A successful phishing simulation should not demonstrate how easy it is to trick employees. It should make the organisation harder to trick next time. As explored in our earlier Cyber Security Awareness Training: What IT Teams Should Compare buyer’s guide, effective security awareness is increasingly focused on changing behaviour rather than simply demonstrating that employees have completed training. Phishing simulations can provide one way to test whether that behaviour carries into the workplace. But the way simulations are designed, measured and communicated matters.
Run badly, they can embarrass employees, create resentment and encourage people to view the security team as trying to catch them out. Run well, they can help employees develop a simple and valuable habit: Pause. Question. Verify. Report.
Decide What Behaviour You Are Testing
Before creating a simulated phishing email, IT teams should ask:
What do we want employees to do differently?
Possible objectives might include:
- Recognising suspicious links
- Checking unusual requests
- Identifying impersonation
- Reporting suspicious emails
- Challenging unexpected payment instructions
- Protecting credentials
The simulation can then be designed around that behaviour.
Awareness Principle
Don’t start by asking “How convincing can we make the phishing email?” Start by asking “What security behaviour are we trying to improve?”
This changes phishing simulation from a test of employee gullibility into a structured security exercise.
Establish a Baseline
Initial simulations can help organisations understand current behaviour.
Useful measures might include:
- Emails opened
- Links clicked
- Credentials submitted
- Attachments opened
- Suspicious emails reported
- Time to first report
- Time until security teams respond
The purpose of the baseline is not to identify the organisation’s “worst” employees.
It is to understand where risk and training needs exist.
Repeated simulations can then show whether behaviour is changing.
Make Scenarios Realistic
Generic phishing simulations can still be useful, but scenarios that reflect the organisation’s genuine threat environment may provide greater learning value.
Examples might involve:
- Microsoft 365 login requests
- Password resets
- Shared documents
- Delivery notifications
- HR messages
- Invoice requests
- Executive impersonation
- Supplier communications
The NCSC highlights phishing as one of the common ways attackers attempt to obtain information or encourage users to visit malicious websites.
NCSC – Phishing Attacks: Defending Your Organisation – https://www.ncsc.gov.uk/guidance/phishing
IT teams can use real attack patterns seen by the organisation to inform future simulations without reproducing malicious content unnecessarily.
Increase Difficulty Gradually
If every simulation is extremely sophisticated, employees may feel the exercise is designed primarily to make them fail.
If every email is obviously fake, the programme teaches little.
A more useful approach is to vary difficulty over time.
For example:
Stage 1: obvious warning signs.
Stage 2: plausible external messages.
Stage 3: more contextual impersonation.
Stage 4: scenarios reflecting threats actually encountered by the organisation.
This allows employees to develop judgement rather than simply memorising a list of obvious phishing clues.
Avoid Humiliating Employees
Publishing league tables of employees who clicked a simulated phishing link may attract attention.
It can also send the wrong message.
If employees believe reporting mistakes will result in embarrassment or punishment, they may become less willing to tell IT when something genuinely goes wrong.
That is dangerous.
An employee who clicks a suspicious link and immediately reports it gives the security team an opportunity to respond.
An employee who hides the mistake does not.
Security Culture Principle
The organisation needs employees to report mistakes faster than attackers can exploit them.
Creating that behaviour requires trust.
Make Reporting Easy
Recognising a suspicious email is only half the task.
Employees also need to know what to do next.
Organisations can provide a clear reporting route through mechanisms such as:
- A phishing-report button
- A dedicated security mailbox
- Service desk reporting
- Security platforms integrated with email
Whatever method is chosen, it should be easy to remember and quick to use.
Employees should not have to search an intranet for a ten-step reporting procedure while deciding whether an email is dangerous.
Measure Reporting, Not Just Clicking
Click rates are one of the most familiar phishing simulation metrics.
But on their own they provide a limited picture.
Consider two organisations.
Organisation A: 4% click rate, 10% reporting rate.
Organisation B: 6% click rate, 70% reporting rate.
Which has the stronger security culture?
The answer cannot be determined from click rate alone.
