Glossary
What is a phishing simulation?
A phishing simulation is a controlled, authorised exercise in which an organisation sends realistic but harmless phishing messages to its own employees.
- Also known as
- Phishing test, simulated phishing
- Channels
- Email, SMS, voice, chat apps, QR codes, calendar invites
- Typical goal
- Safe practice and evidence of readiness
- Related term
- Security awareness training
How it works
Plan, send,
teach, measure.
- 01
Plan
Choose the audience, channel and scenario, matched to the attacks that team really receives.
- 02
Send
Realistic, harmless lures go out on a schedule, without warning so the practice is genuine.
- 03
Teach
Anyone who clicks or submits sees a short explanation of the warning signs in that message.
- 04
Measure
Track clicks, submissions and reports over time, then plan the next round and targeted training.
How to run one well
Practice, not
punishment.
Simulations work when people see them as rehearsal. Share why you run them, keep scenarios within agreed boundaries, and focus follow-up on learning.
Before you launch a campaign
- Leadership and HR agree on scope and pretexts
- Reporting route is clear to everyone
- Lessons are ready for people who click
- Results are used for training, not blame
- Next round is planned before this one ends
General good practice; adapt to your organisation.
Questions buyers ask
Frequently asked questions.
Are phishing simulations legal?
Simulations run by an organisation on its own staff, with proper internal authorisation, are a common security practice. Check with your legal and HR teams on local employment and privacy requirements.
How often should you run phishing simulations?
Regular, varied simulations throughout the year tend to be more useful than a single annual test. The right rhythm depends on your team size and goals.
Should employees be told about phishing simulations?
It’s good practice to tell people that simulations happen and why, without announcing individual campaigns in advance.
Let’s connect the dots
See the human risk.
Change what happens next.
Bring your awareness program, your reporting workflow, or the question your current metrics cannot answer.
Book a demo