A phishing simulation is a controlled, fake phishing email that a company sends to its own employees to measure how many people click, enter credentials, or report it — without any real risk to data or systems. It's the single most effective way to find out whether your security awareness training is actually working before a real attacker finds out for you.
Nearly a third of untrained employees (33.1%) fail a baseline phishing test the first time they're tested, according to KnowBe4's 2025 Phishing by Industry Benchmarking Report, which analyzed 67.7 million simulated phishing tests. With consistent simulation and training, that number drops to roughly 5% within a year. The gap between those two numbers is the entire business case for running phishing simulations.
This guide walks through exactly how to set one up: preparing your environment, choosing a campaign type, launching it, and reading the results — plus the mistakes that quietly sabotage most programs.
A phishing simulation (also called a simulated phishing attack or phishing test) is a safe, internal exercise where an organization sends realistic-looking phishing emails to its own employees. The goal isn't to catch people out — it's to measure susceptibility, identify who needs more training, and build the habit of pausing before clicking.
Unlike a real phishing attack, a simulation:
Skipping setup is the number one reason phishing simulations produce misleading results — usually because the test email lands in spam, or IT accidentally "catches" it and alerts the whole company before it even reaches inboxes.
Before launching your first campaign, confirm three things:
Most phishing simulation platforms offer two core campaign types. Picking the right one up front saves you from re-running everything a month later.
A single round of phishing emails sent to some or all of your organization. This is the right choice when you want to:
One-time campaigns are ideal for onboarding a new security awareness program, satisfying an annual compliance requirement, or benchmarking a department before a bigger rollout.
An ongoing, recurring simulation program that sends new templates on a schedule — weekly, biweekly, or monthly — without manual relaunching. This is the right choice when you want to:
Security awareness practitioners generally recommend simulations every 2–4 weeks at minimum to build lasting habits without triggering fatigue or desensitization — a cadence that's only realistic with an automated, "smart" campaign rather than manual one-off sends.
Template choice determines whether your simulation measures anything useful. Two principles matter most:
Match current attack patterns. Generic "you won a prize" emails no longer reflect what employees actually face. Prioritize templates that mirror real 2026 threats: business email compromise (invoice or wire-transfer requests), credential-harvesting login pages, QR-code phishing ("quishing"), MFA-fatigue prompts, and SMS or voice-based lures. AI-generated phishing emails now account for the large majority of attacks detected in the wild, and they read far more convincingly than the typos-and-urgency templates of a few years ago — your simulations should keep pace.
Stay proportionate and transparent. Avoid lures that impersonate sensitive topics like layoffs, bonuses, health benefits, or a colleague's personal crisis — these erode trust even when technically effective. Tell employees, at a program level, that phishing simulations will happen periodically (without revealing exact timing or templates). Programs that are transparent about their existence — while keeping specifics a surprise — see meaningfully higher reporting rates than programs run in total secrecy.
Once the campaign is live, track results in real time: emails sent, opened, clicked, and "phished" (credentials or data submitted). But click rate alone is a shallow metric — it tells you who failed, not whether the program is working.
Track these instead:
The single biggest driver of program failure isn't a bad template — it's what happens after someone clicks. Best practice is to deliver an immediate, short (2–3 minute) training moment explaining exactly what indicator they missed, rather than a generic "you failed" notice.
Avoid public leaderboards of "worst performers," disciplinary action tied to simulation results, or manager-cc'd shame emails. Research on security awareness programs consistently finds that punitive approaches backfire: they suppress future reporting, damage trust in leadership, and make employees less likely to report a real attack out of fear of consequences. Organizations that frame simulations as skill-building — not entrapment — see both higher engagement and better long-term click-rate reduction.
At minimum, every employee should receive one simulation per quarter to establish a trend line. For meaningful behavior change, monthly simulations are the widely recommended baseline, with many mature programs running every 2–4 weeks. Organizations that maintain a consistent monthly cadence with immediate feedback typically see a 40%+ drop in phishing-prone employees within 90 days, and long-term click rates that stabilize in the low single digits after about a year — down from an industry-wide baseline of roughly 33% on an untrained population.