Phishing Simulation for Small Businesses: A Complete Guide (No IT Team Required)
Small businesses are the most targeted by phishing attacks and the least likely to be running simulations. Here's how a company with 50–500 employees can test and train their team on a realistic budget — without a dedicated security team.
Phishing attacks don't target enterprise companies because they're easy — they target small businesses because they're easier. Most organisations with under 500 employees have no dedicated security analyst, no email security gateway, and no phishing simulation programme. Attackers know this.
The good news: running a phishing simulation at a small company is dramatically simpler than at an enterprise. You don't need a security budget, an IT department, or a dedicated tool administrator. This guide covers everything a small business needs to run its first simulation and actually reduce its risk.
Why small businesses need phishing simulations more than enterprises
Enterprise companies have layers of defence: security operations centres, advanced email gateways, dedicated security awareness programmes, incident response teams. When one employee clicks a phishing link, there are seven other controls between that click and a breach.
At a 50–200 person company, the employee who clicks is often also the person with admin access to the CRM, the accounting system, and the file server. There's no SOC watching for anomalous login behaviour. There's no IR team on retainer. One credential submission can mean a direct path to everything.
Phishing is the entry point for over 90% of data breaches. For small businesses, reducing that entry point is one of the highest-ROI security investments available.
What you actually need to run a simulation
The barrier is lower than most IT managers assume. For a small company, you need:
- Written authorisation from leadership — one email from the CEO or founder confirming they've approved the exercise. This protects you if an employee raises a complaint.
- A domain to send from — either your real company domain or a lookalike. You'll add 3 DNS records (SPF, DKIM, DMARC) — takes 15 minutes in Cloudflare.
- A list of employee emails — a CSV export from your HR system or Google Workspace admin console.
- A phishing simulation platform — or GoPhish if you're comfortable with servers (see above).
That's it. No security degree required. No external consultant needed.
The right approach for a team of 50–200 people
Start with one department
Don't send your first phishing simulation company-wide. Pick one department — Finance is the highest-risk; IT is usually the most aware. Run the simulation on 20–30 people, see what percentage click, then use those results to make the case for a company-wide rollout.
Starting small lets you refine your template and process before you're explaining yourself to the entire company.
Choose a medium-difficulty template
Your goal isn't to catch people out — it's to measure actual susceptibility and use the result to improve. An extremely obvious fake email ("Dear Valued User, Click Here For Gift Card!!!") tells you nothing useful. An impossibly sophisticated spearphish demoralises employees unfairly.
The right starting templates for small businesses:
- IT password reset — "Your Microsoft 365 / Google Workspace password expires in 48 hours." Works at nearly every company, familiar enough to be plausible, urgent enough to trigger action.
- Payroll notification — "Your payslip for this month is ready. Please update your bank details to ensure payment." Finance anxiety is universal.
- Shared document — "[Colleague name] shared a file with you." Uses a familiar workflow pattern.
Whitelist the simulation IP first
If your company uses Microsoft 365 or Google Workspace with their built-in email security (which they almost certainly do), the mail system automatically clicks every link in every inbound email to check for malware. This inflates your click stats massively — you'll see 80–100% click rates before any human has read the email.
Before launching: add an exception in your email platform for your simulation tool's sending IP. PhishSpark shows you the exact IP and the step-by-step instructions for Microsoft 365 Defender and Google Workspace admin console.
Run the simulation and wait 72 hours
Send the campaign and leave it alone. Many employees read email infrequently — waiting 72 hours before pulling results ensures you're capturing the full picture, not just the early responders.
What to do with the results
After 72 hours, you'll have three numbers that matter:
- Click rate — percentage who clicked the link. Under 10%: your team is reasonably aware. 10–30%: typical, needs improvement. Over 30%: high risk, prioritise training.
- Credential submission rate — percentage who entered their username/password. This is the more serious indicator. Even 1–2% credential submission in a 100-person company means real risk.
- Time to first click — if someone clicked within 60 seconds of receiving the email, they didn't pause to evaluate it at all.
Do not email the results to all-staff. Don't name individuals in department-wide meetings. Employees who clicked should be notified privately and pointed to training resources — not embarrassed. The goal is behaviour change, not blame.
The phishing landing page (on PhishSpark) shows clicked employees an immediate training message: what red flags they should have noticed, why this kind of email is dangerous, and what to do next time. This is the most effective training moment — it happens at the exact point of failure, not six months later in an annual CBT module.
How much does this cost for a small business?
For most small businesses:
- Under 500 employees: PhishSpark free tier covers your first simulation entirely. No credit card required.
- 100–500 employees running quarterly campaigns: ₹999/month ($12) — covers 1,000 targets/month, all templates, 5 domains.
- Strict data residency (legal, finance, healthcare): Self-hosted licence at ₹15,000/year ($180) — deploy on your own server, all data stays in your infrastructure.
Compare that to the cost of a single successful phishing attack: the average cost of a data breach for a small business is $2.98 million according to IBM's 2025 Cost of a Data Breach report. The ROI calculation is straightforward.
Running your first simulation this week
The most common reason small businesses haven't run a phishing simulation yet is that it sounds complicated. It isn't — not anymore.
- Create a free PhishSpark account (2 minutes)
- Add your domain and follow the DNS verification wizard (15 minutes)
- Upload a CSV of employee emails (5 minutes)
- Pick a template and launch (5 minutes)
- Read results in 72 hours
Total time investment: under 30 minutes. The results will tell you more about your organisation's actual phishing risk than any compliance checklist ever has.
Questions about setup? Email [email protected] — we're available for free accounts too.
Run your first phishing simulation today
Free for up to 500 targets. No credit card, no DevOps, no setup headache.
Get started free