← All articles

// awareness · 5 min

Phishing Simulations: Doing Them Without Wrecking Trust

AWARENESS

Phishing simulations are the most common security-awareness tool and the easiest to get wrong. Done badly, they teach staff to distrust IT and hide mistakes. Done well, they build reflexes that stop real attacks.

Report rate (the real metric)
Time to report
Repeat clickers

The wrong way

  • Gotcha emails promising bonuses, then publicly shaming everyone who clicked.
  • One test a year, treated as a pass/fail exam.
  • No follow-up training — just a scary statistic in a board deck.

The right way

  • Frame it as team training, not a trap. Announce that simulations happen; the goal is practice, not punishment.
  • Make reporting the win. Measure and celebrate the report rate, not just the click rate. A workforce that reports fast beats one that never clicks but stays silent.
  • Teach at the moment of the click. The landing page should be a 30-second lesson, not a reprimand.
  • Escalate difficulty gradually and tie scenarios to real threats your sector faces.

Metrics that matter

Report rate (up), time-to-report (down), repeat-clicker trend (down). Click rate alone is vanity. The organisations that survive real phishing are the ones where someone reports within minutes — giving the security team time to act.

Concerned about any of this in your environment?

I help organisations test, find, and fix exactly these issues — with evidence, not scanner output. Start with a no-obligation conversation.

Written by Abdullah Bin Zarshaid, MSc, CEH.

Discuss your security →