A phishing simulation is a safe, fake phishing email sent to your own staff to test whether they spot it, then used to train them. Staff who click get a short explainer and follow-up course, staff who report or ignore it get praise, and the results show you where your real risk sits.
TL;DR
- A phishing simulation tests behaviour by sending realistic fake phishing emails to staff.
- KnowBe4's 2026 benchmark puts the global baseline at 33.2% of employees likely to engage with a phishing email before training.
- Good simulations record who clicked and who reported, with no credential harvesting.
- Clickers should be enrolled in remediation training automatically.
- Run simulations all year with varied templates, not once.
What is a phishing simulation?
A phishing simulation imitates the emails attackers send, such as an invoice awaiting approval, a password expiry notice or a tax refund, but the sender is you. Nobody is harmed. The point is to measure behaviour and teach in the moment.
The starting point is often worse than leaders expect. KnowBe4's 2026 Phishing by Industry Benchmarking Report found a global average baseline of 33.2%, meaning roughly one in three employees is likely to engage with a malicious email before training. After a full year of continuous training the same report puts the figure at 4.2%.
How does a phishing simulation work?
- Choose a template and a group. Pick a scenario, such as a Xero invoice or a Google password expiry, and the staff who will receive it.
- Send it. The email arrives like any other.
- Record the outcome. The platform logs who clicked and who reported it.
- Coach. Clickers land on a branded explainer showing the red flags and are enrolled in a short follow-up course.
- Report. Admins get results, trends and a PDF summary.
Cyber Aware's phishing simulations work this way, with 100+ templates, difficulty levels from easy to hard to detect, and no credential harvesting. Auto Phish can also build a year of campaigns from one chat about which services the team uses.
What does a phishing simulation measure?
| Measure | What it tells you |
|---|---|
| Click rate | How many staff would have fallen for the email |
| Report rate | How many staff flagged it, which is the behaviour you want |
| Repeat failures | Who needs extra support |
| Trend over time | Whether training is working |
Report rate matters as much as click rate. A staff member who reports a phish protects everyone else, and a report button in Outlook or Gmail makes that easy.
Are phishing simulations legal and fair?
In Australia, simulations are legal, but workplace surveillance rules in some states call for notice and a no-blame design. The details are in our legal guide, linked below. A no-blame approach also keeps staff reporting.
Why run phishing simulations at all?
- They test behaviour, not knowledge. Staff can pass a quiz and still click.
- They show real risk. You get a measured click rate, not a guess.
- They train at the right moment. Coaching right after a click sticks.
- They produce evidence. Click and report trends support insurer and client questions.
- They reflect the threat. Verizon's 2025 DBIR finds the human element in about 60% of breaches (Verizon 2025 DBIR).
Cyber Aware states that its customers see an average 80% reduction in clicked links within eight months. That is the vendor's own figure, so check it against your own results.
How do you run a phishing simulation well?
- Warn leadership and follow the notice rules before the first send.
- Allowlist the sending domain so emails arrive, using the whitelisting guide linked below for Microsoft 365.
- Vary templates and ramp up difficulty gradually.
- Run monthly so the lesson does not fade.
- Coach, do not shame. Keep results private.
FAQ
What is a phishing simulation? A safe fake phishing email sent to your own staff to measure who clicks and who reports, followed by coaching.
Do phishing simulations capture passwords? Not with Cyber Aware: reporting shows who clicked and who reported, with no credential harvesting.
How often should phishing simulations run? At least monthly, with varied templates, so staff learn the behaviour rather than one example.
What happens when someone clicks? They see a branded explainer and are enrolled in a follow-up course automatically.
Are phishing simulations effective? KnowBe4's 2026 data shows susceptibility falling from 33.2% to 4.2% after a year of continuous training and testing.
One last thing
Celebrate the reports. The best metric is not a low click rate on its own but a rising report rate. Staff who tell you about a suspicious email, simulated or real, are your fastest detection system.