How to Simulate Phishing Attacks on Your Staff

Phishing remains one of the most effective attack vectors used against organisations of all sizes. Not because the technology is weak, but because humans sit at the centre of most systems. Over the past few years, security awareness has improved noticeably, yet real world behaviour still tells a more nuanced story.

Recently, I ran a phishing simulation for a client using CanIPhish, a phishing simulation and awareness platform. The goal was straightforward: test how employees respond to realistic phishing emails and identify gaps in behaviour, not to shame individuals or “catch people out”.

What we found was encouraging and also quietly concerning.

 

Why Run a Phishing Simulation?

Most organisations believe they are “reasonably secure” against phishing. Staff are told not to click suspicious links, antivirus software is installed, and email filtering is in place. However, belief and reality do not always align.

Phishing simulations serve a specific purpose:

  • To assess how employees behave under realistic conditions
  • To test awareness, not just knowledge
  • To identify where training is effective and where it falls short

Importantly, simulations should always be run ethically, with management approval, clear scope, and no punitive intent. The aim is resilience, not embarrassment.

 

Why I Chose CanIPhish

From a practitioner’s perspective, CanIPhish stood out for a few reasons.

First, it was easy to set up. The platform does not require excessive configuration, complex infrastructure changes, or heavy technical overhead. This makes it suitable not just for large enterprises, but also for small and medium businesses that lack dedicated security teams.

Second, it allowed me to run a campaign using legitimate-looking phishing emails. This is critical. Poorly designed simulations teach the wrong lesson. Real attackers do not send obviously broken emails full of spelling mistakes and red flags. Modern phishing campaigns are polished, contextual, and often convincing.

Finally, the reporting was clear and actionable. For a consultant or IT manager, this matters far more than flashy dashboards. The ability to explain outcomes to non technical stakeholders is just as important as collecting the data itself.

 

The Campaign Setup

The phishing campaign was designed to mirror common real-world attacks:

  • A believable email theme relevant to the organisation
  • Legitimate branding and tone
  • Links that appeared authentic at a glance

No attachments or malware were involved. The focus was purely on user decision-making: click, ignore, or report.

All relevant stakeholders were aware of the simulation, and the campaign was conducted within agreed boundaries. Transparency and consent are non negotiable when running exercises like this.

 

The Results: A Mixed Success

At first glance, the results looked excellent.

None of the employees interacted with the phishing content. No links were clicked. No credentials were entered. From a traditional metric standpoint, this is often reported as a “successful” outcome.

However, a deeper look revealed an important issue.

Not a single employee reported the phishing email.

The emails were ignored or deleted, but no reports were made through the organisation’s reporting process.

 

Why This Matters More Than You Think

Many organisations train staff to “not click suspicious links” — and stop there. While this is important, it is only half the equation.

In real-world security operations, reporting is critical.

When an employee reports a phishing email:

  • Security teams can analyse the threat
  • Email filters can be updated
  • Other employees can be warned
  • Indicators of compromise can be blocked

Silence, even when no one clicks, creates blind spots.

If ten people receive a phishing email and all quietly delete it, the organisation learns nothing. Worse, if the same campaign reaches someone less experienced later, the opportunity to intervene early is lost.

 

The Gap Between Awareness and Action

This campaign highlighted a common trend I see across many organisations: employees know what not to do, but not what they should do instead.

Avoidance behaviour feels safe. Reporting feels risky.

Staff may worry about:

  • Being wrong
  • Causing unnecessary trouble
  • Appearing foolish
  • Triggering an investigation

If reporting is not normalised, simple, and encouraged, people default to doing nothing.

 

Improving Phishing Readiness

Based on this experience, a few practical lessons stand out.

1. Reporting Must Be Explicitly Trained

Security awareness training should treat reporting as a first-class action, not an optional extra. Employees should know:

  • Exactly how to report a suspected phishing email
  • That reporting is encouraged, even if they are unsure
  • That there are no negative consequences for false positives

2. Make Reporting Easy

If reporting requires multiple steps, logging a ticket, or finding the right email address, it will not happen.

One-click reporting buttons, clear inbox rules, or simple forwarding processes significantly increase reporting rates.

3. Measure More Than Clicks

Click rates are useful, but incomplete.

Mature phishing programs track:

  • Clicks
  • Credential submissions
  • Report rates
  • Time to first report

In this case, zero clicks but zero reports tells a very specific story.

4. Close the Feedback Loop

When someone reports a phishing email, acknowledge it. Even a simple automated response reinforces the behaviour and builds confidence.

 

Final Thoughts

Running this phishing simulation reinforced an important truth: security maturity is not binary. An organisation can be strong in one area and weak in another at the same time.

The fact that employees did not interact with the phishing emails is a positive outcome. It shows awareness training has had an effect.

However, the lack of reporting highlights a gap that needs attention. In real incidents, visibility and response speed matter just as much as prevention.

Tools like CanIPhish make it easier to test these scenarios in a controlled, ethical way. But the real value comes from what you do with the results.

Phishing resilience is not just about avoiding mistakes – it is about creating a culture where speaking up is the default response.

That is where the next level of security maturity is built.