Useful measures can include:
- Click rate
- Credential submission rate
- Reporting rate
- Time to first report
- Repeat behaviour
- Performance by scenario type
Measurement Insight
A falling click rate is useful. A rising reporting rate may be even more valuable.
It demonstrates that employees are actively participating in the organisation’s detection capability.
Provide Immediate Learning
When somebody interacts with a simulated phishing message, the learning opportunity is strongest while the decision is still fresh.
Instead of simply displaying:
“You failed the phishing test.“
the organisation can explain:
- What indicators were present
- What the employee could have checked
- What action would have been safer
- How to report similar messages
Short, contextual guidance may be more useful than sending the employee back through a lengthy generic awareness course.
Train for Decision-Making, Not Memorisation
Traditional phishing advice often focuses on clues such as spelling mistakes, suspicious addresses and unusual links.
These remain useful.
But phishing techniques continue to evolve, and well-written malicious emails may contain few obvious errors.
Employees therefore need broader decision-making habits.
For unexpected or sensitive requests:
Pause.
Does this request make sense?
Question.
Is anything unusual about the sender, timing or action requested?
Verify.
Can I confirm the request through another trusted channel?
Report.
Does the security team need to know?
This behaviour is useful even when an email looks entirely professional.
Use More Than Email-Based Training
Security awareness can also benefit from different learning formats.
Esc. The Cyber Escape Room, for example, uses interactive cyber escape-room experiences to engage employees with security scenarios.
Esc. The Cyber Escape Room – https://www.cyberescaperoom.co/
Experiential learning can help employees practise security decisions in a setting that feels different from traditional compliance training.
Providers including Protrona, Arcanum Cyber Security, Core To Cloud and IntaForensics also operate across different areas of cybersecurity, risk, training, technical services and incident response.
This reinforces a wider point: phishing resilience is not created by simulations alone.
It sits within an organisation’s broader combination of people, processes and technical controls.
Adapt Training According to Risk
Different employees can face different phishing threats.
Finance teams may encounter invoice fraud.
Senior executives may be targeted by impersonation.
HR employees handle valuable personal information.
IT administrators may possess privileged system access.
Rather than giving everybody exactly the same simulation programme, organisations can introduce scenarios reflecting different roles and risks. This does not mean making particular employees targets for punishment. It means making security training more relevant to the decisions they actually face.
Respond Differently to Repeat Behaviour
Repeated risky behaviour may indicate that an employee needs additional support.
The response should be proportionate.
That might include:
- Short refresher training
- Coaching
- Additional simulations
- Discussion with the employee
- Review of whether the original training is effective
Persistent high-risk behaviour involving privileged roles may require stronger intervention.
But the starting point should be understanding why the behaviour is occurring, rather than assuming negligence.
Connect Simulations with Technical Controls
Employees should never be the only defence against phishing.
Technical controls remain essential.
These can include:
- Email filtering
- Multi-factor authentication
- Endpoint protection
- Domain protection
- Web filtering
- Identity controls
- Monitoring
Cybersecurity specialists such as Core To Cloud and Arcanum Cyber Security operate across wider security technologies and services that can form part of this layered approach.
The NCSC similarly recommends combining staff awareness with technical measures to make phishing attacks more difficult.
Defence Principle
The purpose of awareness training is not to transfer responsibility for cybersecurity from technology to employees. It is to add another effective layer of defence.
Use Simulation Results to Improve Security Controls
Simulation data should not only influence training.
It can also reveal wider security weaknesses.
For example:
Employees repeatedly struggle with fake login pages
Could authentication controls be strengthened?
Staff cannot easily verify payment requests
Does the finance process need an independent verification step?
Employees recognise phishing but rarely report it
Is the reporting process too difficult?
One department repeatedly performs poorly
Does its workflow expose staff to unusually difficult decisions?
This turns simulation results into input for wider security improvement.
Prepare for the Real Incident
Ultimately, the purpose of phishing simulation is to improve behaviour when the email is not a simulation.
Employees should know:
- How to recognise something suspicious.
- How to report it.
- What to do if they clicked.
- What to do if they entered credentials.
- Who will help them.
Organisations should make one message particularly clear: Report the incident quickly, even if you think you made a mistake.
Fast reporting gives IT and security teams more time to investigate, reset credentials, isolate devices or take other appropriate action.
