Phishing Simulation and Awareness
Most breaches begin with somebody clicking. Awareness training delivered once a year as a slide deck changes almost nothing, because the skill being taught is recognition under time pressure rather than knowledge. Simulation works because it creates the moment safely, measures who fell for it, and lets training go to the people who need it.
1
Baseline
Measure before training
2
Campaign
Realistic, safe scenarios
3
Measure
Clicks and reports
4
Train
Target the exposure
5
Repeat
Prove improvement
How the Programme Works
01
Baseline Campaign
We start with an unannounced baseline so improvement can be demonstrated later. Announcing it first produces a flattering number that measures nothing. The baseline is agreed with executive sponsors beforehand and handled carefully.
- Scenario design appropriate to your organisation
- Executive sponsorship agreed before launch
- Unannounced baseline across the target population
- Click, submit and report rates captured per department
02
Scenario Design
Generic templates get ignored. Effective scenarios mirror the messages your staff genuinely receive: supplier bank detail changes, payroll notices, procurement enquiries. We keep them realistic without being cruel.
- Scenarios modelled on messages staff actually receive
- Difficulty graded from obvious to sophisticated
- Pretexts reviewed for tone and appropriateness
- Landing pages that teach rather than shame
03
Measurement and Analysis
Three numbers matter: who clicked, who submitted credentials, and who reported it. The reporting rate is the one most organisations ignore and the one that best predicts whether a real attack gets caught early.
- Click rate by department and role
- Credential submission rate
- Report rate, the strongest predictive indicator
- Time to first report from delivery
04
Targeted Training
Training goes where the exposure is. Finance and procurement staff face different threats from operations, and a department clicking at three times the average needs different attention from one already reporting reliably.
- Role based training aligned to actual threats
- Immediate teaching moment at the point of click
- Focused sessions for high exposure departments
- Guidance on how and where to report
05
Repeat Testing and Reporting
A single campaign is a data point. A programme run quarterly shows a trend, and the trend is what demonstrates to a board that awareness spending is achieving something.
- Quarterly campaigns with varied scenarios
- Trend reporting against the baseline
- Departmental comparison over time
- Board level reporting on human risk
What You Receive
- Baseline campaign results by department and role
- Click, submission and report rate metrics
- Targeted training delivered to high exposure areas
- Quarterly campaign results with trend analysis
- Guidance material and reporting instructions for staff
- Board reporting on human risk over time
Indicative Timeline
A baseline campaign runs over one to two weeks including analysis. Thereafter the programme is quarterly and ongoing, because a single campaign changes behaviour only briefly.
- Scenario design and sponsorship: one week
- Baseline campaign and collection: one week
- Analysis and targeted training: one to two weeks
- Repeat campaigns: quarterly thereafter
How We Run It
Simulation is a measurement and training exercise, not a trap, and the design reflects that throughout.
Executive Sponsorship
Agreed before launch, so nobody is blindsided and the programme is understood as training rather than surveillance.
Realistic Scenarios
Modelled on the messages your staff genuinely receive rather than generic templates they will never see.
Teaching at the Click
Anyone who clicks lands on an explanation of the indicators they missed, at the moment they are most receptive.
No Individual Blame
Results reported by department and trend. Naming individuals suppresses reporting, which is the opposite of the objective.
Report Rate Focus
We measure and reward reporting, because the fastest containment comes from a person raising the alarm.
Trend Over Time
Quarterly repetition so the board sees whether behaviour is actually changing rather than a single snapshot.
Frequently Asked Questions
Is this not entrapment of our own staff?
It is training, and how it is run determines how it is received. Executive sponsorship is agreed up front, results are reported by department rather than by name, and anyone who clicks gets an explanation rather than a reprimand. Handled that way, staff generally engage with it well.
Should we tell staff in advance?
Not for the baseline, or the number is meaningless. We do recommend announcing that a programme exists generally, so people understand simulations happen periodically without knowing when.
What is a good click rate?
First campaigns commonly land between fifteen and thirty percent. What matters more is the direction over subsequent campaigns and the report rate, which should rise as the click rate falls.
Why does the report rate matter so much?
Because in a real attack, containment speed depends entirely on somebody raising the alarm. An organisation with a modest click rate and a strong reporting culture detects and contains faster than one where nobody clicks but nobody tells anyone either.
What happens to repeat clickers?
They get additional focused training, not disciplinary action, unless your own policy says otherwise. Punitive responses reliably suppress reporting, which costs more than the clicking does.
Can you train specific high risk teams?
Yes, and we recommend it. Finance and procurement face targeted business email compromise attempts that differ substantially from generic phishing, and their training should reflect that.
Related Services
This sits inside our Cyber Security Assessments practice. Related work: Penetration Testing, which can include scoped social engineering, and Training for the wider staff development programme.
