What is a phishing simulation?

A phishing simulation is a safe, fake phishing email sent to staff to test their response. How it works, what it measures and why it matters in 2026.

A phishing simulation is a fake phishing email, deliberately sent to your own staff, that mirrors a real attack and records how each person responds: whether they click the link, hand over credentials, or report it. It is the practice half of security awareness training — the lesson teaches what phishing looks like, and the simulation shows whether the lesson stuck. Run monthly and paired with a two-minute coaching moment for anyone who clicks, it is the control behind most of the click-rate improvement security programmes report.

What is a phishing simulation?

A simulation borrows every trick a real phisher uses, then wraps it in safety. Staff receive an email in their normal inbox; nothing malicious sits on the other end of the link, and every interaction is logged against the campaign, not held against the person.

ElementWhat staff seeWhat it tests
Sender addressA lookalike domain or a spoofed internal nameSender-checking habits
The lureInvoice reminder, shared document, MFA prompt, delivery noticeRecognition of the pretexts in use this year
The link or attachmentA button to a safe landing page, or a harmless fileReflexes in the seconds before clicking
The landing pageA fake login screen or an explainer pageWhether credentials would have been handed over
The report pathA report button or a forwarding routineWhether the reporting habit exists

The point is measurement, not blame. Click data shows where the programme is working; report data shows the reflex you are actually trying to build. Cyber Aware's phishing simulations record both numbers per person and roll them into human risk reporting, so a manager sees one trend line per team instead of a spreadsheet of campaign results.

The lures that work in 2026

Realistic campaigns copy the emails staff actually receive that week:

Mixing lure types each month matters more than difficulty. A team that only sees obvious fakes learns to spot obvious fakes.

How a phishing simulation runs, step by step

  1. Plan the campaign. Choose one or two lure types that match the attacks your team actually faces, and set the send window.
  2. Send to everyone — or a segment. Deliveries stagger over hours so results reflect individual judgement, not corridor warnings.
  3. Track the two numbers. Who clicked, and who reported. Both matter; the second matters more as the programme matures.
  4. Coach immediately. Anyone who clicks lands on a short teachable page explaining the tells they missed — security awareness training covers the same material in its monthly lessons, so the click and the lesson reinforce each other.
  5. Report and repeat. Results go into the monthly report, and the next campaign rotates the lure.

What good results look like

Benchmark data cited across the industry shows about a third of untrained staff click a simulated phishing email, falling to 4-5% after twelve months of monthly training and simulation. Report rates climb past 20% as the habit forms. Two trends tell you whether your programme is working: click rate falling month over month, and report rate rising. A single campaign in isolation proves almost nothing — one well-crafted lure catches anyone.

Phishing simulation vs a real phishing attack

SimulationReal attack
TechniquesIdentical: spoofed senders, urgency, lookalike pagesIdentical
DestinationA safe landing or explainer pageCredential theft or malware
OutcomeA logged data pointAn incident, often a payment
Follow-upImmediate coachingResponse plan, password resets, disclosure

The similarity is the point. If the simulation feels routine and slightly boring, staff are ready; if it catches people, it caught them before the real one did.

Are phishing simulations legal in Australia?

Yes, when run as a training exercise. The defensible design is consistent across programmes: tell staff a simulation programme exists (without pre-announcing the exact send), keep consequences coaching-first, and never treat a single click as misconduct. A no-blame design also protects the reporting culture the entire control depends on — staff who fear punishment stop reporting, and an unreported real phish costs far more than a clicked simulation.

How often should you run one?

Monthly is the standard for small teams, and the cadence the published click-rate reductions are measured on. Quarterly is the practical floor below which memory decay wins. New starters are the exception: give them a baseline simulation in their first weeks, before habits form.

Who runs the simulations?

Two models exist. Self-serve platforms put the calendar in your hands: pick lures, set the send, read the report — realistic for a small team without IT staff. Managed delivery (through an MSP or the platform itself) removes the work entirely and suits businesses that want the programme to simply happen. Either way the mechanics stay the same; only ownership of the calendar changes.

FAQ

What is a phishing simulation in one sentence? A safe, fake phishing email sent to staff to test whether they click, report or fall for it, with coaching attached to every outcome.

Can a simulation steal real credentials? No. Landing pages are harmless by design, and anything typed into a simulated page is discarded — which is also why staff should never enter real passwords anywhere they cannot verify.

Will staff feel tricked or embarrassed? Handled well, no. Immediate, blame-free coaching turns the click into the lesson, and the report rate — not a shame list — is the number worth celebrating.

How many emails go out per campaign? One or two lures per month is enough for most teams; more risks fatigue and trains staff to expect tests rather than spot real ones.

Do simulations work on technically skilled staff? Yes, with harder lures. Technical staff click realistic pretexts at close to the same rate as everyone else — the lures just need to be built for them.

What happens after someone clicks? A short coaching page, an optional two-minute module, and the click logged as a data point. The next campaign measures whether the lesson landed.

Related guides

Ready to deploy

Same playbook.
Your brand.

Cyber Aware's Human Risk Score works the same way for every MSP partner - under your brand, on your cadence.