What is a phishing simulation?
A phishing simulation is a fake but realistic phishing email your organisation sends to its own staff, with safe links and full tracking. Anyone who clicks lands on a friendly training page instead of an attacker's site, and the results show exactly where your risk sits.
Simulations exist because phishing is not a knowledge problem, it is a reflex problem. Most people can describe a phishing email in a quiz; far fewer pause on a convincing one at 4:55pm on a Friday. APWG's quarterly tracking shows phishing volumes at historic highs, and CISA's guidance treats recognising and reporting it as a baseline workplace skill. The only way to build a reflex is repetition in safe conditions.
Do phishing simulations work?
Yes, measurably, when they train rather than punish. Programmes that pair regular simulations with instant coaching see click rates fall sharply over the first year and reporting rates climb. Simulations used to name and shame produce fear, resentment and no lasting improvement.
The evidence sits in the difference between first and later campaigns. Baselines routinely catch a large share of any untrained workforce; after a year of monthly or quarterly cycles with immediate micro-training for clickers, the same templates catch a fraction of that. Just as importantly, the number of people who report the email, the metric that actually protects you, goes up. The failure mode is real too: punish clickers and staff stop reporting anything, which leaves you blinder than before the programme started.
That is why the platform behaviour matters. train2secure auto-enrols clickers into a short refresher the moment they click, keeps individual results private to admins, and tracks the trend per campaign, so the programme trains instead of trapping. The broader case for training the human layer is in the security awareness training guide.
How do you run a phishing test on employees?
Get leadership sign-off and a policy, run an unannounced baseline, then move to a regular cycle: pick a realistic template, send to a sample, coach clickers instantly, and report the trend. Six steps, repeated, with the lure rotated so nobody learns the pattern.
| Step | What to do | Watch out for |
|---|---|---|
| 1. Authorise | Leadership sign-off, a written policy, HR in the loop | Surprising HR is worse than surprising staff |
| 2. Baseline | One unannounced campaign to measure the honest starting point | Announcing it first inflates your score |
| 3. Choose templates | Realistic lures: delivery notes, invoice approvals, password resets | Cruel lures (fake bonuses) destroy trust |
| 4. Send & track | Stagger delivery, track opens, clicks and reports per recipient | Everyone at 9:00am sharp gets noticed and shared |
| 5. Coach instantly | Clickers land on a friendly page and get a short refresher, automatically | Blame kills reporting; keep results private |
| 6. Report & repeat | Share the trend with leadership, rotate templates, run the next cycle | A single test proves nothing; the trend is the product |
Sending a test phishing email to employees is the one step you should not improvise with a mail merge: you need safe landing pages, per-recipient tracking and automatic coaching, or the exercise collects risk without reducing it. The fastest way to see the whole loop is to run a free phishing test on your team and watch the results arrive live.
What makes a good phishing simulation template?
Plausibility beats polish. The best templates mirror emails your staff genuinely receive (deliveries, invoices, IT notices), carry one deliberate tell, and match the difficulty to the audience. Rotate scenarios so the lesson is scrutiny, not pattern-matching.
Difficulty should be a dial, not an accident. Early campaigns use obvious tells: mismatched sender domains, generic greetings, odd urgency. Later ones tighten up, because real attackers do. Role-targeting matters too: finance sees payment fraud, executives see whaling attempts, IT sees credential lures. train2secure Pro ships a rotating library of 15+ templates plus a custom builder for scenarios that copy your own workflows, with campaign-level tracking and PDF reports for the board.
Cadence and the compliance angle (how often frameworks expect testing, and what counts as evidence) get their own guide in this series shortly. For the questions a specific framework asks, the standards page maps what train2secure covers today, and the questions hub answers the single-question follow-ups, including what should happen when someone fails a test and whether simulated emails should be reported.
Common questions
Are phishing simulations legal and ethical?
Yes, when run by the employer on its own staff with a policy behind them. The ethical line is purpose: simulations exist to train, not to trap. Coach clickers immediately, never publish names, and avoid cruel lures such as fake bonuses, and the exercise stays firmly on the right side.
What is a good click rate on a phishing test?
First baselines commonly land in double digits, and mature programmes push simulated click rates into the low single digits. Treat the trend as the metric, not any one number: template difficulty moves results, so compare like with like.
What is a baseline phishing test?
The first unannounced simulation you run before training starts. It measures where the organisation genuinely stands, gives leadership an honest number, and makes the improvement from training visible instead of anecdotal.
Do you need special software to run a phishing simulation?
In practice, yes. A realistic campaign needs safe landing pages, per-recipient tracking, automatic training for clickers and clean reporting. Hand-rolling that with a mail merge risks spam filters, broken tracking and awkward HR conversations.
Can a phishing simulation include my own custom scenario?
It should. The most effective lures mirror your real workflows: your invoicing process, your HR portal, your delivery notifications. train2secure Pro includes custom template building alongside the ready-made library.
Start with the security awareness training guide, then put it into practice: free phishing test or see Pro plans with phishing included.
