Phishing Simulation Programs That Change Behavior
A phishing simulation is a controlled, authorized exercise in which an organization sends realistic but harmless phishing emails to its own employees to measure who clicks, who reports, and how quickly. This page covers what a phishing simulation is, how to run a program that improves numbers instead of just producing them, how to evaluate phishing simulation software and vendors, the metrics that actually predict resilience, and what auditors expect to see.
Key Takeaways
- A phishing simulation is a measurement instrument, not a punishment. Its job is to tell you which people, departments, and message types your organization is genuinely vulnerable to, so that training can be aimed rather than sprayed.
- Click rate is the metric everyone quotes and the weakest one available. Report rate, time to first report, and the ratio between the two tell you far more about whether an organization would survive a real campaign.
- A single annual simulation is a compliance checkbox. A continuous program with monthly or quarterly waves, varied difficulty, and immediate teachable moments is what moves behavior.
- HIPAA, CMMC and NIST SP 800-171, PCI DSS, the FTC Safeguards Rule, and SOC 2 all expect documented, recurring security awareness activity. Simulation results are among the cleanest pieces of evidence you can hand an assessor.
- Petronella Technology Group, Inc. has been running security programs for regulated businesses since April 2002 and delivers simulated phishing as part of a managed awareness program, not as a standalone report.
Before You Send the First Email
- Get written authorization from an executive sponsor. A phishing simulation sends deceptive email to your own staff, and it needs the same documented approval any authorized security test does.
- Decide the consequence model before the results exist. If people learn that clicking gets someone disciplined, they will stop reporting, and reporting is the capability you are trying to build.
- Make sure a report button exists and works before you test whether people use it. Many first campaigns measure the absence of a tool rather than the absence of awareness.
- Brief your help desk and security monitoring team. An unannounced simulation that triggers a genuine incident response at 4 p.m. on a Friday costs more goodwill than the data is worth.
What Is a Phishing Simulation?
The plain definition, and the distinction that separates a useful exercise from theater.
A phishing simulation is a controlled exercise in which an organization, with documented authorization, sends realistic but harmless phishing emails to its own employees and records how each person responds. Nobody's credentials are actually stolen and no malware is delivered. The links lead to a landing page that records the click and, in most programs, immediately explains what the recipient missed. The output is a behavioral dataset: who clicked, who submitted data on a fake login page, who reported the message, how long each of those took, and how the results break down by department, role, and message type.
The exercise is sometimes called a phishing attack simulation, a phishing email simulation, or a simulated phishing campaign. The terms are interchangeable in practice. What matters is the distinction between the simulation and the training that surrounds it. The simulation measures. The training teaches. A phishing simulation on its own produces a number and changes very little. Security awareness training on its own produces attendance records and changes somewhat more. The two together, run on a repeating cycle where each simulation result determines what gets taught next, is what actually moves an organization's susceptibility.
There is a second distinction worth being precise about, because buyers routinely conflate the two. A phishing simulation tests people. A penetration test tests systems and, when social engineering is in scope, tests people as part of a broader attempt to reach a specific objective. A simulation program is continuous, low-intensity, and aimed at population-level behavior change. A social engineering engagement inside a penetration test is a point-in-time, high-intensity attempt to prove a path exists. Both are worth doing. Neither substitutes for the other.
The reason this exercise remains the most common single control in a security awareness program is unglamorous: email is still where most intrusions begin for small and mid-sized organizations. Business email compromise, credential harvesting, invoice fraud, and ransomware delivery all typically start with a message that a human being decided to trust. Every other control in the stack, including managed detection and response and email filtering, is designed to catch what gets through. A simulation program is how you find out how much is likely to get through in the first place, and how fast anyone would tell you.
How a Phishing Simulation Works
Six stages, from authorization to the report that leadership actually reads.
Authorization and Scope
The program begins with a written authorization from an executive sponsor naming who is in scope, what pretexts are permitted, what data will be collected, how long it will be retained, and who may see individual-level results. This document matters more than most organizations expect. It is the difference between an authorized security exercise and an unsanctioned deception of your own workforce, and it is the first thing a works council, a union representative, or an employment attorney will ask to see. Decide here whether executives are in scope. Excluding them is common and almost always a mistake, since they are the population attackers target hardest.
