A phishing simulation consists in deliberately sending your staff a fake trap e-mail, built the way an attacker would, and then observing what happens. Who clicks, who reports, who does nothing.
The exercise has a very good reputation, and it partly deserves it. But it is also one of the rare cybersecurity measures capable of doing more harm than good. Poorly designed, a campaign teaches nothing and leaves behind a lasting sense of having been trapped by the employer. Here, how it is done matters as much as the tool itself.
What does a phishing simulation actually deliver?
It delivers two things, and they need to be distinguished.
An objective measurement. Until you have tested it, you only have a gut feeling about your teams’ ability to spot a fake e-mail. The simulation turns that feeling into a finding. It often reveals unexpected things: an entire department that does not know where to report, a generic address that everyone checks and no one monitors.
A learning moment placed at the right spot. This is the real value, and it is hard to achieve any other way. A person who has just clicked and discovers, at that exact instant, that they have just fallen into a trap retains the lesson in a way no presentation will ever produce. Attention is at its peak because the mistake is concrete and personal.
This is exactly why the page shown after the click is the single most important element of the whole campaign, well ahead of the choice of scenario or the sophistication of the fake e-mail.
The rules that separate learning from humiliation
Four rules. They are not negotiable, and just one of them being dropped is enough to turn the exercise into a source of resentment.
No sanction, ever. Not a formal one, not an informal one, not even a remark in a team meeting. As soon as clicking becomes risky, no one reports their mistakes anymore, and it is precisely that capacity to report that will save you during a real attack.
No results shared by name. Figures circulate in aggregate: an overall rate, possibly broken down by department if the headcount is large enough that no one can be identified. The list of people who clicked has no business reaching management, nor a team leader.
Management takes part too. An executive left out of the scope sends a clear message: the exercise is for subordinates. Yet executives are precisely the preferred targets of targeted attacks, as shown by CEO fraud. Their participation completely changes how the approach is perceived.
The page after the click explains, it does not reprimand. No “you failed”, no red counter. A short text that goes back over the e-mail received, points out the two or three clues that gave away the trick, reminds people where to report a suspicious e-mail, and thanks them. The tone should be that of a colleague, not an inspector.
Before launching a campaign, ask yourself this question: if an employee runs into the executive in the hallway right after clicking, would the conversation be awkward? If so, something is wrong with the design of the exercise. A good simulation creates curiosity, not shame.
Which bait scenarios should never be used?
This is the point where many campaigns go wrong, often with the best intentions in the world. The designer’s logic is tempting: the more effective the bait, the more realistic the test. It is wrong.
The fake e-mail announcing a bonus or a pay rise. The fake e-mail mentioning a layoff, a redundancy plan or a restructuring. The fake e-mail touching on a sensitive personal matter: health, family, financial situation, disciplinary procedure. These campaigns get spectacular click rates and teach absolutely nothing.
Why nothing? Because these e-mails do not test vigilance. They exploit an emotion that vigilance cannot withstand. No one coolly analyses the sender’s address of a message announcing the elimination of their own job. The result measures the strength of the bait, not people’s competence.
And the cost is real. An employee who believed for thirty seconds in a nonexistent bonus, or an imaginary layoff, will not retain a cybersecurity lesson. They will remember that their employer played with their money, their job or their private life to produce a statistic. That damaged trust is not repaired with an explanatory e-mail.
The practical rule is simple: the scenario must stay within the realm of ordinary professional matters. An invoice, a delivery, an electronic signature request, a message from a supplier. This is, moreover, what most attackers actually do, as detailed in our article on phishing.
What does the click rate really tell you?
The click rate is the indicator everyone looks at. It is worth knowing what it is actually worth.
It tells you one useful thing: at a given moment, faced with this specific message, a certain proportion of people took the bait. As a starting point, that is instructive.
It does not tell you that your teams are vigilant. A decline over successive campaigns mainly means that your staff now recognise your simulations. They spot the format, the time it is sent, the phrasing, the domain used. That learning is real, but it applies to your exercises, not to tomorrow’s attacks.
It also does not say much about the company’s security. A low click rate with zero reporting describes a blind organisation: no one bites, no one raises the alarm, and the day a single person clicks, you will find out too late.
| Indicator | What it measures | Its limitation |
|---|---|---|
| Click rate | How appealing this specific bait is | Mainly falls because your simulations are recognised |
| Credential entry rate | The complete follow-through on the action | Heavily depends on how realistic the fake page is |
| Reporting rate | The organisation’s actual ability to detect | Assumes a reporting channel exists and is known |
| Median reporting time | Speed of reaction in a real attack | Meaningless if the channel is poorly identified |
The indicator that really matters
The reporting rate, and the reporting time.
The logic here is that of incident management, not of a school grade. In a real attack, you cannot hope that no one will click. What you can hope for is to be warned quickly, so you can block the sender, warn everyone else and reset a password before the attacker makes use of it.
Ten people who report a suspicious e-mail are worth more than a single one who silently does not click. The ten give you an actionable alert. The eleventh gives you nothing.
The time factor is just as telling. A report within three minutes allows you to act. A report the next morning arrives after the battle is over. Track the median time from one campaign to the next, it is one of the rare figures that reflects a genuine improvement in your organisation.
This obviously assumes that a reporting channel exists, that it is simple, and that everyone knows about it. If your staff do not know who to write to, no campaign will be of any use at all.
The legal and social aspects
A phishing simulation processes data concerning identifiable people: who opened it, who clicked, when. This deserves a few precautions, and some care in how the results are presented.
As a general rule, three habits avoid most of the difficulties.
Inform staff in advance of the principle behind the exercises, their educational purpose, and the fact that results will not be used against individuals. You announce that there will be some, never when.
Limit and anonymise the data. Do not keep named results beyond what is strictly necessary to run the campaign, and think in aggregate figures as soon as you report back.
Involve staff representation where it exists. A staff committee or a delegate informed in advance becomes a useful relay, rather than a stakeholder who discovers the exercise after the fact.
These points touch on employment law and data protection, two areas where the situation depends heavily on your company, its size and its internal organisation. We are not stating any specific legal obligation here: before a first campaign, have your set-up validated by legal counsel. The general principles applicable to the processing of personal data are presented in our article on the FADP for SMEs.
Where to start in an SME with 15 employees?
By not starting there.
A simulation only makes sense once the basics have been laid down. In a company that has never explained to its teams what a fraudulent e-mail is, the exercise only measures an ignorance that no one is responsible for, and it is experienced as being caught out.
The order that works has four steps. First, basic awareness training, one hour is enough, on the mechanisms of phishing and social engineering. Then, a clear reporting channel, known to everyone, with a guaranteed response. Then the technical measures that limit the damage from a click, starting with two-factor authentication. Only then, a first campaign, announced in principle, with an ordinary scenario.
This first campaign serves as a baseline measurement, nothing more. Its value lies not in the figure obtained, but in the conversations it triggers and what it reveals about your procedures.
To gauge your maturity level before getting started, the cyber check-up covers the prerequisites, and the other building blocks of awareness training are grouped in the Training pillar.
Finally, a reminder that applies to this whole article: these principles form a starting framework, they do not replace an assessment of your actual situation. Designing a campaign engages the internal climate as much as security, and this is typically the kind of exercise where an experienced outside perspective avoids lasting social damage for an educational benefit that could have been achieved another way.