Keepnet AI-powered human risk management platform logo
Menu
HOME > blog > what is phishing simulation

What Is a Phishing Simulation?

What a phishing simulation is, which channels to test, the metrics that matter beyond click rate, and the mistakes that break a program.

Ozan Ucar, Founder and CEO of Keepnet

What Is a Phishing Simulation?

Editor's Note: This article was updated on September 28, 2026.

A phishing simulation is a safe phishing attempt an organization sends to its own employees. It looks realistic, but nothing in it can cause harm.

The point is to give employees the chance to recognize it and report it, and to measure how well that is going. Those are the behaviors that matter when a genuine attempt arrives.

It is mainly for employees, though enterprises run it for contractors and the supply chain as well. And it is no longer only email. Attackers work through SMS, voice calls, QR codes, callback scams and messaging apps, so simulations follow them there.

What a phishing simulation involves

There are always three parts: a lure, a landing page that records what happened and nothing else, and a follow-up that turns the moment into learning.

None of it touches anything real. No credentials are captured, no data leaves the organization, and no system is compromised. What you get instead is a record: who engaged with the lure, who ignored it, who reported it, and how long that took.

The technique a simulation copies is catalogued as T1566, Phishing, in MITRE ATT&CK, with sub-techniques for attachments, links and services.

A simulated phishing attack is most useful when it repeats. One exercise gives you a number. A program run over months gives you a trend, and the trend tells you whether secure behavior is taking hold.

Repetition matters here. Recognizing a lure is a skill, not a fact, and skills tend to form through practice with feedback. That is why a program running through the year is a different thing from an annual briefing.

In Keepnet’s anonymised customer research, email phishing campaigns created in January through September were about twice as high in 2026 as in 2025 (up 98.3%).

Methodology: https://doc.keepnetlabs.com/resources/research-methodology Reference date: 2026-09-28.

What a phishing simulation is not

A simulated phishing test is not a penetration test. A penetration test probes technical controls. A phishing attack simulation looks at employee decisions.

A phishing simulation is not a compliance exercise. Completing a campaign proves an exercise happened, not that any employee is safer.

A phishing simulation is not an audit of individual employees. Naming employees who clicked can discourage reporting and damage trust in the program, and reporting is the one behavior it exists to build.

Why organizations run phishing simulations

Employees are still the most common route into an organization. The human element appeared in 62% of breaches analyzed in the Verizon 2026 Data Breach Investigations Report, and phishing accounted for 16% of initial access (p. 12). In the UK Cyber Security Breaches Survey 2025/26, 38% of breached businesses named phishing as the cause, and 69% of affected businesses called it the most disruptive attack they faced.

Volume has not fallen either. The Anti-Phishing Working Group recorded roughly 3.8 million phishing attacks across 2025, and the wider picture is in our roundup of phishing statistics.

Security leaders agree on where the pressure sits. In Gartner’s 2026 CISO Role-Based Survey, 66% of CISOs put email and spear-phishing in their top five threats, and 36% named attackers using AI as a top-three priority.

Awareness training alone has not closed this. The same survey program found that 81% of organizations had at least one phishing, vishing or smishing incident in the past year, and all of them already ran security awareness training. Knowing what phishing looks like and acting differently when one arrives are two separate things. Only the second one shows up in an incident report.

Exposure is also uneven. Keepnet’s 2025 New Hires Phishing Susceptibility Report, covering 237 organizations, found that 71% of new starters engage with a phishing lure in their first 90 days, and that new employees are 44% more likely to do so than longer-tenured colleagues. A program that gives every employee the same exercise at the same rate spends most of its effort on the employees least likely to need it.

Source: Verizon 2026 Data Breach Investigations Report, p. 12.

Source: UK Cyber Security Breaches Survey 2025/26.

Source: Anti-Phishing Working Group, Phishing Activity Trends Report, Q4 2025, p. 3-4.