Technical Preparation
Simulation messages must reach the inbox, which means allow-listing the sending infrastructure in your secure email gateway and in Microsoft 365 or Google Workspace. This is where a surprising number of first campaigns quietly fail: the filter catches the simulation, delivery drops to a fraction of the population, and the resulting click rate looks wonderful for reasons that have nothing to do with your people. At the same stage, confirm that a one-click report button is deployed to every mail client in use, including mobile, and that reports route somewhere a human monitors. Brief the help desk so a wave of reports is recognized rather than escalated as a live incident.
Baseline Campaign
The first wave is a measurement, not a training event, and its purpose is to establish where you actually stand. Use a moderate-difficulty pretext that resembles what your industry genuinely receives rather than the most devious message the platform offers. Send to the entire in-scope population, stagger delivery across a working day rather than firing everything at 9 a.m., and let it run for a full week so late openers and vacationing staff are captured. Resist the urge to tune the result. A baseline that flatters you is useless as a comparison point for everything that follows.
The Teachable Moment
When someone clicks, what happens in the next ten seconds determines whether the exercise taught anything. The landing page should tell the person immediately and without condescension that this was a simulation, walk through the specific signals in the message that gave it away, and take under two minutes. Long mandatory modules assigned days later are the single most reliable way to build resentment toward a security program. Recognition for the people who reported matters just as much, and costs nothing: a short note thanking reporters, or a department-level scoreboard for report rate rather than click rate, changes the social meaning of the exercise.
Analysis Beyond the Headline Number
Break results down by department, role, tenure, and message type. The organization-wide click rate is a board slide. The actionable findings live underneath it: the finance team that opens anything resembling an invoice, the clinical staff who are unusually resilient to generic lures but vulnerable to messages that appear to come from a supervisor, the new hires in their first ninety days, the small group of repeat clickers who appear in every wave. Also record the messages nobody reported at all, because an unreported message that also went unclicked is not a success. It means the message was ignored rather than recognized, and the next one like it may not be.
Targeted Follow-Up and the Next Wave
Feed the analysis into the next cycle. Assign short, specific training to the groups the data identified rather than reassigning the same annual module to everyone. Schedule the next wave using a pretext family the population demonstrably struggles with, and raise difficulty gradually as numbers improve. Keep the cadence predictable to the security team and unpredictable to everyone else. Record each wave, its parameters, its results, and the remediation that followed, because that record is both your trend line and your audit evidence.
Phishing Simulation vs Security Awareness Training vs Penetration Testing
Three controls that overlap in conversation and almost never in purpose.
Buyers frequently ask which of the three they should purchase, as though they were alternatives. They answer different questions. A simulation asks how your population behaves under a realistic lure. Awareness training asks whether people know what to do. A penetration test with social engineering in scope asks whether a determined attacker can reach a specific objective through your people. Budget-constrained organizations usually start with the first two as a paired program, then add the third once the population-level numbers have stabilized.
| Dimension | Phishing Simulation | Awareness Training | Penetration Test |
|---|---|---|---|
| Question answered | How does our population actually behave? | Do our people know what to do? | Can an attacker reach a specific objective? |
| Frequency | Monthly or quarterly waves, continuous | Annual baseline plus targeted follow-ups | Annual or on significant change |
| Population | Everyone with an inbox | Everyone, with role-based modules | Whatever the objective requires |
| Primary output | Behavioral metrics and trend lines | Completion records and comprehension scores | Findings report with proven attack paths |
| Fails when | Run once a year with no follow-up | Delivered as a single annual video | Scoped so narrowly it cannot find anything |
| Audit value | Evidence of practiced, tested awareness | Evidence the requirement was delivered | Evidence of technical assessment |
| Typical owner | Security team or managed provider | Human resources with security input | Independent testing firm |
The practical sequence for most organizations: stand up security awareness training and a simulation program together so each informs the other, add a tabletop exercise once leadership needs to practice the decisions rather than the detection, and bring in independent testing when you want an outside party to prove what the internal numbers imply.
