it. QR code scanning behavior operates under different psychological and technical assumptions than clicking a desktop email link. An employee who has been thoroughly trained to hover over links and check URLs before clicking on a desktop screen often applies none of that learned scrutiny to a QR code, because the action feels different: it involves picking up a phone, opening a camera app, and scanning, a sequence that does not trigger the same trained caution as hovering a mouse over a hyperlink.
Mobile context adds further risk. On a phone, the destination URL is often not visible before the scan completes, removing the visual inspection step that desktop training relies on entirely. Employees also frequently associate QR codes with convenience and legitimate everyday use, restaurant menus, parking payments, conference materials, which lowers natural suspicion compared to an email link, even though the underlying risk of a malicious destination is identical. Organizations that have built a mature traditional phishing simulation programme but never added a quishing-specific campaign type have an untested and growing blind spot, given the documented increase in quishing attack volume. Adding quishing simulation should be treated as a required addition to a current programme, not an optional advanced extra.
How Do You Design a Realistic Phishing Simulation?
Base templates on real, current attack patterns rather than generic or outdated phishing examples that no longer reflect what employees actually encounter. Vary difficulty progressively, starting with more obvious indicators for a new programme, then increasing sophistication as baseline recognition improves. Tailor templates to your specific industry and organization, referencing internal tools or common supplier names, since this significantly increases realism and the value of the test. Include a mix of channels and pretexts across a campaign rather than relying on a single repeated template.
An explicit ethical design boundary deserves direct statement, because most competitor content avoids this entirely until an organization learns the lesson the hard way. Simulation templates should never exploit genuinely distressing personal topics purely to maximize click rates: fake medical emergencies, fabricated family crises, or scenarios designed to trigger acute personal fear or grief have no place in a legitimate simulation programme, regardless of how effectively they might drive engagement metrics.
These approaches produce a specific and damaging outcome: they generate impressive-looking click-through numbers while actively damaging the trust and psychological safety the broader awareness programme depends on to function. An employee who clicks a fake “your child’s school called” email is not demonstrating a security skill gap; they are responding to a manufactured personal crisis, and discovering afterward that it was a test designed to catch them in exactly that vulnerable moment causes a different and more lasting harm than discovering they clicked a fake invoice link. This harm extends beyond the individual employee, since news of a particularly distressing simulation spreads quickly through an organization and can poison goodwill toward the entire programme, making future genuine reporting less likely across the whole workforce.
The practical design standard: simulations should mimic genuine attacker tactics, urgency, authority, financial incentive, curiosity, without weaponising real personal vulnerability. A simulated CEO fraud request testing urgency and authority is legitimate. A simulated message about a family medical emergency is not, regardless of its realism or effectiveness at producing clicks.
How Do You Launch and Schedule a Phishing Simulation Campaign?
Step 1: Run a baseline simulation before any training to measure starting susceptibility.
Step 2: Select and customize realistic templates relevant to your industry.
Step 3: Segment campaigns by role and risk level.
Step 4: Schedule simulations at sensible, varied intervals.
Step 5: Deliver immediate just-in-time training to employees who fail.
Step 6: Track click rate, credential submission rate, and report rate over time.
Step 7: Adjust difficulty and targeting based on trend data.
Establish a baseline first by running an initial simulation before any awareness training, providing a genuine before-and-after comparison point. Avoid telegraphing specific dates, though general organizational awareness that simulations occur periodically is appropriate. Schedule monthly or bi-monthly simulations, varied in template and timing. Segment campaigns by role, sending different simulation types to finance, HR, IT, and general staff. Coordinate timing sensitively, avoiding major organizational stress points like redundancy announcements or critical deadlines.
The baseline-before-training sequencing requirement is a measurement integrity issue, not just a scheduling preference, and treating it as optional undermines the entire evidence base a simulation programme is meant to produce. If the first simulation runs after training has already begun, even partially, there is no honest way to demonstrate how much the training actually improved behavior, because the starting point was never genuinely captured. Organizations that skip this step and run their first simulation a few weeks into a new training rollout often end up unable to answer the single question leadership, auditors, and cyber insurers most want answered: is this programme actually working? Without an honest, pre-training baseline, every subsequent improvement claim rests on assumption rather than evidence.
