How to run a phishing simulation: complete 2026 guide

How to run a phishing simulation in 2026: baseline tests, realistic templates, whitelisting, coaching clickers and the click and report rates to expect.

A phishing simulation is a harmless fake phishing email sent to your own staff to test whether they click, delete or report it - and to coach the ones who click. Run one at least monthly: the benchmark data shows organisations that train and test monthly cut the share of staff who fall for phishing from 33.2% to 4.2% within twelve months (KnowBe4, 2026).

TL;DR

What a phishing simulation actually is

A phishing simulation sends an email that looks like a real lure - a payroll update, a shared document, an invoice - through your own email system to your own staff. Nothing malicious sits behind the link: clicking lands on a benign page that records the click and immediately shows a short coaching message. The output is three numbers: who clicked, who reported, and how fast.

It matters because roughly 60% of breaches involve a human element (Verizon, 2025 DBIR), and the average Australian small business now loses $56,571 per cybercrime incident (ASD, Annual Cyber Threat Report 2024-25). You cannot fix what you never measure.

Step 1: run a baseline test

Before any training, send one simulation to everyone. This is your starting number. KnowBe4's 2026 benchmarking report puts the global pre-training average at 33.2% - one in three staff likely to engage with a malicious email. Your own baseline will differ, and that is the point: every later improvement is measured against it.

Step 2: pick realistic templates

Use lures your staff would genuinely receive:

Avoid comically obvious lures - misspelled Nigerian princes teach nothing. Modern attacks are ordinary-looking; your test should be too. Rotate templates monthly so nobody learns to recognise one specific email.

Step 3: whitelist the simulation domain

Ask your email administrator to allow-list the simulation sender before launch. If the filter silently quarantines your own test, you will read a 0% click rate that means nothing - one of the most common ways programmes produce false comfort.

Step 4: coach clickers immediately

The moment someone clicks, show a short page: what gave it away, what to check next time. Follow with a 2-minute micro-module. Never name, shame, fine or performance-manage clickers - punishment teaches staff to hide real clicks, which is the most expensive outcome a programme can produce. Reporters get a thank-you; speed of reporting is the behaviour you are building.

Step 5: repeat monthly and track the trend

A single test is a snapshot; the programme is the trend. The benchmark trajectory at monthly cadence:

StageClick-prone share
Baseline (no training)33.2%
After 90 days20.1%
After 12 months4.2%

Two numbers to track every month: click rate (falling) and report rate (rising). A rising report rate with a flat click rate is still progress - it means staff are flagging lures even when they hover. Roll both into the monthly human risk reporting score your leadership sees.

Common mistakes

FAQ

How often should we run a phishing simulation? Monthly at minimum. Monthly testing plus monthly micro-training is the cadence behind the benchmark 33.2% to 4.2% trajectory.

Is it legal to phish your own employees? Yes, when it is your own staff, the lures are harmless, data is handled per your privacy policy, and the purpose is training rather than entrapment. Tell staff simulations exist and that reporting is always rewarded.

What click rate should we expect at the start? The global benchmark is 33.2%, but small organisations often start lower (24.7% under 250 staff) and enterprises higher (39.5% over 10,000 staff). Your own baseline is the number that matters.

Should repeat clickers be disciplined? No. Coach them with targeted content instead - repeated clicking signals a learning gap, not insubordination.

What do we do with the results? Feed click rate, report rate and repeat-clicker counts into a monthly score - see human risk reporting - and adjust next month's templates toward the departments with the highest click concentration.

Related guides

Ready to deploy

Same playbook.
Your brand.

Cyber Aware's Human Risk Score works the same way for every MSP partner - under your brand, on your cadence.