The Metrics That Actually Predict Resilience
Click rate is the number everyone reports. It is not the number that matters most.
Consider two organizations with an identical fifteen percent click rate. In the first, nobody reported the message and the security team learned about the campaign from the simulation platform. In the second, a third of recipients reported it and the first report arrived four minutes after delivery. The second organization would survive a real campaign and the first would not, and the metric they both lead with cannot tell them apart. This is why a serious program tracks the following set rather than the headline alone.
| Metric | What It Measures | Why It Matters |
|---|---|---|
| Click rate | Share of recipients who followed the link | The standard exposure indicator, easily distorted by pretext difficulty and delivery failures |
| Credential submission rate | Share who entered data on the landing page | Far closer to real-world loss than a click; a click is curiosity, a submission is compromise |
| Report rate | Share who reported the message | The capability you are actually building; the only metric that helps during a real campaign |
| Time to first report | Minutes from delivery to the first alert | Determines whether responders can pull remaining copies before the rest of the population opens them |
| Resilience ratio | Reports divided by clicks | The single best summary of program health; a ratio above one means more people help than fall |
| Repeat clickers | Individuals clicking across multiple waves | A small, persistent group that ordinary training does not reach and that needs a different intervention |
| Dwell time before click | Seconds between open and click | Distinguishes reflexive clicking from considered clicking, which need different remedies |
| Departmental spread | Variance between business units | Shows where culture or workload, rather than knowledge, is driving the risk |
One methodological warning that applies to every number above. Do not compare your results to published industry averages and conclude anything. Those figures aggregate wildly different pretext difficulties, delivery success rates, populations, and definitions of a click. The only comparison with analytical value is your organization against itself over time, holding pretext difficulty roughly constant. Internal trend beats external benchmark in every case.
How to Evaluate Phishing Simulation Software and Vendors
What separates the platforms, once you look past template libraries and dashboards.
Phishing simulation platforms demonstrate well. Every vendor shows a large template library, an attractive dashboard, and a chart that trends downward. The differences that matter surface in month four, not in the demonstration. When evaluating phishing simulation software or comparing phishing simulation vendors, weight these criteria over template count.
Delivery Reliability Into Your Actual Mail Environment
Ask for the documented allow-listing procedure for your specific stack, whether that is Microsoft 365 with Defender, Google Workspace, or a third-party gateway in front of either. Then ask what the platform reports when messages are filtered rather than delivered. A platform that silently counts filtered messages as delivered will hand you a flattering click rate built on a fraction of your population, and you will not discover the problem until an assessor asks how many messages actually landed.
Report Button Quality and Routing
The report button is the product. Confirm it works in Outlook desktop, Outlook web, the mobile clients your staff actually use, and any other client in the environment. Confirm where reports go, whether real threats reported by users can be triaged in the same queue as simulations, and whether the reporter receives acknowledgement. A platform where reporting a genuine phishing message and reporting a simulation are two different actions will train your people to do neither reliably.
Localized and Industry-Relevant Pretexts
Generic package-delivery lures wear out quickly and stop measuring anything. Look for the ability to author custom pretexts that reflect your industry, your vendors, and your internal systems, and check whether custom templates require professional services hours or can be built by your own team. For a medical practice, a fake patient portal notification measures something real. For a defense subcontractor, a message referencing a contracting portal does. A generic lottery scam measures nothing except who is not paying attention at all.
Training Integration and Assignment Logic
Check whether simulation results can automatically assign specific short modules, and whether that assignment is rule-based rather than all-or-nothing. The value of an integrated platform is that a finance-team invoice click assigns a four-minute invoice-fraud module rather than the same annual course everyone already took. Also verify how completion is tracked and exported, because that export is what your auditor will want.