The telegraphing question also deserves a more precise answer than competitor content typically gives. General organizational transparency that a simulation programme exists and runs periodically is appropriate, expected, and actually beneficial: it signals organizational seriousness and removes any sense of deception about the programme’s existence. What should specifically be avoided is announcing exact dates, sharing template previews in advance, or providing any other tell that would let employees recognize a specific test as a test before genuinely encountering it. This is a navigable, specific distinction, not an all-or-nothing secrecy requirement, and getting it right preserves both organizational trust and measurement realism simultaneously.
What Happens When an Employee Fails a Simulation?
Immediate, automated just-in-time training is the most effective response. A brief, specific module delivered the moment a failure occurs reinforces the exact lesson when it is most relevant and memorable. Avoid public callouts or punitive responses, since naming individuals in team meetings or company-wide communications discourages honest engagement and damages psychological safety. Track repeat failures for targeted follow-up, and recognise correct reporting behaviour publicly, not just silence, to reinforce that the desired behaviour is noticed and valued.
Distinguishing failure severity by outcome type deserves explicit treatment, because most competitor frameworks collapse every simulation failure into a single undifferentiated category. An employee who clicked a simulated phishing link but stopped there, never proceeding to enter any information, represents a meaningfully different and lower risk level than an employee who clicked through and entered working credentials on a fake login page. Treating both outcomes identically, with the same follow-up intensity and the same framing, wastes an opportunity to calibrate response proportionately to actual demonstrated risk.
A practical tiered response: a link click alone warrants a brief, low-friction just-in-time module covering URL inspection and hover-to-preview habits. Credential entry on a fake landing page warrants a more substantial follow-up, since this outcome means the employee’s actual account credentials would have been compromised in a real attack, potentially requiring a brief one-to-one conversation rather than only an automated module, alongside a genuine password reset as if the credentials had actually been exposed. This calibration also extends to repeat patterns: an employee who fails their first simulation needs different support than one who has failed the last four consecutive campaigns, where the underlying issue may not be a simple knowledge gap and may benefit from a direct, supportive conversation about what specifically is causing the repeated pattern.
See What Happens If You Click a Phishing Link? For the technical recovery steps that mirror this same severity distinction in a real incident.
How Do You Measure Phishing Simulation Results?
Click-through rate is the most commonly tracked baseline metric: the percentage of recipients who clicked the simulated phishing link. Credential submission rate tracks the percentage who proceeded to enter credentials on a fake landing page, representing the most serious failure outcome. Report rate, the percentage who correctly identified and reported the simulation, is an equally important metric often under-tracked relative to click rate. Time-to-report indicates genuine vigilance versus delayed reporting. Track trend over time across consecutive campaigns, and benchmark against published industry data like KnowBe4’s annual Phishing Industry Benchmarking Report.
Elevating report rate and time-to-report to equal importance alongside click-through rate is the single most important measurement correction most simulation programmes need, and it directly addresses a specific, common failure pattern. A programme that tracks only click-through rate, and optimizes purely for driving that number down, can produce a workforce that has learned to avoid clicking suspicious emails while never developing any active reporting habit at all. Employees in this scenario simply delete suspicious emails silently rather than reporting them, which looks identical to genuine security awareness on a click-rate dashboard but represents a completely different and much weaker actual security posture.
This distinction matters enormously in a real attack scenario. An organization with low click rates but near-zero reporting has no early-warning capability whatsoever: if a genuine, well-crafted phishing campaign targets multiple employees simultaneously, security teams have no visibility into the attack until damage has already occurred, because nobody is surfacing what they are seeing. An organization with moderate click rates but strong, fast reporting, where employees who do click immediately flag it and a meaningful proportion of the workforce actively reports suspicious email without ever clicking, gives security teams genuine operational intelligence and the ability to contain a real campaign before it spreads. Time-to-report adds further precision: a report submitted within minutes has dramatically more operational value than one submitted days later, since rapid reporting is what actually enables containment. Programmes should report all four metrics together rather than allowing click rate to stand in as a proxy for overall programme success.
