Phishing Simulation and Awareness

Most breaches begin with somebody clicking. Awareness training delivered once a year as a slide deck changes almost nothing, because the skill being taught is recognition under time pressure rather than knowledge. Simulation works because it creates the moment safely, measures who fell for it, and lets training go to the people who need it.

1

Baseline

Measure before training

2

Campaign

Realistic, safe scenarios

3

Measure

Clicks and reports

4

Train

Target the exposure

5

Repeat

Prove improvement

How the Programme Works

01

Baseline Campaign

We start with an unannounced baseline so improvement can be demonstrated later. Announcing it first produces a flattering number that measures nothing. The baseline is agreed with executive sponsors beforehand and handled carefully.

02

Scenario Design

Generic templates get ignored. Effective scenarios mirror the messages your staff genuinely receive: supplier bank detail changes, payroll notices, procurement enquiries. We keep them realistic without being cruel.

03

Measurement and Analysis

Three numbers matter: who clicked, who submitted credentials, and who reported it. The reporting rate is the one most organisations ignore and the one that best predicts whether a real attack gets caught early.

04

Targeted Training

Training goes where the exposure is. Finance and procurement staff face different threats from operations, and a department clicking at three times the average needs different attention from one already reporting reliably.

05

Repeat Testing and Reporting

A single campaign is a data point. A programme run quarterly shows a trend, and the trend is what demonstrates to a board that awareness spending is achieving something.

What You Receive

Indicative Timeline

A baseline campaign runs over one to two weeks including analysis. Thereafter the programme is quarterly and ongoing, because a single campaign changes behaviour only briefly.

How We Run It

Simulation is a measurement and training exercise, not a trap, and the design reflects that throughout.

Executive Sponsorship

Agreed before launch, so nobody is blindsided and the programme is understood as training rather than surveillance.

Realistic Scenarios

Modelled on the messages your staff genuinely receive rather than generic templates they will never see.

Teaching at the Click

Anyone who clicks lands on an explanation of the indicators they missed, at the moment they are most receptive.

No Individual Blame

Results reported by department and trend. Naming individuals suppresses reporting, which is the opposite of the objective.

Report Rate Focus

We measure and reward reporting, because the fastest containment comes from a person raising the alarm.

Trend Over Time

Quarterly repetition so the board sees whether behaviour is actually changing rather than a single snapshot.

Frequently Asked Questions

It is training, and how it is run determines how it is received. Executive sponsorship is agreed up front, results are reported by department rather than by name, and anyone who clicks gets an explanation rather than a reprimand. Handled that way, staff generally engage with it well.

Not for the baseline, or the number is meaningless. We do recommend announcing that a programme exists generally, so people understand simulations happen periodically without knowing when.

First campaigns commonly land between fifteen and thirty percent. What matters more is the direction over subsequent campaigns and the report rate, which should rise as the click rate falls.

Because in a real attack, containment speed depends entirely on somebody raising the alarm. An organisation with a modest click rate and a strong reporting culture detects and contains faster than one where nobody clicks but nobody tells anyone either.

They get additional focused training, not disciplinary action, unless your own policy says otherwise. Punitive responses reliably suppress reporting, which costs more than the clicking does.

Yes, and we recommend it. Finance and procurement face targeted business email compromise attempts that differ substantially from generic phishing, and their training should reflect that.

Related Services

This sits inside our Cyber Security Assessments practice. Related work: Penetration Testing, which can include scoped social engineering, and Training for the wider staff development programme.

Discuss a phishing programme