Reporting That Maps to Your Frameworks
Ask to see the evidence export, not the executive dashboard. You need per-user and per-campaign records with dates, retained long enough to cover your audit period, in a format an assessor accepts. If your organization is subject to HIPAA, CMMC, PCI DSS, or the FTC Safeguards Rule, ask specifically how the platform's output maps to the awareness requirements in each. Platforms vary enormously here and it rarely comes up in a sales demonstration.
Data Handling and Employee Privacy
The platform will hold behavioral data about named employees. Establish where it is stored, how long it is retained, who inside your organization can see individual-level results, and what the vendor does with aggregate data. Decide your own internal disclosure policy at the same time. Many organizations restrict individual results to the security team and share only departmental aggregates with management, which preserves the trust the program depends on.
Whether You Are Buying a Tool or an Outcome
This is the question most organizations answer wrongly. A platform license is inexpensive and a program is not, because the program is the work: authorization, allow-listing, pretext design, wave scheduling, analysis, targeted follow-up, and the executive reporting that keeps it funded. Organizations without a dedicated security staffer routinely buy the license, run two campaigns, and let it lapse. If nobody on your team owns the recurring work, buy the managed outcome instead and let the license be someone else's problem.
What Auditors and Frameworks Expect
Simulation records are among the easiest pieces of awareness evidence to produce and the easiest to lose.
No major framework says the words "you must run a phishing simulation." What they say is that personnel must receive security awareness training appropriate to their roles, that the training must recur, and that the organization must be able to evidence both. Simulation results satisfy that requirement more convincingly than attendance sheets because they demonstrate practiced capability rather than delivered content. Assessors have noticed this, and simulation records now come up routinely in assessments even where no rule names them.
Under the HIPAA Security Rule, the security awareness and training standard at 45 CFR 164.308(a)(5) includes an addressable implementation specification for protection from malicious software and periodic security reminders. Simulation waves and their follow-up training are a defensible way to satisfy both, and the records document the periodicity that a reminders program otherwise struggles to prove. For defense contractors, NIST SP 800-171 requirement 3.2.1 requires that managers and users be made aware of the security risks associated with their activities, and 3.2.2 requires role-based training. Our page on CMMC control 3.2.1 covers what an assessor looks for in detail.
PCI DSS requires a formal security awareness program with personnel trained at hire and at least annually, with acknowledgement retained. The FTC Safeguards Rule, which reaches a much wider set of businesses than most owners realize, including auto dealers, mortgage brokers, tax preparers, and other non-bank financial institutions, requires security awareness training for personnel and periodic updates reflecting current risks. SOC 2 common criteria expect evidence that the organization communicates security responsibilities and evaluates whether personnel understand them.
The practical failure mode is never the exercise. It is the record. Organizations run simulations for two years, change platforms, and discover during an assessment that the historical evidence lives in a cancelled vendor account. Export campaign results, per-user outcomes, and training completions at the end of every wave, store them with your other compliance artifacts, and treat the export as part of the campaign rather than an afterthought. Our ComplianceArmor® platform generates and maintains the documentation set these frameworks require and keeps evidence attached to each control, so awareness records stay connected to the requirement they satisfy instead of drifting into a shared drive nobody can find at audit time.
Six Ways a Phishing Simulation Program Backfires
Each of these is common, and each converts a useful control into a liability.
Punishing the Clickers
The fastest way to destroy a program is to attach discipline to click results. People stop reporting, because a report is an admission that they engaged with the message at all. Some will warn colleagues out of band, which contaminates the data. A minority will start reporting every internal newsletter to be safe, which floods the queue. The exception worth defining in advance is the small group of persistent repeat clickers, who need a manager conversation and a different kind of coaching rather than a fourth identical module. Make that distinction explicit in policy before the first wave.
Pretexts That Cross the Line
Simulations using bonus announcements, layoff notices, benefits changes, or bereavement themes generate excellent click rates and lasting resentment. The organizational cost is real: staff conclude that security is something done to them rather than with them, and every subsequent initiative meets more friction. Attackers will use those themes, which is exactly why the honest answer is to teach the pattern directly in training rather than weaponize it against your own staff and spend the trust.
