Back to blog
Guide 5 min readApril 28, 2026

What Is Phishing Simulation? A Complete Guide for Security Teams

Phishing simulation is a controlled security exercise where you send fake phishing emails to your own employees to measure how many click, and then train those who did. Here's everything you need to know.

A phishing simulation is a controlled security exercise in which an organisation sends realistic-looking fake phishing emails to its own employees — without telling them in advance — to measure how many people click the link, open an attachment, or enter their credentials.

The goal is not to catch people out or punish them. The goal is to get accurate, measurable data on your organisation's phishing susceptibility, and to train employees in a way that sticks — because they've just experienced the real thing.

Why phishing simulations work better than training videos

Traditional security awareness training (online modules, annual CBT courses) suffers from a well-documented problem: employees complete the training, click through the slides, pass the quiz — and then fall for the exact same phishing email six weeks later.

Phishing simulations work differently because they trigger experiential learning. An employee who clicks a phishing link and is immediately shown a training page explaining what just happened retains that lesson significantly longer than one who watched a video about phishing in the abstract.

Research consistently shows that organisations running regular phishing simulations (quarterly or more) reduce click rates by 60–80% over 12 months.

How a phishing simulation works

  1. Authorisation — get written sign-off from leadership, HR, and legal
  2. Domain setup — configure a sending domain with SPF, DKIM, and DMARC
  3. Template selection — choose a realistic phishing scenario (IT password reset, payroll update, shared document)
  4. Target list — upload your employee email list, optionally segmented by department
  5. IP whitelisting — whitelist your simulation tool's sending IP in your email gateway so security scanners don't inflate click stats
  6. Launch and monitor — send the campaign and watch who clicks in real time
  7. Review results — analyse click rate, credential submission rate, and time-to-click by department
  8. Train — employees who clicked see a training page immediately; follow up with department briefings

What metrics matter

  • Click rate — percentage of recipients who clicked the phishing link. Industry average on first campaign: 25–35%.
  • Credential submission rate — percentage who entered their username/password on the fake login page. This is the more serious risk indicator.
  • Time to click — how quickly after receiving the email people clicked. Under 60 seconds indicates very low suspicion levels.
  • Department breakdown — which teams are most vulnerable. Finance and HR typically have the highest rates; IT and Security the lowest.

Is phishing simulation legal?

Yes — when done properly. The key requirement is that you are simulating phishing against your own organisation, with written authorisation from the people who are accountable for the organisation's risk. You cannot run phishing simulations against another company's employees, even as a service, without explicit written authorisation from that company's leadership.

PhishSpark requires agreement to an Acceptable Use Policy during signup and reserves the right to suspend accounts used for unauthorised phishing.

How often should you run simulations?

Once a year is the minimum — but it produces minimal behaviour change. Quarterly simulations show measurable improvement. Monthly simulations (with varying templates) produce the fastest reduction in click rates.

The sweet spot for most teams with limited security headcount is quarterly campaigns, alternating between different templates so employees don't learn to recognise a specific style.

Ready to run your first simulation?

PhishSpark is free for up to 500 targets — no credit card required. You can have your first campaign live in 30 minutes, with built-in templates, automatic DKIM signing, and real-time analytics.

what is phishing simulationphishing awareness trainingemployee security training

Run your first phishing simulation today

Free for up to 500 targets. No credit card, no DevOps, no setup headache.

Get started free