Source: Gartner, "Don’t Let AI-Powered Phishing Simulations Paralyze Your Employees" (G00853107, June 2026), 2026 Gartner CISO Role-Based Survey (n=297).

Source: Gartner, "Ditch Security Awareness and Adopt AI-Powered Secure Behavior Management" (G00860839, September 2026), 2026 Gartner CISO Role Survey (n=297).

Source: Keepnet, 2025 New Hires Phishing Susceptibility Report (237 organizations).

How difficulty, targeting and timing are set

Difficulty is not fixed, and neither is who gets which scenario. A program sets both from what it already knows about the employee: their role, what their account can do, the language they work in, and how they responded last time. A finance approver with payment rights and a warehouse operative on a shared device do not face the same attacks, so they should not get the same scenario.

The most widely used way to rate difficulty is the NIST Phish Scale, which scores how hard a message is to spot. It matters because a click rate only means something next to the difficulty of the message that produced it. How to use the NIST Phish Scale.

Difficulty is also a moving target. Microsoft’s Digital Defense Report 2025 recorded a 54% click-through rate on AI-automated phishing against 12% for standard phishing. A lure that counted as difficult two years ago is now routine.

Timing works the same way. Many programs run monthly or quarterly, but there is no universal frequency, and a calendar is only a starting point.

The better question is when a simulation will be most relevant. A program that knows an employee’s role, their previous behavior and the threat patterns currently in play can send the exercise when the learning opportunity appears, rather than simply when another month starts.

This follows a similar idea in behavioral science known as just-in-time adaptive intervention: support is adapted to the individual and delivered close to a moment of risk or opportunity.

The goal is not to simulate more often. It is to simulate at the right moment for the right employee.

Source: Microsoft Digital Defense Report 2025.

Source: Nahum-Shani et al., "Just-in-Time Adaptive Interventions (JITAIs) in Mobile Health: Key Components and Design Principles for Ongoing Health Behavior Support", Annals of Behavioral Medicine, 52(6), 2018.

Source: Hsu et al., "Personalized interventions for behaviour change: A scoping review of just-in-time adaptive interventions", British Journal of Health Psychology, 2024.

How a phishing simulation works

A phishing simulation is a cycle, not a project with an end date. One campaign gives you a number that describes a single Tuesday. The cycle is what produces change, and it has three moves.

Test. Send a lure that looks like something the employee could plausibly receive, through a channel they actually use, and record opens, clicks, data submitted and reports.

Coach in the moment. A click opens the just-in-time learning page straight away, and that page teaches on the spot. It explains why the message was a simulation, what brand or process it was imitating, and which red flags were there to be caught. It is built on behavioral science, not on a warning notice, so it shows what the safe response looks like and has the employee do it there and then. The point is that the same cues are recognizable next time, whether next time is another simulation or a genuine attempt. This is the same timing principle at a smaller scale: the teaching arrives while the decision is still fresh.

There is a right answer to aim for. Deleting the message or moving it to spam is a correct response and better than acting on it. But the behavior worth building is reporting it through the report button, because that is the only response that reaches the security team. Programs that recognize and reward reporting see more of it: how gamification raises reporting rates.

Re-measure. Run the next campaign with a different scenario and compare. The comparison is the finding. One result describes a moment, a sequence describes a direction.

In the same anonymised customer research, email phishing campaigns created in H1 2026 were 1.97× H1 2025, and deliveries on those campaigns were 1.99×.

Methodology: https://doc.keepnetlabs.com/resources/research-methodology Reference date: 2026-09-28.

Most of the work sits in the first move, and the details matter: who to target, how often, which lure, how to reach the inbox without allowlisting, and who to consult before anything goes out. Full walkthrough with campaign settings and timing: how to run a phishing simulation campaig.

Which channels to test

Phone-based simulations produce a higher click rate than email ones, and most programs never run them. That is the clearest gap in the evidence.