Measuring Delivery Failure as Success
If your gateway filters most of the simulation, the click rate reflects filtering rather than behavior. It looks like improvement. It is a measurement artifact. Always reconcile the count of messages the platform sent against the count actually delivered, and treat any wave with a large gap as invalid rather than encouraging.
Running It Once a Year
Annual simulations produce annual data points, and awareness decays on a much shorter cycle than twelve months. New hires arrive untested. Roles change. A single yearly wave measures a population that no longer exists in the same form. Monthly or quarterly waves against rotating segments cost little more in effort once the process is established and produce a trend line rather than a pair of disconnected numbers.
Exempting Leadership
Executives are targeted more precisely than anyone else in the organization, hold the broadest access, and are the population attackers research most carefully before a business email compromise attempt. Excluding them from simulations removes the most valuable data in the program and signals that the exercise is for the rank and file. If an executive objects, the honest response is that their inbox is the one attackers want most.
No Owner, No Cadence, No Budget Line
Programs die quietly when nobody owns the recurring work. The license renews, campaigns stop, and two years later someone discovers the account has been idle since the second wave. Name an owner, put the wave schedule on a calendar, and give the program a budget line so it survives the quarter when everyone is busy. Where there is no internal owner, a virtual CISO or managed provider is the practical answer.
How Petronella Technology Group Runs Simulated Phishing
Delivered as a managed program rather than a platform login and good luck.
Petronella Technology Group, Inc. has been securing regulated businesses from its Raleigh headquarters since April 2002, and simulated phishing has been part of our security awareness offering for years because it is the control that most reliably converts abstract training into measured behavior. We run it as an ongoing program: authorization and scoping with your executive sponsor, allow-listing and report-button deployment in your Microsoft 365 or Google Workspace environment, a baseline wave, recurring campaigns with pretexts drawn from what your industry actually receives, immediate teachable moments, targeted follow-up training, and an evidence export at the end of every wave that slots directly into your compliance file.
The program pairs with our security awareness training, which is authored by a CyberAB Registered Provider Organization, and with phishing protection on the technical side, because behavior and filtering are complementary rather than alternative controls. For organizations that want to see where they stand before committing to anything, our free phishing security test provides a first data point at no cost.
Craig Petronella, founder and MIT-certified cybersecurity professional, NC Licensed Digital Forensics Examiner (License #604180) and CMMC Registered Practitioner, has written fifteen books on business technology and security, including How Hackers Can Crush Your Business, which examines how attackers exploit ordinary trust inside small and mid-sized organizations rather than exotic technical weaknesses. That perspective shapes how we design pretexts: the goal is to reproduce the messages your people will genuinely receive, not to prove that a sufficiently clever email can fool anyone.
When a simulation reveals a genuine exposure rather than a training gap, the same team handles what comes next. Our managed detection and response service covers the endpoints, and our digital forensics practice handles investigation if a real compromise is discovered along the way, which happens more often than clients expect during a first engagement.
"Petronella Cybersecurity provides outstanding service! Their team is extremely knowledgeable, responsive, and truly cares about protecting their clients. They take the time to explain complex issues in simple terms and deliver real solutions, not just promises."
GB Entrainement, verified TrustIndex review. Rated 4.7 across 92 verified TrustIndex reviews.
Phishing Simulation Questions
What organizations ask most often before they run their first campaign.
What is a phishing simulation?
How often should we run phishing simulations?
What is a good click rate for a phishing simulation?
Should employees be told that phishing simulations are happening?
Is phishing simulation software enough on its own?
Do phishing simulations satisfy compliance requirements?
What is the difference between a phishing simulation and a penetration test?
Can Petronella Technology Group run our phishing simulation program?
Find Out How Your Team Actually Responds
Start with the free phishing security test, or have the team that has been securing regulated businesses since 2002 run a full simulation and awareness program for you. Free consultation, no long-term contract required.
Petronella Technology Group, Inc. / 5540 Centerview Dr., Suite 200, Raleigh, NC 27606 / 919-348-4912 / Last Updated: August 8, 2026