What Phishing Simulation Tools Are Available?
| Tool | Type | Best For | Key Strength |
| KnowBe4 | Dedicated platform | Organizations wanting extensive content library | Largest template and content library, strong benchmarking data |
| Proofpoint Security Awareness Training | Dedicated platform | Existing Proofpoint customers | Tight integration with Proofpoint threat intelligence |
| Microsoft Defender for Office 365 Attack Simulator | Native platform feature | Microsoft 365 Plan 2 organizations | No separate tool required, native integration |
| GoPhish | Open source | Technical teams wanting self-managed control | Free, fully customizable, no license cost |
Dedicated security awareness platforms combine simulation campaign management with broader training content libraries and reporting dashboards. Microsoft Defender for Office 365 Plan 2 includes Attack Simulator, providing built-in capability without a separate tool. GoPhish offers simulation capability for organizations with technical capacity to self-manage campaigns, though without commercial content library depth.
When evaluating a tool, assess template realism and update frequency, ease of campaign scheduling, quality of just-in-time training content, reporting and trend analysis capability, and integration with your existing email platform. Cyber Security Solutions Ltd helps organizations select and configure the right simulation platform for their specific risk profile and existing email infrastructure.
What Are Common Mistakes When Running Phishing Simulations?
Common mistakes include running simulations as an isolated, infrequent event disconnected from any broader training programme, using outdated or unrealistic templates that produce misleadingly low click rates, and applying punitive responses to failure that suppress honest reporting. Other recurring mistakes include failing to track and act on report rate alongside click rate, and applying identical simulation difficulty and frequency across all roles rather than recognizing that finance, executive, and IT staff face meaningfully different risk profiles deserving tailored testing.
Conclusion
A well-run simulation programme measures more than click rate, builds genuine reporting culture rather than just click avoidance, and follows ethical design boundaries that protect employee trust. Getting the baseline, segmentation, and follow-up calibration right is what separates a programme that actually improves security from one that just generates numbers. Visit cybersecuritysolutionsltd.com for expert help designing and running phishing simulation campaigns tailored to your organization’s specific risk profile and team structure.
FAQs
A phishing simulation is a controlled, authorized exercise sending realistic but harmless fake phishing emails to employees. It measures who clicks, who enters credentials, and who correctly reports the attempt, providing objective data on real-world security awareness rather than relying on assumptions about training effectiveness.
Run simulations monthly or bi-monthly, varied in template and timing, rather than infrequent annual tests. This sustains genuine vigilance better than predictable, rare testing. Establish a baseline before any training begins, then maintain regular cadence segmented by role and risk level.
Click rate measures how many employees clicked the simulated link. Report rate measures how many correctly identified and reported it. Both matter equally: a low click rate with poor reporting leaves an organization blind to real attacks, while strong reporting provides genuine early-warning capability even with moderate click rates.
Deliver immediate, automated just-in-time training calibrated to the failure severity. Avoid public callouts or punitive responses, which discourage honest reporting. Distinguish between clicking a link and entering credentials, since these represent different risk levels deserving proportionate follow-up, including password resets for credential entry.
No. Templates exploiting genuine distress, fake medical emergencies, family crises, or similar scenarios, should never be used purely to maximize click rates. These approaches damage employee trust and psychological safety without improving genuine security skill, and can poison goodwill toward the entire awareness programme.
It depends on your existing platform and needs. Microsoft 365 Plan 2 organizations can start with built-in Attack Simulator at no extra cost. Organizations wanting extensive content libraries and benchmarking should consider KnowBe4 or Proofpoint. Technical teams with self-management capacity can use GoPhish for free.
