What is a phishing simulation? How it works and how to run one in 2026

What a phishing simulation is, how the click and report data works, and how to run monthly campaigns that cut click rates into single digits in 2026.

A phishing simulation is a safe, deliberate fake attack sent to your own staff: an email that looks like a real invoice, delivery notice or IT alert, built to test whether people click or report. This guide explains how simulations work, what a first campaign should look like and which numbers tell you it is working.

TL;DR

What a phishing simulation actually does

A phishing simulation is a controlled test. Your security tooling sends an email that imitates the lures attackers really use — a fake supplier invoice, a myGov renewal, a shared-document notification, an IT help desk reply — to a defined group of staff. The message links to a safe landing page: no malware, no credentials collected, nothing that leaves your control.

Every interaction is logged:

Those four data points per person per campaign are what turn security training from a checkbox into a measurable programme.

Why simulate at all

Email filters catch most phishing, but the messages that reach an inbox are the ones written to defeat filters — and every one of them ends with a human decision. Verizon's 2025 Data Breach Investigations Report, the 18th annual edition, analysed 22,052 real-world security incidents and 12,195 confirmed breaches and again placed a human element in roughly 60% of breaches. The Australian picture is no softer: ASD's Australian Cyber Security Centre logged more than 84,700 cybercrime reports in FY2024-25 — one every six minutes — with average self-reported costs of $56,600 for small businesses and $97,200 for medium ones.

Training alone tells people what to look for. Simulation shows whether they look for it under pressure, on a busy Tuesday, in the inbox where they actually work.

How to run your first simulation

  1. Baseline before you announce. Send one moderately difficult lure before the awareness programme starts. The honest starting click rate is the number every later improvement is measured against.
  2. Start simple. First campaigns should be obviously identifiable once you look: odd sender domain, generic greeting, urgency without detail. Save sophisticated spoofing for later months.
  3. Escalate as report rates climb. Monthly difficulty tiers — from plain lures to personalised ones — keep the test honest as staff improve.
  4. Coach instantly. Anyone who clicks lands in a two-minute lesson about that specific lure the same day. Never name and shame; punishing clicks kills reporting, and reporting is the habit you are building.
  5. Rotate themes. Invoice fraud, delivery scams, government renewals, help desk impersonation — rotate so staff learn to judge, not memorise one template.

Cyber Aware's phishing simulations run on exactly this pattern: scheduled monthly campaigns with escalating difficulty, automatic enrolment of clickers into a follow-up lesson, and clickers and reporters both logged per person.

What the numbers mean

MetricWhat it tells youGood signal after 6-12 months
Click rateWho falls for a fake attackSingle digits
Report rateWho flags the messageAbove 50%
Time to first reportHow fast someone raises the alarmMinutes, not hours
Repeat clickersWho needs extra coachingA shrinking short list
Follow-up completionWhether the coaching landsNear 100%

Report rate deserves special attention. A falling click rate with a flat report rate can mean staff are quietly ignoring email rather than judging it — which is not a win, because a real attack that is reported in minutes can be pulled from every other inbox before a second person clicks. Human risk reporting turns these per-person results into a score you can trend month over month.

Common objections

Is it fair to trick my own staff? Done well, yes. The simulation is safe, the coaching is instant and non-punitive, and the first campaign is easy. Staff experience it as practice, not entrapment. A clear note in the staff handbook about awareness testing removes any surprise.

Will it look bad if the results are poor? Poor results are the point of the first campaign — you cannot fix what you never measured. Baselines commonly sit at 30% or more clicks and fall into single digits within a year of monthly cadence.

Do simulations actually stop real attacks? They change the behaviour that real attacks exploit: fewer clicks, faster reports. They work alongside email filtering and MFA, not instead of them — a relay kit that defeats the filter still has to defeat a trained human.

How often should we send them? Monthly. A single annual test decays before it builds anything; monthly cadence plus instant coaching is what moves the metrics.

Where simulations fit in the programme

A simulation is the testing half of awareness training, not a standalone product. The teaching half — short monthly lessons — carries the knowledge, and the simulation measures whether it held. Running them on the same platform keeps the loop closed: click, lesson, better next month.

If you are comparing vendors for the whole programme rather than the simulation alone, the comparison page puts them side by side, and a security gap assessment tells you whether training or a technical control deserves the next dollar.

FAQ

What is a phishing simulation? A controlled fake attack sent to your own staff to measure whether they click, report or ignore — logged per person and used to drive instant coaching.

Is it safe? Yes. Simulation links lead to a safe landing page — no malware, no real credentials captured — and the campaign is fully controlled by you.

What click rate should we expect? First campaigns commonly land near 30% or higher; monthly programmes typically reach single digits within a year.

Who should be included? Everyone with a mailbox, including executives and contractors. New starters should be enrolled in their first week.

Can we use the results in performance reviews? Resist it. The moment clicks are punished, reporting stops — and a silent clicker is exactly the person a real attacker wants. Use results for coaching, not discipline.

One last thing

Send the baseline campaign before you announce anything. Every number you report to a board in 2026 — click rate, report rate, risk score — is only meaningful against an honest starting point.

Related guides

Ready to deploy

Same playbook.
Your brand.

Cyber Aware's Human Risk Score works the same way for every MSP partner - under your brand, on your cadence.