Phishing simulations promise a simple story: keep sending fake phishes, and staff stop falling for real ones. The honest answer sits between the vendor pitch and the cynic's eye-roll. Simulations do not block a single real email from arriving — that is what email filtering and multi-factor authentication are for. What they do change is what happens in the ninety seconds after a real phishing email lands in a human inbox, and those ninety seconds decide most small-business breaches.
TL;DR
- Simulations train two behaviours that stop real attacks: spotting the phish, and reporting it fast enough for IT to act.
- They work through repetition, not revelation — one campaign does almost nothing, a quarterly cadence measurably does.
- Click rates are the vanity metric; report rate and time-to-report are the ones that contain incidents.
- Simulations cannot fix bad process: if payment changes are approved by email alone, no amount of training saves you.
- Attack realism matters — generic templates build generic immunity that evaporates against a targeted spear phish.
What a phishing simulation actually does
A phishing simulation is a controlled fake: a realistic email sent to your own staff, with a tracking link instead of a malicious one. When someone clicks, the platform records it and usually serves a short teachable moment on the spot. When someone reports it, that gets recorded too.
The point is not to catch people out. It is rehearsal. Reading a policy document about phishing builds knowledge; being handed a convincing fake invoice on a Tuesday afternoon builds reflex. The Australian Signals Directorate's threat guidance Small Business Cyber Security Guide lists email attacks such as phishing among the most common threats to small businesses, and the human layer is the one control that no firewall config can replace — which is exactly why rehearsal matters.
There is a second, underrated effect: simulated phishes keep phishing salient. Staff who clicked a fake delivery notice last month read the real one next month with slightly more suspicion. That priming effect decays, which is why one-off tests do almost nothing and repetition does the work.
The evidence: what changes and what doesn't
Here is what programs consistently show, and what they don't.
What improves. Click rates on repeated simulation campaigns decline over the first few cycles for most organisations, and reporting rates climb. The reporting shift is the valuable one: a staff member who forwards a suspicious invoice to IT in three minutes turns a potential payment fraud into a five-minute investigation. The ACSC's threat reporting year after year shows business email compromise remains a top-cost attack for Australian small businesses, and BEC is exactly the attack a fast internal report disrupts — the fraudster's window closes the moment someone phones the supplier to verify the bank details.
What doesn't improve. Simulations do not stop the email from arriving. They do not patch a spoofed domain, and they do nothing against an attacker who calls staff on the phone instead. They also don't fix process gaps: if your finance team changes supplier bank details because an email asked them to, the failure is approval process, not awareness. Training supports a verification step; it cannot be the verification step.
What separates programs that work from ones that don't
The same platform produces opposite outcomes depending on how it's run.
Cadence over intensity. Monthly or quarterly short campaigns beat one annual surprise test. New starters are the biggest exposure window — onboarding simulation from day one, not at the next company-wide cycle.
Realism matched to your risk. Templates should mirror the emails your staff actually receive: invoices from your accounting software, courier notices, shared-document alerts, HR payroll updates. Generic templates from a template library build generic immunity. A finance team rehearsed on fake invoices is exactly the team that pauses before a real one.
No-punishment reporting. If clicking a simulation means trouble, staff learn to conceal. If reporting a suspicious email earns visible thanks, staff report more — including real ones. The programs with the best outcomes are almost always the ones where reporting a simulation is treated as a win.
Follow-through on the click. A click without follow-up training is a data point wasted. The platforms that work serve immediate micro-training, and the ones that work best escalate repeat clickers to targeted coaching rather than to HR.
Measuring whether it's working
Track four numbers across consecutive campaigns — a single campaign is noise:
- Click rate and its trend across campaigns.
- Report rate: the share of simulated phishes reported by staff. Rising is the signal that matters.
- Time to report: minutes from send to report.
- Repeat clickers: a small group usually accounts for a large share of clicks; name the coaching, not the shame.
Those numbers, plus completion records, are what a board, an insurer or an auditor actually inspect — which is the point of structured human risk reporting rather than screenshots in a slide deck.
FAQ
Do phishing simulations actually reduce real-world clicks? They reduce clicks on the patterns staff have rehearsed, and they raise reporting rates across the board. The effect is strongest when campaigns repeat on a cadence and use realistic templates.
Isn't tricking staff unfair or bad for morale? Framing decides this. Run as a silent trap, it breeds resentment and hidden clicks. Run openly — announced program, no punishment, reporting celebrated — it builds the habit without the bitterness.
How often should we run simulations? Monthly is the research-backed ceiling; quarterly is the practical floor most small businesses sustain. Below quarterly, the priming effect fades between campaigns.
What if a staff member clicks a simulation repeatedly? Treat it as a coaching signal: extra targeted modules, a check of their mailbox security settings, and in some cases a role-based risk review. Discipline reliably produces concealment instead of reporting.
Can simulations replace email filtering and MFA? No. Filtering stops most phishing before a human sees it, and multi-factor authentication limits the damage of a stolen password. Simulations cover the residual attacks that reach a person — which is still a meaningful share.
Do simulations work against spear phishing? Only if the templates are targeted too. A generic campaign does little against a personalised attack on your finance team; that audience needs scenario-specific rehearsal, like fake CEO payment requests.
One last thing
Simulations stop real attacks the way fire drills stop fires: not directly, but by making the human response fast and automatic when the real thing happens. A team with a low click rate and a fast report rate contains most phishing incidents in minutes. A team that has never rehearsed finds out when the money has already moved.