✓ OSCP · OSWE · OSEP certified | Joost performs every test himself — no juniors | Response within 1 business day | Based in Haarlem

Running a Phishing Simulation: What Can You Expect?

Running a Phishing Simulation: What Can You Expect?

More than 90% of all cyberattacks start with a phishing email. Yet phishing simulations still aren’t a standard part of many organisations’ security programmes. How does such a simulation work, what does it deliver, and what should you watch out for?

What is a phishing simulation?

In a phishing simulation, a security specialist sends fake phishing emails to your organisation’s employees — without them knowing in advance. The emails look realistic: they imitate well-known brands, internal systems or suppliers. If employees click a link or enter credentials, that’s recorded and reported — without any real harm occurring.

What gets tested?

  • Click behaviour — what percentage of employees click the phishing link
  • Data entry — how many employees enter login credentials on a fake login page
  • Reporting behaviour — how many employees report the suspicious email to IT or security
  • Department- and role-specific vulnerability — are finance, HR or management more vulnerable?

What does a phishing simulation look like in practice?

  1. Intake and goal-setting — We discuss the objective: awareness, risk measurement or compliance. We determine the scope (all employees, specific departments) and the type of phishing scenario.
  2. Scenario development — We build realistic, custom phishing emails: your IT department’s house style, a fake IT helpdesk request, a false invoice notification, or a spoofed CEO email.
  3. Execution — Emails are sent over a period of several days to two weeks, at various times.
  4. Measurement and logging — Every click, every completed page and every report is logged.
  5. Reporting — You receive a report with click rates per department, the most vulnerable scenarios, and concrete recommendations for training and technical measures.

What are realistic click rates?

Without prior preparation, on average 25–40% of employees click a convincing phishing email. After good awareness training, this drops to 5–15%. With advanced spear-phishing (personalised attacks), click rates are higher, even among trained employees.

Difference from a real phishing attack

A simulation is controlled, safe and focused on learning — no real harm is possible. A genuine phishing attack by criminals, of course, has real consequences. The simulation gives you an honest picture of your vulnerability before attackers exploit it.

What does it deliver?

  • Insight into your real human vulnerability
  • Concrete input for security awareness training
  • Meets the awareness requirements of NIS2, ISO 27001 and BIO
  • Measurable improvement possible on repeat (before/after comparison)

FAQ

Won’t employees get upset?

This is a common question. The simulation is meant to educate, not punish. Communicate this clearly to management beforehand — and make sure the simulation is followed by good explanation and training, not an accusatory message.

Does the works council need to approve it?

In the Netherlands, the works council has a right of consent for introducing systems that monitor employees. A phishing simulation falls into a grey area — discuss this with your legal advisor or HR department beforehand.

How often should you run a phishing simulation?

At least annually, preferably two to four times a year for lasting effect. One-off simulations lead to temporary awareness that fades quickly.

Request a phishing simulation  ·  More about our phishing services

Scroll to Top