Blog/Phishing

Phishing Simulations: Measuring How People Respond

A phishing simulation sends safe practice phishing emails to see how people respond. How they work, what to measure beyond click rates, and how to run them fairly.

CyberWatch AI2 October 2026 · 2 min read
A team meeting around a whiteboard

A phishing simulation is a practice attack. An organization sends realistic but harmless phishing emails or texts to its own people, then looks at what happens: who reports it, who ignores it, who clicks, and who enters details on the practice page.

How a simulation works

  1. A scenario is chosen, often based on real lures such as a shared document or a delivery notice.
  2. Messages are sent to staff, usually spread over time so people do not warn each other.
  3. Anyone who clicks sees a short, friendly explanation of the signs they missed.
  4. Results are reviewed as a group trend, not as a list of names to blame.

What to measure

MeasureWhy it matters
Report rateReporting is what stops real attacks spreading.
Time to first reportShows how fast the team could react to a real campaign.
Click rateUseful as a trend, but noisy on its own.
Credential entryThe most serious outcome, and the one to drive down.

Running them fairly

  • Tell staff simulations happen, even if not when.
  • Avoid cruel lures, such as fake bonuses or health scares.
  • Never punish clicks; reward reports.
  • Pair each exercise with short, practical training. See training that works.

More on balance: simulations that keep staff trust.

CyberWatch AI runs phishing simulations for teams, with a confirmation step before any campaign launches and results focused on reporting, not blame.

For the full picture, see how to protect yourself from phishing.

Frequently asked questions

Is a phishing simulation a trick on staff?

It should not feel like one. Done well, it is practice with clear rules, quick learning and no punishment for mistakes.

What is the most useful measure?

How many people report the message, and how quickly. Clicks matter, but reporting is what lets a team respond to real attacks.

How often should simulations run?

Regularly but not constantly. Varied, occasional exercises keep skills fresh without breeding resentment.

Sources

  1. Phishing attacks: defending your organisation, UK National Cyber Security Centre
  2. Cyber Essentials, US Cybersecurity and Infrastructure Security Agency
  3. Recognize and Report Phishing, US Cybersecurity and Infrastructure Security Agency
Share this article
LinkedIn WhatsApp X
For organizations

Your people get these messages at work too.

CyberWatch AI sends your staff realistic practice attacks, trains the gaps it finds, and shows management exactly where the organization stands.