Skip to main content
Category: Security Awareness & Training

Simulated Phishing

Also known as: Phishing Simulation, Phishing Test
Simply put

Simulated phishing is a controlled exercise in which an organization sends its own employees fake but realistic phishing emails to see how they respond. The goal is not to trick staff for its own sake, but to measure how well people recognize and report suspicious messages and to identify where additional training may help. Unlike a real attack, the emails are harmless and the results are used to strengthen awareness.

Formal definition

Simulated phishing is a cybersecurity exercise in which an organization dispatches fabricated yet realistic deceptive emails, modeled on genuine phishing tactics, to its own staff in order to gauge susceptibility and measure the ability to recognize and appropriately respond to phishing attempts. Programs typically capture behavioral metrics such as click rates and reporting rates, and often pair simulations with instant feedback or targeted training. It functions as a governance and awareness control that informs risk assessment and training strategy; it tests human response rather than validating technical email defenses, and its value depends on ethical design, defined scope, and follow-up rather than on any single simulation outcome.

Why it matters

Phishing remains one of the most common ways attackers gain an initial foothold in an organization, and it targets people rather than technology. Technical email defenses can filter many malicious messages, but they cannot catch everything, which means the human response to a suspicious email is often a meaningful line of defense. Simulated phishing gives an organization a controlled, low-risk way to understand how its workforce actually behaves when confronted with a realistic lure, rather than assuming that awareness training alone has changed behavior.

The value of simulated phishing lies less in any single result and more in what it reveals over time. By capturing behavioral metrics such as click rates and reporting rates, an organization can identify where additional training may help, track whether awareness is improving, and inform its broader risk assessment and training strategy. Increased reporting of suspicious messages is often a more constructive indicator of program health than click rates alone, because it reflects employees actively participating in defense.

It is important to be clear about what simulated phishing does and does not accomplish. It tests human response, not the effectiveness of technical email controls, and its usefulness depends heavily on ethical design, defined scope, and meaningful follow-up. Poorly designed campaigns that aim to embarrass staff can erode trust and reduce reporting, undermining the very outcome the exercise is meant to strengthen. A single simulation is a snapshot; the control derives its value from sustained, well-governed use paired with feedback and training.

Who it's relevant to

Virtual and fractional CISOs
A virtual or fractional CISO typically directs and advises on security awareness strategy, and simulated phishing is a common component of the awareness and governance programs they help design. In most engagements a vCISO defines the objectives, scope, and ethical parameters of a simulation program and interprets the resulting metrics to guide training strategy, but they generally do not perform hands-on campaign administration unless that is explicitly contracted. Accountability for acting on the results, and for the security decisions that follow, usually remains with the client organization.
Security and IT leaders
Internal security and IT leaders often own the operational side of running simulations, including selecting tooling, launching campaigns, and coordinating follow-up training. They rely on click and reporting metrics to understand where awareness gaps exist and to demonstrate program progress over time. These leaders should treat simulated phishing as a measure of human response rather than a validation of technical email defenses, which require separate testing.
Business and executive stakeholders
Executives and business leaders are relevant because simulated phishing is a governance and business risk activity, not a purely technical one. Their support shapes the culture around the program, including whether it is framed as constructive rather than punitive, which in turn affects reporting behavior and overall value. Because organizational accountability for security decisions typically rests with client officers, executive engagement helps ensure results translate into meaningful action.
Organizations pursuing compliance readiness
Organizations working toward frameworks or standards that expect security awareness activities may use simulated phishing to support and evidence their training programs. It can contribute to readiness by demonstrating ongoing awareness efforts, but it does not by itself guarantee compliance or certification. Its contribution depends on how it fits within a broader, well-governed program and on the organization's maturity and follow-through.

Inside Simulated Phishing

Simulated Phishing Campaign
A controlled exercise in which an organization sends benign but realistic phishing-style messages to its own employees to measure susceptibility and reinforce awareness. It is a training and measurement tool, not an actual attack.
Baseline and Metrics Collection
The capture of measurable indicators such as click rates, credential submission rates, and reporting rates. These metrics establish a baseline and track change over time rather than guaranteeing behavioral improvement.
Targeting and Scenario Design
The selection of recipient groups and the construction of message scenarios, which may vary in difficulty and pretext. Scenario realism and scope typically depend on organizational context and stakeholder agreement.
Follow-Up Training and Remediation
The educational component delivered to users who interact with a simulation, often described as just-in-time or point-of-failure training, intended to reinforce recognition of phishing indicators.
Reporting Mechanism Integration
The pathway employees use to report suspicious messages, which a simulation program often exercises and measures alongside click behavior to gauge active detection culture.
Governance and Program Oversight
Where a virtual CISO typically contributes: setting objectives, defining scope, interpreting results, and integrating findings into the broader security awareness and risk program. This is advisory and strategic rather than hands-on campaign administration.

