Phishing Simulations: Measuring How People Respond
A phishing simulation sends safe practice phishing emails to see how people respond. How they work, what to measure beyond click rates, and how to run them fairly.

A phishing simulation is a practice attack. An organization sends realistic but harmless phishing emails or texts to its own people, then looks at what happens: who reports it, who ignores it, who clicks, and who enters details on the practice page.
How a simulation works
- A scenario is chosen, often based on real lures such as a shared document or a delivery notice.
- Messages are sent to staff, usually spread over time so people do not warn each other.
- Anyone who clicks sees a short, friendly explanation of the signs they missed.
- Results are reviewed as a group trend, not as a list of names to blame.
What to measure
| Measure | Why it matters |
|---|---|
| Report rate | Reporting is what stops real attacks spreading. |
| Time to first report | Shows how fast the team could react to a real campaign. |
| Click rate | Useful as a trend, but noisy on its own. |
| Credential entry | The most serious outcome, and the one to drive down. |
Running them fairly
- Tell staff simulations happen, even if not when.
- Avoid cruel lures, such as fake bonuses or health scares.
- Never punish clicks; reward reports.
- Pair each exercise with short, practical training. See training that works.
More on balance: simulations that keep staff trust.
CyberWatch AI runs phishing simulations for teams, with a confirmation step before any campaign launches and results focused on reporting, not blame.
For the full picture, see how to protect yourself from phishing.
Frequently asked questions
Is a phishing simulation a trick on staff?
It should not feel like one. Done well, it is practice with clear rules, quick learning and no punishment for mistakes.
What is the most useful measure?
How many people report the message, and how quickly. Clicks matter, but reporting is what lets a team respond to real attacks.
How often should simulations run?
Regularly but not constantly. Varied, occasional exercises keep skills fresh without breeding resentment.
Sources
- Phishing attacks: defending your organisation, UK National Cyber Security Centre
- Cyber Essentials, US Cybersecurity and Infrastructure Security Agency
- Recognize and Report Phishing, US Cybersecurity and Infrastructure Security Agency


