What Is a Phishing Simulation?

Also called: Simulated phishing, Phishing test

Related problems: Not sure whether staff would fall for a real phishing email; Cyber insurer asking for proof that we test employees; Training completion rates that say nothing about real behavior; Staff not reporting suspicious emails to IT

A phishing simulation is a controlled exercise in which an organization sends realistic but harmless phishing emails, or sometimes text messages or calls, to its own employees. The goal is to see who recognizes and reports the message, who clicks a link or enters credentials, and to give immediate, private feedback to those who were fooled. Phishing simulations are usually part of a wider security awareness training program, and their results help measure whether staff behavior is actually improving.

At a glance

  • Simulations are fake, harmless attacks sent to your own staff with the organization’s approval.
  • They test both sides of behavior: not clicking, and reporting suspicious messages.
  • People who fall for a simulation typically get immediate feedback and a short lesson.
  • Results are most useful as trends over time, alongside report rates, rather than as a single click rate.
  • They work best when framed as learning and agreed with HR and leadership, not used to punish.

What problem it solves

Phishing remains one of the most common ways attackers get into companies, and email filtering doesn’t catch everything. Training courses teach people what phishing looks like, but completion certificates say little about how someone reacts to a convincing message on a busy afternoon. Companies need a safe way to find out.

Simulations provide that evidence. They show which departments or roles are most susceptible, whether training is working, and whether people use the report button. They also give staff low-risk practice, so recognizing and reporting a suspicious message becomes a habit. For many companies, simulation results are also evidence that cyber insurers, auditors and customers ask for when reviewing security controls.

How it works

Planning. The organization chooses a platform, agrees the program with HR and leadership, and decides frequency, audience and how results will be used. Many announce the program in general terms so staff know tests happen.

Allowing messages through. IT configures email security, such as the secure email gateway (SEG) or the email platform’s built-in filters, to deliver simulation messages without weakening protection against real attacks.

Sending simulations. The platform sends messages based on templates that mimic real attacks: fake delivery notices, shared document requests, password expiry warnings or invoice requests resembling business email compromise (BEC). Difficulty and timing vary. Some platforms also simulate SMS and voice phishing as part of broader social engineering testing.

Feedback. When someone clicks or enters credentials, they see a landing page explaining what they missed. They may be enrolled in a short training module. People who report the message through the report button get positive confirmation.

Measurement. Dashboards track click rates, credential submission rates, report rates and time to report, by department and over time. Repeat clickers may get additional, supportive training.

When it matters for buyers

  • When launching or renewing security awareness training (SAT). Simulation features differ widely between platforms.
  • When cyber insurance renews. Insurers often ask whether staff are trained and tested on phishing.
  • After a phishing incident. Simulations show whether lessons have stuck.
  • When customers or auditors request evidence. Simulation reports provide measurable proof of a working program.
  • When onboarding new staff or acquiring companies. New groups often start with a baseline test.

Our security awareness training overview covers programs that combine simulations with ongoing training.

Questions to ask vendors

  • What simulation types do you support: email, SMS, voice, QR codes, collaboration tools?
  • How are templates kept current with real-world attacks, and can we customize them?
  • How do we allow simulations through our email security without weakening it?
  • What happens when a user clicks, and can we adjust the follow-up training?
  • Does your report button also handle real suspicious messages, and where do those reports go?
  • What metrics and reports do you provide, and can we export them for insurers or auditors?
  • How is the platform priced: per user, per feature tier or another way?

How it differs from security awareness training

Security awareness training (SAT) is the overall program that teaches employees to recognize, avoid and report threats, including training modules, policies, communications and measurement. A phishing simulation is one tool within that program: a practical test that measures behavior and reinforces lessons. Simulations without training mostly measure; training without simulations mostly informs. Most platforms sell both together. A simulation also differs from a penetration test, which may include phishing but aims to find and exploit weaknesses to show what an attacker could achieve, rather than to teach staff.

Frequently Asked Questions

Should we tell employees we run phishing simulations?
Usually, yes. Announcing the program, without revealing when tests will arrive, builds trust and keeps the focus on learning. Many companies agree the approach with HR and leadership first, including how results will and won't be used.
What happens when an employee clicks a simulated phishing link?
Typically they see a short explanation of the warning signs they missed, and they may be assigned a brief training module. Nothing harmful happens. Good programs treat clicks as learning opportunities and avoid public shaming.
How often should we run phishing simulations?
Many organizations run them monthly or quarterly, varying the style and difficulty. Too rarely and people forget; too often and people tune out or feel targeted. Check whether your insurer or auditor expects a particular frequency.
What is a good click rate?
There isn't a universal target, because results depend heavily on how difficult the simulations are. Trends over time, the share of people who report the message, and how quickly reports arrive are more useful than a single click rate.
Will our email security block the simulations?
It may, unless it is configured to allow them. Simulation vendors provide instructions for allowing their messages through your email filtering without weakening protection against real attacks.

You Don’t Need Another Sales Call. You Need an Answer.

30 minutes. No pitch. Just an honest conversation about where you are, what you need, and whether working together makes sense.

We use your details to set up and prepare for the call, and send the newsletter only if you ask for it. Privacy policy.