A phishing simulation is a safe, deliberate fake attack sent to your own staff: an email that looks like a real invoice, delivery notice or IT alert, built to test whether people click or report. This guide explains how simulations work, what a first campaign should look like and which numbers tell you it is working.
TL;DR
- A phishing simulation sends realistic fake attacks to your own staff and measures clicks, reports and completion of follow-up lessons.
- Verizon's 2025 Data Breach Investigations Report analysed 22,052 incidents and 12,195 confirmed breaches and again found a human element in roughly 60% of breaches (full report PDF) — the behaviour simulations rehearse.
- Run one campaign per month: baseline first, escalate difficulty as report rates climb, coach clickers with a short lesson the same day.
- The numbers that matter are click rate (down), report rate (up) and time to first report (down).
- ASD received more than 84,700 cybercrime reports in FY2024-25, one every six minutes; the average self-reported cost was $56,600 for a small business (ASD Annual Cyber Threat Report 2024-25).
What a phishing simulation actually does
A phishing simulation is a controlled test. Your security tooling sends an email that imitates the lures attackers really use — a fake supplier invoice, a myGov renewal, a shared-document notification, an IT help desk reply — to a defined group of staff. The message links to a safe landing page: no malware, no credentials collected, nothing that leaves your control.
Every interaction is logged:
- Opened — the recipient saw the message.
- Clicked — the recipient followed the link, which is the moment a real attack would have succeeded.
- Entered data — a small number of tools track whether credentials were typed into the fake page.
- Reported — the recipient used the phishing report button, which is the outcome you actually want.
Those four data points per person per campaign are what turn security training from a checkbox into a measurable programme.
Why simulate at all
Email filters catch most phishing, but the messages that reach an inbox are the ones written to defeat filters — and every one of them ends with a human decision. Verizon's 2025 Data Breach Investigations Report, the 18th annual edition, analysed 22,052 real-world security incidents and 12,195 confirmed breaches and again placed a human element in roughly 60% of breaches. The Australian picture is no softer: ASD's Australian Cyber Security Centre logged more than 84,700 cybercrime reports in FY2024-25 — one every six minutes — with average self-reported costs of $56,600 for small businesses and $97,200 for medium ones.
Training alone tells people what to look for. Simulation shows whether they look for it under pressure, on a busy Tuesday, in the inbox where they actually work.
How to run your first simulation
- Baseline before you announce. Send one moderately difficult lure before the awareness programme starts. The honest starting click rate is the number every later improvement is measured against.
- Start simple. First campaigns should be obviously identifiable once you look: odd sender domain, generic greeting, urgency without detail. Save sophisticated spoofing for later months.
- Escalate as report rates climb. Monthly difficulty tiers — from plain lures to personalised ones — keep the test honest as staff improve.
- Coach instantly. Anyone who clicks lands in a two-minute lesson about that specific lure the same day. Never name and shame; punishing clicks kills reporting, and reporting is the habit you are building.
- Rotate themes. Invoice fraud, delivery scams, government renewals, help desk impersonation — rotate so staff learn to judge, not memorise one template.
Cyber Aware's phishing simulations run on exactly this pattern: scheduled monthly campaigns with escalating difficulty, automatic enrolment of clickers into a follow-up lesson, and clickers and reporters both logged per person.
What the numbers mean
| Metric | What it tells you | Good signal after 6-12 months |
|---|---|---|
| Click rate | Who falls for a fake attack | Single digits |
| Report rate | Who flags the message | Above 50% |
| Time to first report | How fast someone raises the alarm | Minutes, not hours |
| Repeat clickers | Who needs extra coaching | A shrinking short list |
| Follow-up completion | Whether the coaching lands | Near 100% |
Report rate deserves special attention. A falling click rate with a flat report rate can mean staff are quietly ignoring email rather than judging it — which is not a win, because a real attack that is reported in minutes can be pulled from every other inbox before a second person clicks. Human risk reporting turns these per-person results into a score you can trend month over month.
Common objections
Is it fair to trick my own staff? Done well, yes. The simulation is safe, the coaching is instant and non-punitive, and the first campaign is easy. Staff experience it as practice, not entrapment. A clear note in the staff handbook about awareness testing removes any surprise.
Will it look bad if the results are poor? Poor results are the point of the first campaign — you cannot fix what you never measured. Baselines commonly sit at 30% or more clicks and fall into single digits within a year of monthly cadence.
Do simulations actually stop real attacks? They change the behaviour that real attacks exploit: fewer clicks, faster reports. They work alongside email filtering and MFA, not instead of them — a relay kit that defeats the filter still has to defeat a trained human.
How often should we send them? Monthly. A single annual test decays before it builds anything; monthly cadence plus instant coaching is what moves the metrics.
Where simulations fit in the programme
A simulation is the testing half of awareness training, not a standalone product. The teaching half — short monthly lessons — carries the knowledge, and the simulation measures whether it held. Running them on the same platform keeps the loop closed: click, lesson, better next month.
If you are comparing vendors for the whole programme rather than the simulation alone, the comparison page puts them side by side, and a security gap assessment tells you whether training or a technical control deserves the next dollar.
FAQ
What is a phishing simulation? A controlled fake attack sent to your own staff to measure whether they click, report or ignore — logged per person and used to drive instant coaching.
Is it safe? Yes. Simulation links lead to a safe landing page — no malware, no real credentials captured — and the campaign is fully controlled by you.
What click rate should we expect? First campaigns commonly land near 30% or higher; monthly programmes typically reach single digits within a year.
Who should be included? Everyone with a mailbox, including executives and contractors. New starters should be enrolled in their first week.
Can we use the results in performance reviews? Resist it. The moment clicks are punished, reporting stops — and a silent clicker is exactly the person a real attacker wants. Use results for coaching, not discipline.
One last thing
Send the baseline campaign before you announce anything. Every number you report to a board in 2026 — click rate, report rate, risk score — is only meaningful against an honest starting point.