Phone-based phishing simulations produce a click rate roughly 40% higher than email, and Keepnet contributed the voice and SMS data behind that finding to the Verizon 2026 Data Breach Investigations Report (p. 50, contributors list p. 118).

The underlying medians are about 1.4% for email-based simulations and about 2% for phone-centric ones (p. 50).

Our own campaign data says the same thing from a different angle. Across an anonymized subset of Keepnet customer programs between 1 January and 14 August 2026, simulated SMS messages reached a median delivery rate of 95.5% across 13,069 messages. Simulated voice calls in the same period connected at 97.9% across 1,799 attempts.

And employees respond differently on those channels. In the Keepnet Vishing Response Report, 70% of employees disclosed sensitive information or took an unsafe action when a simulated voice call reached them. That is a long way from what the same employees do with a simulated email. More on the pattern in our vishing statistics.

Buyers have noticed. Gartner records surging CISO demand for vishing and smishing simulation, and lists multivector simulation across email, voice and SMS as one of the things that separates current tools from the previous generation.

ChannelWhat it testsTypical scenario
EmailJudgment with time to re-readVendor invoice change, payroll update, MFA prompt
SMSMobile judgment, usually away from a deskParcel notice, account security alert
Voice callReal-time judgment with no chance to re-readIT support callback, spoofed internal number
QRPhysical-world trust, on or off a screenCode inside an email, poster in a lift, card on a cafeteria table
CallbackMulti-step attacks that begin in the inboxInvoice PDF carrying a phone number

Deepfake audio belongs inside the voice row, not beside it. It is a technique for making a call convincing, not a delivery channel of its own. It raises the difficulty of an existing test rather than adding a new one.

If a program only tests email, the channels where employees respond least safely are the ones it has never measured. Channel-specific guides: how to run an SMS phishing simulation, how to run a voice phishing simulation, quishing, callback phishing simulation and deepfake phishing simulation.

Source: Verizon 2026 Data Breach Investigations Report, p. 50 and p. 118.

Source: Keepnet customer programs, 1 January to 14 August 2026 (n=13,069 SMS messages; n=1,799 call attempts).

Source: Keepnet Vishing Response Report.

Source: Gartner, "Ditch Security Awareness and Adopt AI-Powered Secure Behavior Management" (G00860839, September 2026).

What a simulation asks employees to do

The channel is how a simulation arrives. The vector is what it asks the employee to do once it has. A single simulation can carry more than one: an email with an attachment that hides a QR code is one campaign testing three separate decisions.

Four vectors cover most programs. Click only, where following the link is the whole test. Attachment, where a file is included and any employee who opens it is shown that it was a simulation. QR, where a code sits in the message or is printed on something physical, which is why a code on a poster in a lift tests your building as well as your inbox. And data submission, where the destination looks like a genuine sign-in or request and the exercise measures who fills it in.

Every vector except click only can end on a page that asks for information, and this is where a simulation has to be built carefully. A properly designed one records that a submission happened and nothing else. The password is not captured, not transmitted and not stored. It never leaves the employee’s device. What an attacker would have taken is exactly what the exercise refuses to take.

The landing page is also served from a domain that belongs to the simulation, never from the brand being imitated. A campaign that mimics a Microsoft sign-in does not link to microsoft.com; it links to something like microsoft-login.com, controlled by the organization running the exercise. That detail is the tell. The page can be a pixel-accurate copy of the genuine sign-in screen and the address bar will still say it is not, which is exactly the check the exercise exists to teach.

What to measure

Click rate is the easiest number to produce and the least useful on its own. It describes exposure. It says nothing about whether any employee would raise the alarm during a genuine incident.

There is a harder problem underneath. Gartner argues that click rates are routinely manipulated, because programs are pushed to produce a low number: easier lures, narrower audiences, friendlier timing. A number you can engineer downward is not a measurement of risk. Gartner reads a click as a sign that a process was not followed, rather than simply that a message was not spotted. That is more useful to know, because you can redesign a process and you cannot redesign a moment of judgment.