Common questions

Answers to the questions practitioners most commonly ask about Simulated Phishing.

Does running simulated phishing campaigns mean my virtual CISO is handling incident response and security operations?
No. Simulated phishing is a governance and awareness activity, not an operational security function. A virtual CISO may recommend, design, or oversee a simulated phishing program as part of a broader security awareness and human-risk strategy, but conducting live incident response, SOC monitoring, or hands-on tool administration is typically out of scope for a vCISO engagement unless explicitly contracted. In many engagements the actual campaign execution is delegated to internal staff or a specialized vendor, with the vCISO providing direction and interpreting results at the program level.
If we run simulated phishing regularly, does that guarantee we won't fall victim to a real phishing attack or breach?
No. Simulated phishing is intended to measure and improve user susceptibility and reinforce awareness over time; it does not guarantee breach prevention. Human behavior, attacker techniques, and organizational conditions vary, so results should be treated as indicators of relative risk and training effectiveness rather than assurances of protection. A virtual CISO can help set realistic expectations and position simulated phishing as one component within a layered program rather than a standalone safeguard.
How does a virtual CISO typically fit into a simulated phishing program?
A virtual CISO generally operates at the strategy and governance level: defining objectives, recommending frequency and difficulty progression, establishing metrics, and interpreting outcomes for leadership. They often advise on how results feed into broader risk decisions and awareness training. Day-to-day execution, platform administration, and campaign delivery are frequently handled by internal teams or a dedicated vendor, with the specific division of labor varying by engagement scope and provider.
Who is accountable for how simulated phishing results are used within the organization?
Accountability for decisions arising from simulated phishing results, such as disciplinary approaches, remediation requirements, or communications to staff, typically remains with the client organization and its officers. A virtual CISO advises on and may direct the program, but legal and organizational accountability generally stays with the client unless a contract specifies otherwise. Establishing a clear, non-punitive use policy up front often depends on client cooperation and stakeholder alignment.
How often should simulated phishing campaigns be run?
There is no universal cadence, and frequency may vary by provider, organizational maturity, and risk profile. In many engagements a virtual CISO recommends a recurring schedule that balances measurable reinforcement against user fatigue, and adjusts difficulty over time as awareness improves. The appropriate rhythm depends on factors such as workforce size, prior training, and how results are integrated into broader awareness efforts, so it should be defined within the engagement scope rather than assumed.
How can simulated phishing support compliance-related objectives?
Simulated phishing can support security awareness expectations referenced in frameworks and standards, and may contribute to readiness activities for regimes where user training is relevant. However, a virtual CISO engagement supports readiness rather than asserting certification or guaranteeing compliance. The program should be documented as part of a broader awareness and governance effort, with its role in any specific framework clarified rather than overstated. The value of these efforts often depends on defined scope and access to stakeholders.

Common misconceptions

Simulated phishing prevents breaches or guarantees that employees will not fall for real attacks.
Simulated phishing is an awareness and measurement tool that can reduce susceptibility over time, but it does not guarantee breach prevention. Outcomes vary by organizational maturity, participation, and how results are acted upon, and no program eliminates human error entirely.
A virtual CISO personally runs, administers, and monitors phishing simulation platforms as part of a standard engagement.
A vCISO typically advises on strategy, scope, cadence, and interpretation of results, and directs the program at a governance level. Hands-on tool administration, campaign execution, and day-to-day monitoring are often out of scope unless explicitly contracted, and may be delivered by internal staff or a separate provider.
High click rates on a simulation mean the security program has failed, or low click rates mean the organization is secure.
Click and reporting rates are indicators, not verdicts. They reflect a point-in-time measurement of awareness and should be interpreted alongside reporting behavior and program maturity. Metrics inform where to focus training rather than certifying overall security posture.

Best practices

Define clear objectives and scope before launching, agreeing with stakeholders on which groups are targeted, what scenarios are appropriate, and how results will be used.
Establish a baseline and track trends over time rather than treating a single campaign result as a definitive measure of risk.
Pair every simulation with follow-up or point-of-failure training so that employees who interact with a message receive reinforcement rather than only being scored.
Measure and exercise the reporting mechanism, not just click rates, to encourage a culture of active detection and reporting.
Use results to inform governance and program decisions, keeping in mind that accountability for security decisions and outcomes remains with the client organization and its officers.
Avoid punitive framing that can discourage reporting, and set realistic expectations that simulated phishing supports awareness rather than guaranteeing protection against real attacks.