Phishing simulation
Also known as: phishing test, simulated phishing campaign
Sending staff harmless fake phishing mails to see who clicks and to teach them to spot the real thing.
Draft - this entry has not been reviewed yet.
Formal
A planned training exercise in which an organisation sends realistic but safe phishing messages to its own staff, measures how many click or report them, and follows up with short lessons.
In plain English
Like a fire drill for the inbox - practising the right reaction while nothing is really burning.
In practice
The IT security officer at an audit firm sends a fake “You have new digital post” mail; staff who click see a friendly page pointing out the warning signs they missed.
Why it matters
It turns awareness into a number that can be followed over time and gives safe practice before a real attacker tests people - as long as it is used to teach rather than to shame.
How to put it into practice
The usual steps, in order. Adapt them to your organisation.
- Decide the purpose first - practising reporting and finding weak processes, not catching people - and get written approval from management, HR, employee representatives and the DPO.
- Tell staff in advance that simulations will run, why and how the data is used, and document the GDPR lawful basis (usually Art. 6(1)(f)) and a retention period for click data.
- Before the first campaign, make reporting easy with a report button and a quick, thankful reply to everyone who reports, whether the mail is real or simulated.
- Build lures from threats you actually see, rate their difficulty with the NIST Phish Scale, and avoid cruel pretexts such as bonuses, pay rises or health scares.
- Allow the simulation through your mail filters the supported way (for example the advanced delivery policy in Microsoft 365) and filter out clicks made by link scanners.
- Run small campaigns spread over the year with varied templates instead of one big blast that staff warn each other about.
- Follow every campaign with a short, friendly explanation of the warning signs and praise for those who reported, and never name or punish individuals.
- Report aggregated report rate, time to report and click rate per difficulty level to management, and fix the processes that failed, such as invoice approval.
Common pitfalls
- Using the click rate alone as the measure of success without controlling for how hard the templates were.
- Naming, shaming or disciplining staff who click, which destroys trust and makes people stop reporting.
- Lures that exploit pay, bonuses or personal worries and cause a backlash against the security team.
- Running simulations without telling staff or employee representatives and without a GDPR basis for the click data.
Good guides
- Phishing attacks - defending your organisation(opens in a new tab) · NCSC UK
- NIST TN 2276 - NIST Phish Scale User Guide(opens in a new tab) · NIST
- Get started using Attack simulation training(opens in a new tab) · Microsoft
- Film om god sikkerhedsadfærd(opens in a new tab) · Styrelsen for Samfundssikkerhed (in Danish)
Technical deep dive
A simulation platform - commercial suites, Microsoft Defender for Office 365 Attack Simulation Training, or the open-source GoPhish - sends templated messages with per-recipient tracking tokens embedded in links, attachments or QR codes, and records opens, clicks, credential submissions, attachment opens and reports. Typical payload types mirror real techniques: credential harvest, malware attachment, link in attachment, drive-by URL and OAuth consent grant. Because production defences would otherwise block or detonate the mails, third-party simulations must be explicitly exempted, in Microsoft 365 via the advanced delivery policy rather than blanket transport-rule bypasses, and link scanners must be accounted for, since sandbox detonation produces false clicks that inflate results.
Results are only comparable when difficulty is controlled. The NIST Phish Scale (introduced in 2020, user guide NIST TN 2276, 2023) rates a template by counting observable cues (sender, formatting, technical and content anomalies) and assessing premise alignment, how well the pretext fits the recipient's actual work. A low-cue, high-alignment lure will produce far higher click rates than a clumsy one, so a falling click rate may reflect easier templates, not better staff. Report rate and time-to-report are more robust, and the difference between the two gives a picture of both susceptibility and detection. Small departments, one-off campaigns and seasonal effects add noise that is easily mistaken for trend.
The empirical evidence is sobering. Lain, Kostiainen and Čapkun (IEEE S&P 2022), with more than 14,000 employees over 15 months, found that embedded training shown after a click did not make employees more resilient and could make them more susceptible, while crowd-sourced reporting worked. Ho et al. (IEEE S&P 2025), in a randomised experiment with about 19,500 staff at UC San Diego Health, found no significant relationship between recent annual training and failure rates, and that most users spent a minute or less on embedded training pages. Simulations are thus better used to exercise reporting and to find processes that fail than as proof that training works.
Design and governance matter. Lures offering bonuses, pay rises or pandemic information have caused well-publicised staff backlash, for example at GoDaddy in 2020, and erode trust in the security team. Click data is personal data about employees, so under GDPR the programme needs a lawful basis (usually legitimate interest, Art. 6(1)(f)), transparent information to staff, data minimisation and, preferably, aggregated reporting to management rather than named lists. NIST SP 800-50 Rev. 1 places simulations under experiential learning alongside tabletop and cyber-range exercises, and CIS Controls v8 Control 14 expects training on recognising social engineering attacks.
What to learn first
Everything this builds on, foundations first.
- Digital identity
- →Credential
- →Phishing
- →Phishing simulation
Relationships
- A kind of
- Security control
- Part of
- Awareness programme
- Requires
- Phishing
- Used with
- Security awarenessAwareness officer
Sources & further reading
Standards & official texts
- CIS Controls v8 - Control 14 (Security Awareness and Skills Training) · Center for Internet Security
- NIST TN 2276 - NIST Phish Scale User Guide · NIST
Course material
- Cyber Security Fast Track - Kursuskompendium, Modul 2
Other
Where this data comes from
This entry was drafted by an AI from the sources above and has not yet been checked by a person. Treat it as a starting point, and check anything important against the sources.
See the review queueSuggest a correction on GitHubThis term as JSON
Mentioned in
Check yourself
Loading…