What is a phishing simulation and how does it work?

A phishing simulation sends staff safe fake phishing emails to test and train them. How it works, what it measures and how to run one well in 2026.

A phishing simulation is a safe, fake phishing email sent to your own staff to test whether they spot it, then used to train them. Staff who click get a short explainer and follow-up course, staff who report or ignore it get praise, and the results show you where your real risk sits.

TL;DR

What is a phishing simulation?

A phishing simulation imitates the emails attackers send, such as an invoice awaiting approval, a password expiry notice or a tax refund, but the sender is you. Nobody is harmed. The point is to measure behaviour and teach in the moment.

The starting point is often worse than leaders expect. KnowBe4's 2026 Phishing by Industry Benchmarking Report found a global average baseline of 33.2%, meaning roughly one in three employees is likely to engage with a malicious email before training. After a full year of continuous training the same report puts the figure at 4.2%.

How does a phishing simulation work?

  1. Choose a template and a group. Pick a scenario, such as a Xero invoice or a Google password expiry, and the staff who will receive it.
  2. Send it. The email arrives like any other.
  3. Record the outcome. The platform logs who clicked and who reported it.
  4. Coach. Clickers land on a branded explainer showing the red flags and are enrolled in a short follow-up course.
  5. Report. Admins get results, trends and a PDF summary.

Cyber Aware's phishing simulations work this way, with 100+ templates, difficulty levels from easy to hard to detect, and no credential harvesting. Auto Phish can also build a year of campaigns from one chat about which services the team uses.

What does a phishing simulation measure?

MeasureWhat it tells you
Click rateHow many staff would have fallen for the email
Report rateHow many staff flagged it, which is the behaviour you want
Repeat failuresWho needs extra support
Trend over timeWhether training is working

Report rate matters as much as click rate. A staff member who reports a phish protects everyone else, and a report button in Outlook or Gmail makes that easy.

Are phishing simulations legal and fair?

In Australia, simulations are legal, but workplace surveillance rules in some states call for notice and a no-blame design. The details are in our legal guide, linked below. A no-blame approach also keeps staff reporting.

Why run phishing simulations at all?

Cyber Aware states that its customers see an average 80% reduction in clicked links within eight months. That is the vendor's own figure, so check it against your own results.

How do you run a phishing simulation well?

FAQ

What is a phishing simulation? A safe fake phishing email sent to your own staff to measure who clicks and who reports, followed by coaching.

Do phishing simulations capture passwords? Not with Cyber Aware: reporting shows who clicked and who reported, with no credential harvesting.

How often should phishing simulations run? At least monthly, with varied templates, so staff learn the behaviour rather than one example.

What happens when someone clicks? They see a branded explainer and are enrolled in a follow-up course automatically.

Are phishing simulations effective? KnowBe4's 2026 data shows susceptibility falling from 33.2% to 4.2% after a year of continuous training and testing.

One last thing

Celebrate the reports. The best metric is not a low click rate on its own but a rising report rate. Staff who tell you about a suspicious email, simulated or real, are your fastest detection system.

Related guides

Ready to deploy

Same playbook.
Your brand.

Cyber Aware's Human Risk Score works the same way for every MSP partner - under your brand, on your cadence.