MetricWhat it tells you
Click rateExposure. A baseline, nothing more
Report rateWhether employees act on suspicion. The core metric
Time to reportHow quickly your team would learn about a genuine incident
Repeat engagementWho needs coaching rather than another campaign
Susceptibility by roleWhere to spend training time
Trend over 3 to 6 monthsWhether any of this is working

Most programs still measure the wrong thing. Gartner found that 84% of security leaders track training completion as a top metric, against the 62% of breaches that involve the human element. Completion and breach reduction are not the same measurement, and only one of them appears in an incident review.

Report rate and time to report describe your defense. Click rate only describes the test. A program where clicks fall but reports stay flat has produced quieter employees, not safer ones.

You will also see programs report a fail rate, meaning the share of employees who engaged with the lure. It is the click rate with blame attached. We do not use the term, and neither does the UK National Cyber Security Centre, whose guidance warns that punishing employees for clicking on a message you sent them yourself carries legal risk, and advises counting how many employees reported the message alongside how many clicked.

Repeat engagement deserves separate handling. An employee who engages with three campaigns in a row is not telling you the program failed, they are telling you it has not reached them yet. The response is a conversation and a different format, not another campaign at the same difficulty.

Benchmark data and what a healthy report rate looks like: phishing simulation benchmarks.

Source: Gartner, "Redefine Phishing Simulations by Embracing High Click Rates" (G00859817, September 2026). Gartner opinion, not survey data.

Source: Gartner, "6 Ways to Transform Your Cybersecurity Awareness Program" (G00840741, March 2026), 2025 Secure Behavior Strategies Survey (n=65).

Source: Verizon 2026 Data Breach Investigations Report, p. 12.

Source: UK National Cyber Security Centre, "Phishing attacks: defending your organisation".

Phishing simulation best practices

Set a rhythm, then let risk override it. The calendar is the floor, not the plan. A group that reports well can go longer between routine campaigns. A group that does not needs shorter gaps and easier scenarios first. New starters need their own cadence in the first 90 days. Annual testing measures memory, not behavior.

Test the channels attackers use, not only the one that is easiest to automate.

Segment by role, seniority and exposure. A single company-wide campaign produces an average that describes nobody.

Deliver feedback in the moment and keep it under two minutes.

Announce the program, never the individual campaign. Employees should expect the exercise without being able to predict it.

Publish the reporting route everywhere and make reporting one action rather than a forwarded message.

Share what simulations reveal with the team that runs your mail gateway. The patterns that reach the inbox are filter intelligence.

Track the trend, not the campaign. One result is noise.

Match difficulty to the group instead of reaching for the hardest lure. The NIST Phish Scale gives a repeatable way to rate how hard a message is to spot, which makes results comparable between campaigns: how to use the NIST Phish Scale.

Mistakes that break a simulation program

Mimicking critical internal communications. Copying a system outage alert, a year-end financial deadline or a benefits enrollment notice damages confidence in genuine business messages, and Gartner finds this produces missed deadlines and compliance failures. Agree exclusion zones with each business unit in advance: which message types are off limits and which sender domains will never be used.

Punishing employees who click. It discourages reporting, which is the behavior you actually need, and it turns a security program into an HR problem.

Using lures that exploit personal circumstances. Bonus announcements, redundancy notices and bereavement themes produce high engagement and lasting resentment. The number is not worth the trust.

Running the exercise before the teaching. A simulation measures a skill employees have to be given first, otherwise the result records luck.

Measuring only clicks. Falling clicks with a flat report rate means employees have learned to ignore suspicious messages rather than report them.

Skipping the follow-up. Without coaching, a simulation is a test with no teaching attached.