Specialists such as IntaForensics operate within areas including digital forensics, incident response and cyber investigation, illustrating what may be required once a suspected security incident moves beyond prevention.
A Practical Phishing Simulation Checklist
IT teams should ask:
- What behaviour is this simulation designed to test?
- Does the scenario reflect realistic threats?
- Is the difficulty appropriate?
- Are we avoiding unnecessarily deceptive or humiliating scenarios?
- Can employees report suspicious messages easily?
- Are we measuring reporting as well as clicking?
- Do employees receive useful feedback?
- Are scenarios relevant to different job roles?
- How do we support employees showing repeated risky behaviour?
- Are technical controls reducing reliance on users?
- Are simulation findings improving wider security processes?
- Do employees know what to do after a real mistake?
Frequently Asked Questions
How often should organisations run phishing simulations?
There is no single frequency suitable for every organisation. Simulations should form part of an ongoing security-awareness programme and reflect the organisation’s risk, workforce and threat environment rather than becoming a predictable annual exercise.
What is a good phishing simulation click rate?
A single click-rate target can be misleading. Organisations should monitor trends over time alongside reporting rates, credential submission, scenario difficulty and the speed with which suspicious activity is reported.
Should employees be told about phishing simulations?
Employees should understand that simulations form part of the organisation’s security-awareness programme, although giving advance notice of individual exercises would reduce their value.
Should employees who fail phishing tests be punished?
Simulation results are generally more useful when they identify opportunities for learning and risk reduction. Repeated high-risk behaviour may require additional intervention, but creating fear around mistakes can discourage employees from reporting genuine incidents.
Product Guide
Esc. The Cyber Escape Room
Provides interactive cyber escape-room experiences designed to engage employees with cybersecurity risks and improve awareness through scenario-based learning.
Website: https://www.cyberescaperoom.co/
Protrona
Cybersecurity specialist providing services designed to help organisations manage cyber risk, security awareness and wider security requirements.
Website: https://www.protrona.com/
Arcanum Cyber Security
UK cybersecurity consultancy providing security services and support across organisational cyber-risk requirements.
Website: https://arcanum-cyber.com/
Core To Cloud Ltd
Cybersecurity specialist providing security technologies and services across areas including threat detection, protection and cyber resilience.
Website: https://www.coretocloud.co.uk/
IntaForensics
Cybersecurity and digital-forensics specialist providing services including incident response, cyber investigation and digital forensic expertise.
Website: https://www.intaforensics.com/
From Testing Employees to Building Security Behaviour
Phishing simulations are most valuable when the objective is not catching people out.
It is building behaviour that transfers into a real attack.
That creates a simple progression:
simulate → recognise → report → learn → improve
Over time, organisations should be able to see not only fewer risky interactions, but more employees recognising and reporting suspicious activity quickly.
That is a much stronger measure of security culture than training completion alone.
The Cyber Secure Forum connects senior IT and cybersecurity professionals with carefully selected suppliers through pre-arranged one-to-one meetings, providing an opportunity to explore security awareness, cyber training, threat detection and wider cybersecurity solutions.
Related Reading
This article follows our earlier Cyber Security Awareness Training: What IT Teams Should Compare buyer’s guide, covering behaviour change, training formats, phishing simulations, measurement, reporting culture and supplier evaluation.
Together, the two articles move from choosing a security-awareness programme designed to change behaviour to testing and strengthening that behaviour through effective phishing simulations.
Sources
- National Cyber Security Centre – Phishing Attacks: Defending Your Organisation – https://www.ncsc.gov.uk/guidance/phishing
- National Cyber Security Centre – Exercise in a Box – https://www.ncsc.gov.uk/information/exercise-in-a-box
- National Cyber Security Centre – 10 Steps to Cyber Security – https://www.ncsc.gov.uk/collection/10-steps
- National Cyber Security Centre – Multi-Factor Authentication for Your Corporate Online Services – https://www.ncsc.gov.uk/guidance/multi-factor-authentication-online-services
Image credit: https://unsplash.com/photos/a-fishing-hook-hanging-from-the-side-of-a-boat-Fl3Rf_t8dMs



