Blog/Security awareness

How to Run Phishing Simulations Your Staff Won't Resent

Phishing simulations are one of the best ways to measure human risk, and one of the easiest to get wrong. Here is how to run them so your people learn, report more and trust the process.

CyberWatch AI27 September 2026 · 3 min read
Four colleagues gathered around a laptop in a meeting room, reacting to what is on screen

A phishing simulation answers a question no firewall can: what do your people actually do when a convincing message arrives? Run well, simulations turn security from a slideshow into a skill. Run badly, they teach staff to resent the security team and to hide their mistakes, which is the opposite of what you need.

The difference is almost entirely in how you set them up.

1. Tell people simulations will happen

You do not need to say when, or what the message will look like. But announcing that the organization runs practice exercises changes how they are received. A simulation that arrives without warning feels like a trap. One that arrives as part of a known programme feels like a fire drill.

2. Measure reporting, not just clicking

The click rate is the number everyone quotes, but it is only half the picture. The most valuable behaviour is the employee who spots the message and reports it, because in a real attack that report is what lets the security team warn everyone else. Celebrate reports. Track them. Make the report button the easiest thing to press.

A healthy trend is fewer clicks and more reports over time. An organization where nobody clicks but nobody reports either has not learned to defend itself; it has learned to ignore email.

3. Never make it disciplinary

If clicking a simulation leads to punishment, people stop reporting their real mistakes, and a real mistake reported in five minutes is far cheaper than one discovered in five weeks. Treat a click as a training need, not a failure. The goal is a culture where someone says "I think I just clicked something" without fear.

4. Teach at the moment it matters

When someone clicks, show them straight away what they missed: the odd sender, the urgent tone, the link that went somewhere else. A short, specific lesson at that moment is worth more than an hour of generic training months later.

5. Make the scenarios realistic, but fair

Use the kinds of messages your people really receive: delivery notices, invoice queries, password resets, shared documents. Avoid themes that cause genuine distress, such as fake bonuses, pay cuts or medical news. Tricking someone with a message about their salary damages trust far more than it teaches.

6. Vary the difficulty and keep it regular

Start with messages most people can spot and raise the difficulty as the organization improves. A steady rhythm, such as one exercise a month, builds habits; a single big test once a year mostly measures luck.

7. Share results as a team, not as a list of names

Leadership needs to see where the organization stands, by department and over time. Individuals need private, supportive feedback. Publishing names of people who clicked helps nobody.

Start with a baseline. Your first simulation is not a test to pass; it is a measurement of where you are today, so you can show how far you have come.

How CyberWatch AI approaches it

CyberWatch AI was built around these principles. Administrators launch realistic simulations only after an explicit confirmation step, employees who click see what they missed and get short follow-up training on that exact pattern, reporting is one tap, and management sees a single security score with department breakdowns rather than a list of names. Every simulation email is harmless: it measures behaviour and teaches, and nothing more.

Share this article
LinkedIn WhatsApp X
For organizations

Your people get these messages at work too.

CyberWatch AI sends your staff realistic practice attacks, trains the gaps it finds, and shows management exactly where the organization stands.