Source: Gartner, "Don’t Let AI-Powered Phishing Simulations Paralyze Your Employees" (G00853107, June 2026).

Phishing simulation vs security awareness training

A phishing simulation shows what employees do. Security awareness training teaches them what to do. They answer different questions, and neither replaces the other.

Training alone produces knowledge you cannot verify. Simulation alone produces a measurement with nothing attached to it. Run together, the simulation shows who needs which lesson and the training closes the gap it found.

The practical sequence: teach the behavior, test it, coach in the moment, measure the trend.

Full detail on lawful basis, anonymization and works council consultation: GDPR and phishing simulations.

Run multi-channel phishing simulations with Keepnet

Keepnet runs simulations across email, SMS, voice, QR and callback scenarios from one place, assigns training the moment an employee engages with a lure, and reports click rate, report rate and time to report by role and department.

See how it works on the phishing simulator page, and we will run a baseline campaign with you.

SHARE ON

twitter
linkedin
facebook

Schedule your 30-minute demo now

You'll learn how to:
tickRun simulations on the channels attackers actually use, not email alone
tickMeasure report rate and time to report, not just clicks
tickGive employees the practice that changes what they do next time

Frequently Asked Questions

What is a phishing simulation?

arrow down

It is a safe rehearsal of a phishing attempt, run by an organization on its own employees. Nothing in it can cause harm. What it produces is a record of who engaged, who ignored it and who reported it, so training can go to the employees who need it.

What is the difference between a phishing simulation and a phishing test?

arrow down

They describe the same exercise. "Test" usually means a single campaign, while "program" implies a repeated cycle of testing and coaching. A one-off test gives a number. A program gives a trend.

How often should phishing simulations run?

arrow down

There is no universal frequency. Many programs run monthly or quarterly, and new starters and high-exposure roles usually need more than the rest of the organization. But the interval is the floor, not the plan. The campaign that matters most is often the unscheduled one, sent when a role starts being targeted or when an employee has just shown you a gap. Annual testing measures what employees remember, not how they behave.

What is a normal phishing simulation click rate?

arrow down

Around 1 in 70 for email and closer to 1 in 50 on the phone, going by the medians in the Verizon 2026 Data Breach Investigations Report (p. 50). Treat either as a reference point rather than a target. The rate on its own tells you how many employees engaged, not how many raised the alarm, and only the second number describes a defense.

What is a phishing simulation fail rate?

arrow down

It usually means the percentage of employees who engaged with a simulated lure, so it is the click rate under another name. We avoid the term. Once a number implies fault, employees start keeping quiet, and the report rate is the first thing you lose. The UK National Cyber Security Centre gives the same advice: count how many employees reported the message alongside how many clicked.

Is a low click rate a good result?

arrow down

Not on its own. You can lower a click rate by choosing easier lures, narrower audiences or friendlier timing, which is why Gartner treats it as a number programs are pushed to engineer downward. Read it alongside report rate and time to report. A falling click rate with a flat report rate is a warning, not a win.

Why do voice and SMS simulations produce higher click rates than email?

arrow down

A caller sets the pace, and a message on a phone is read once, usually away from a desk, so there is no second look. The gap is measurable: phone-centric simulations run roughly 40% above email in the Verizon 2026 Data Breach Investigations Report (p. 50). Keepnet’s own voice research points the same way, and the channels section above carries the figures.

Should employees who click be punished?

arrow down

No. Punishment discourages reporting, and reporting is what shortens a genuine incident. The right response is short, immediate training and a clear route to report next time.

Can we use the phishing simulation built into Microsoft 365?

arrow down

If you want to test the inbox, it is a reasonable starting point. Microsoft delivers simulations by email and through Teams, and its documentation lists QR code payloads for several of its social engineering techniques. What it does not cover is SMS or live voice calls, which is where the measured response is worst. So it answers part of the question, not all of it. Licensing depends on your Microsoft plan, so check what your tenant includes before planning around it.