A phishing simulation is a fake phishing email, deliberately sent to your own staff, that mirrors a real attack and records how each person responds: whether they click the link, hand over credentials, or report it. It is the practice half of security awareness training — the lesson teaches what phishing looks like, and the simulation shows whether the lesson stuck. Run monthly and paired with a two-minute coaching moment for anyone who clicks, it is the control behind most of the click-rate improvement security programmes report.
What is a phishing simulation?
A simulation borrows every trick a real phisher uses, then wraps it in safety. Staff receive an email in their normal inbox; nothing malicious sits on the other end of the link, and every interaction is logged against the campaign, not held against the person.
| Element | What staff see | What it tests |
|---|---|---|
| Sender address | A lookalike domain or a spoofed internal name | Sender-checking habits |
| The lure | Invoice reminder, shared document, MFA prompt, delivery notice | Recognition of the pretexts in use this year |
| The link or attachment | A button to a safe landing page, or a harmless file | Reflexes in the seconds before clicking |
| The landing page | A fake login screen or an explainer page | Whether credentials would have been handed over |
| The report path | A report button or a forwarding routine | Whether the reporting habit exists |
The point is measurement, not blame. Click data shows where the programme is working; report data shows the reflex you are actually trying to build. Cyber Aware's phishing simulations record both numbers per person and roll them into human risk reporting, so a manager sees one trend line per team instead of a spreadsheet of campaign results.
The lures that work in 2026
Realistic campaigns copy the emails staff actually receive that week:
- Invoice and payment-change requests — the fraud that hits finance teams hardest.
- Fake Microsoft 365 or Google login pages — shared-document notifications leading to a credential lookalike.
- MFA approval prompts — testing whether staff approve a prompt they did not trigger.
- Delivery, toll and government notices — everyday messages nobody expects to be suspicious.
- Executive requests — a gift-card or urgent-payment ask that tests the deference reflex.
Mixing lure types each month matters more than difficulty. A team that only sees obvious fakes learns to spot obvious fakes.
How a phishing simulation runs, step by step
- Plan the campaign. Choose one or two lure types that match the attacks your team actually faces, and set the send window.
- Send to everyone — or a segment. Deliveries stagger over hours so results reflect individual judgement, not corridor warnings.
- Track the two numbers. Who clicked, and who reported. Both matter; the second matters more as the programme matures.
- Coach immediately. Anyone who clicks lands on a short teachable page explaining the tells they missed — security awareness training covers the same material in its monthly lessons, so the click and the lesson reinforce each other.
- Report and repeat. Results go into the monthly report, and the next campaign rotates the lure.
What good results look like
Benchmark data cited across the industry shows about a third of untrained staff click a simulated phishing email, falling to 4-5% after twelve months of monthly training and simulation. Report rates climb past 20% as the habit forms. Two trends tell you whether your programme is working: click rate falling month over month, and report rate rising. A single campaign in isolation proves almost nothing — one well-crafted lure catches anyone.
Phishing simulation vs a real phishing attack
| Simulation | Real attack | |
|---|---|---|
| Techniques | Identical: spoofed senders, urgency, lookalike pages | Identical |
| Destination | A safe landing or explainer page | Credential theft or malware |
| Outcome | A logged data point | An incident, often a payment |
| Follow-up | Immediate coaching | Response plan, password resets, disclosure |
The similarity is the point. If the simulation feels routine and slightly boring, staff are ready; if it catches people, it caught them before the real one did.
Are phishing simulations legal in Australia?
Yes, when run as a training exercise. The defensible design is consistent across programmes: tell staff a simulation programme exists (without pre-announcing the exact send), keep consequences coaching-first, and never treat a single click as misconduct. A no-blame design also protects the reporting culture the entire control depends on — staff who fear punishment stop reporting, and an unreported real phish costs far more than a clicked simulation.
How often should you run one?
Monthly is the standard for small teams, and the cadence the published click-rate reductions are measured on. Quarterly is the practical floor below which memory decay wins. New starters are the exception: give them a baseline simulation in their first weeks, before habits form.
Who runs the simulations?
Two models exist. Self-serve platforms put the calendar in your hands: pick lures, set the send, read the report — realistic for a small team without IT staff. Managed delivery (through an MSP or the platform itself) removes the work entirely and suits businesses that want the programme to simply happen. Either way the mechanics stay the same; only ownership of the calendar changes.
FAQ
What is a phishing simulation in one sentence? A safe, fake phishing email sent to staff to test whether they click, report or fall for it, with coaching attached to every outcome.
Can a simulation steal real credentials? No. Landing pages are harmless by design, and anything typed into a simulated page is discarded — which is also why staff should never enter real passwords anywhere they cannot verify.
Will staff feel tricked or embarrassed? Handled well, no. Immediate, blame-free coaching turns the click into the lesson, and the report rate — not a shame list — is the number worth celebrating.
How many emails go out per campaign? One or two lures per month is enough for most teams; more risks fatigue and trains staff to expect tests rather than spot real ones.
Do simulations work on technically skilled staff? Yes, with harder lures. Technical staff click realistic pretexts at close to the same rate as everyone else — the lures just need to be built for them.
What happens after someone clicks? A short coaching page, an optional two-minute module, and the click logged as a data point. The next campaign measures whether the lesson landed.