A phishing simulation is a harmless fake phishing email sent to your own staff to test whether they click, delete or report it - and to coach the ones who click. Run one at least monthly: the benchmark data shows organisations that train and test monthly cut the share of staff who fall for phishing from 33.2% to 4.2% within twelve months (KnowBe4, 2026).
TL;DR
- A simulation is a controlled drill, not a trap - the goal is a report reflex, not a click count.
- Always run a baseline test first, before any training, so improvement numbers mean something.
- Use realistic templates (payroll, document share, help desk) and never punish clickers.
- Whitelist the simulation domain so filters do not silently eat your own test.
- Expect the click-prone share to drop about 40% in the first 90 days; the full effect takes twelve months.
What a phishing simulation actually is
A phishing simulation sends an email that looks like a real lure - a payroll update, a shared document, an invoice - through your own email system to your own staff. Nothing malicious sits behind the link: clicking lands on a benign page that records the click and immediately shows a short coaching message. The output is three numbers: who clicked, who reported, and how fast.
It matters because roughly 60% of breaches involve a human element (Verizon, 2025 DBIR), and the average Australian small business now loses $56,571 per cybercrime incident (ASD, Annual Cyber Threat Report 2024-25). You cannot fix what you never measure.
Step 1: run a baseline test
Before any training, send one simulation to everyone. This is your starting number. KnowBe4's 2026 benchmarking report puts the global pre-training average at 33.2% - one in three staff likely to engage with a malicious email. Your own baseline will differ, and that is the point: every later improvement is measured against it.
Step 2: pick realistic templates
Use lures your staff would genuinely receive:
- Payroll or HR notifications (password reset, payslip available).
- Document shares and e-signature requests.
- IT help desk replies and MFA expiry warnings.
- Invoice and payment notifications for finance staff.
Avoid comically obvious lures - misspelled Nigerian princes teach nothing. Modern attacks are ordinary-looking; your test should be too. Rotate templates monthly so nobody learns to recognise one specific email.
Step 3: whitelist the simulation domain
Ask your email administrator to allow-list the simulation sender before launch. If the filter silently quarantines your own test, you will read a 0% click rate that means nothing - one of the most common ways programmes produce false comfort.
Step 4: coach clickers immediately
The moment someone clicks, show a short page: what gave it away, what to check next time. Follow with a 2-minute micro-module. Never name, shame, fine or performance-manage clickers - punishment teaches staff to hide real clicks, which is the most expensive outcome a programme can produce. Reporters get a thank-you; speed of reporting is the behaviour you are building.
Step 5: repeat monthly and track the trend
A single test is a snapshot; the programme is the trend. The benchmark trajectory at monthly cadence:
| Stage | Click-prone share |
|---|---|
| Baseline (no training) | 33.2% |
| After 90 days | 20.1% |
| After 12 months | 4.2% |
Two numbers to track every month: click rate (falling) and report rate (rising). A rising report rate with a flat click rate is still progress - it means staff are flagging lures even when they hover. Roll both into the monthly human risk reporting score your leadership sees.
Common mistakes
- Testing quarterly or less. The published improvement figures all come from monthly-or-better cadence.
- Making the simulation a HR event. If clickers fear consequences, real clicks go unreported.
- Running simulations without training. Testing alone plateaus; the 4.2% figure comes from training plus testing together.
- Cherry-picking easy lures. If every template is trivially obvious, you measure nothing about real risk.
FAQ
How often should we run a phishing simulation? Monthly at minimum. Monthly testing plus monthly micro-training is the cadence behind the benchmark 33.2% to 4.2% trajectory.
Is it legal to phish your own employees? Yes, when it is your own staff, the lures are harmless, data is handled per your privacy policy, and the purpose is training rather than entrapment. Tell staff simulations exist and that reporting is always rewarded.
What click rate should we expect at the start? The global benchmark is 33.2%, but small organisations often start lower (24.7% under 250 staff) and enterprises higher (39.5% over 10,000 staff). Your own baseline is the number that matters.
Should repeat clickers be disciplined? No. Coach them with targeted content instead - repeated clicking signals a learning gap, not insubordination.
What do we do with the results? Feed click rate, report rate and repeat-clicker counts into a monthly score - see human risk reporting - and adjust next month's templates toward the departments with the highest click concentration.