Your employees receive a suspicious email. Some delete it. Some report it. Someone clicks the link. Fortunately, nobody has just handed their Microsoft credentials to a cybercriminal. This one was a phishing simulation. But what happens next?
If you add the click to a report, give the employee a metaphorical slap on the wrist, and send another fake phish six months later, probably not much. Done well, however, phishing simulations give employees regular, realistic opportunities to practice spotting the techniques used in genuine phishing attacks, without the consequences of getting it wrong for real.
So, do phishing simulations actually work? It’s a bit more nuanced than a simple “phuck yeah, they do.” To quote Reverend Lovejoy in The Simpsons (you know, season 8 episode 8*, Hurricane Neddy, when Flanders asks whether God’s punishing him) “Short answer yes with an if, long answer no with a but.” Yes, they work IF used properly as part of a wider SAT program. No, they won’t make your employees security experts BUT when there’s relevant tracking, training and follow-up in place they are a key part of your SAT arsenal.
*Admittedly towards the tail end of The Simpsons’ golden age. It’s no Last Exit To Springfield or Homer at the Bat, but we thought it was popular enough to use as a reference. Probably would have worked better if we hadn’t drawn attention to it. Moving on…
Phishing simulations are controlled exercises that send employees realistic but harmless phishing emails to test how they respond. Like real phishing attacks, they might use urgency, authority, curiosity, familiar brands, or requests to click links and take other actions.
Unlike the real thing, clicking doesn't result in malware, stolen credentials, or an awkward conversation about why somebody just transferred $30,000 to "the CEO." Instead, simulations give employees safe, practical experience recognizing phishing techniques and help organizations identify where additional education might be needed.
Yes, phishing simulations can work, but the evidence suggests their effectiveness depends heavily on how they're designed, delivered, and supported by wider security awareness training.
In Phishing in Organizations: Findings from a Large-Scale and Long-Term Study, researchers Daniele Lain, Kari Kostiainen, and Srdjan Capkun followed more than 14,000 employees for 15 months. They found that conventional embedded training did not make employees more resilient to phishing and could even have unintended negative effects. However, employees collectively provided an effective phishing detection mechanism when given the ability to report suspicious emails.
More recently, Andrew T. Rozema and James C. Davis studied 12,511 employees in Anti-Phishing Training (Still) Does Not Work. Their training interventions produced no significant overall improvement in click or reporting rates. However, the difficulty of the simulated phish had a substantial effect: click rates increased from 7% for easy lures to 15% for difficult ones.
That sounds pretty damning until you look at the wider picture.
A 2025 longitudinal study, Sustaining Cyber Awareness: The Long-Term Impact of Continuous Phishing Training and Emotional Triggers, followed more than 1,300 employees across 20 organizations for 12 months. Researchers found that sustained phishing simulations and targeted training approximately halved successful compromise rates within six months.
So, "do phishing simulations work?" might be the wrong question.
A better one is: what makes a phishing simulation program work?
A low click rate doesn't automatically equal success. That's why NIST developed its Phish Scale, which adds context to phishing simulation click and reporting rates by considering how difficult an email is for a human to detect.
An obviously dodgy email that almost everybody spots might produce a beautiful graph for your next cybersecurity report, but it doesn't necessarily tell you what those employees will do when a convincing phishing email arrives.
Good phishing simulations should instead:
The goal isn't to trick employees. It's to make them better prepared to recognize someone who genuinely is trying to trick them.
Sometimes, but there's an important distinction between phishing simulations and security awareness training more broadly.
Cybersecurity frameworks, regulations, and cyber insurance policies may require or encourage ongoing cybersecurity awareness education, including phishing and social engineering. However, requirements vary, and there is no universal rule that every business must run phishing simulations.
Simulations can nevertheless provide a measurable way to demonstrate ongoing security awareness and track behavior over time. Your insurance agent should be able to help determine which cybersecurity compliance standards and cyber insurance requirements apply to your MSP and your clients.
Phin's phishing simulations are designed around continuous learning rather than occasional "gotcha" tests. Realistic phishing emails are delivered throughout the year, and if someone clicks, Phin immediately launches a Learning Moment explaining the warning signs in the exact email they just clicked.
Phin also gives employees a Report Phishing button, with positive feedback when they correctly report a simulated phish. After all, recognizing and reporting something suspicious is exactly the behavior businesses should want to reinforce.
For MSPs, effective phishing simulations also need to be manageable at scale.
Phin provides pre-built phishing content and continuous automated campaigns, allowing an MSP to configure a program and keep it running without manually rebuilding campaigns for every client. MSPs that need something more specific can also create their own phishing templates and associated Learning Moments.
That means consistency for end users without creating a mountain of repetitive administration for the managed service provider running the program.
This is where the theory becomes considerably more interesting.
Kelley Create uses Phin to manage security awareness training for more than 6,400 active users across 148 clients. Between month one and month 36 of using Phin, its overall phishing click rate across those clients fell by 72.66%.
Certified CIO has seen similar long-term behavioral improvement, with its overall phishing simulation click rate decreasing by more than 21% between months three and 36. Joel Chambers also highlighted the importance of reporting: "We've seen a dramatic downtick in the number of failed sims over time, and the number of incidents that derive from email clicks," he said. "Getting people to actually report suspicious activities is the hardest part of our job, and Phin makes that easy."
Results will vary, but these examples demonstrate what sustained phishing simulation programs can look like when they're given time to change behavior.
No phishing simulation can guarantee that an employee will never click a malicious link.
That's not a realistic objective.
The aim is to make the right response more likely when a real phishing email eventually lands: recognize the warning signs, stop before taking a dangerous action, and report the message so someone can investigate it.
That takes more than sending the occasional fake email and counting how many people fail.
Effective phishing simulations need realistic threats, regular practice, relevant feedback, positive reinforcement, and enough consistency to turn cybersecurity knowledge into everyday behavior.
That's what a phishing simulation should be: not a test employees are afraid to fail, but practice for an attack you really don't want them to fail.
[Learn more about phishing simulations with Phin.]
There's no single frequency that's right for every organization, but phishing simulations are most useful as an ongoing program rather than a one-off annual test. Regular simulations expose employees to different phishing techniques and provide better information about behavior over time. It is common for businesses to run monthly or bi-weekly phishing simulations depending on their industry’s susceptibility to phishing attacks. This keeps phishing top of mind without completely disrupting their productivity.
There's no universal "good" click rate. The difficulty and relevance of the simulation matter significantly. NIST's Phish Scale was developed specifically to provide this context, because a low click rate on an easy phishing email can create a false sense of security. Organizations should consider click rates alongside simulation difficulty, reporting behavior, and long-term trends. This graph, however, helps set a benchmark based on industry:
Employees should understand that phishing simulations form part of their organization's security awareness program, but they don't necessarily need to know when an individual simulation is coming. Advance warning of each exercise can undermine its ability to reflect normal email behavior.
Not universally. Cyber insurance requirements differ between insurers and individual policies. Some insurers may ask about security awareness training, phishing testing, or related controls during underwriting. Businesses should check the requirements of their specific policy rather than assuming phishing simulations are either universally required or unnecessary.