An employee has just clicked a link in a fake invoice email, and now you’re wondering how many others would have done the same. Perhaps a cyber insurance renewal asked whether your business runs phishing simulation training, and you didn’t have a confident answer. Your last security review might have flagged the same gap: nobody’s actually testing whether staff can spot a scam.
This article explains what phishing simulation training does, what a realistic programme actually looks like, and how to tell if a one-off test is doing more harm than good.
Key Takeaways
- Phishing simulation training sends realistic fake phishing emails to staff to measure and reduce how many people click, then follows up with targeted training for anyone who falls for it.
- Phishing was involved in around 85% of the cyber incidents UK businesses reported in the past year (DSIT Cyber Security Breaches Survey 2025/2026).
- Globally, an average of 33.2% of employees click a phishing email before any training takes place, falling to around 24.7% for smaller organisations under 250 employees (KnowBe4, 2026 Phishing by Industry Benchmarking Report).
- A single annual phishing simulation isn’t enough on its own. Click rates fall sharply straight after training but drift back up within weeks without repetition, which is why frequency matters more than any single simulation.
- Phishing simulation and phishing awareness training are related but different: simulation tests behaviour, awareness training builds the knowledge that changes it.
- Cyber Essentials Plus, cyber insurance renewals, and client security questionnaires increasingly expect evidence of regular testing. A slide deck shown once a year isn’t enough on its own.
What Is Phishing Simulation Training?
Phishing simulation training sends realistic fake phishing emails to employees to measure how they respond. It records who opens the email, clicks links, downloads attachments, submits credentials, or reports the message, then follows up with targeted phishing awareness training based on individual behaviour rather than assumptions.
For a business with 50 to 200 users, this matters because phishing doesn’t need to fool every employee to succeed. It only needs one person, on one email, to hand an attacker a foothold into your systems.
Most businesses already run some form of security awareness training, whether that’s an annual video course or a slide deck during onboarding. Phishing simulation training answers a different question: what staff actually do when a convincing email lands in their inbox during a normal working day.
How Phishing Simulation Training Actually Works
Phishing simulation training is an ongoing cycle built around three connected stages.
1. Simulation
Realistic phishing emails, styled on genuine attack patterns such as fake invoices, IT password reset requests, or executive impersonation, are sent to staff without warning.
2. Measure Behaviour
The service tracks who opened the email, who clicked a link, who entered credentials on a fake login page, and how quickly anyone reported it as suspicious.
3. Follow-up Training
Anyone who fell for the simulation gets short, targeted training explaining what they missed and what to look for next time, rather than a generic company-wide lecture that treats everyone the same.
Real programmes repeat this cycle regularly rather than annually. Running simulations only once a year tells you almost nothing about ongoing risk, since staff, threats and attack styles all change constantly.
Related reading: Why Social Engineering Works and How to Stay Ahead of It
What a Realistic Phishing Simulation Looks Like

Generic test emails don’t produce useful results because real attackers don’t send generic emails. A well-designed simulation mirrors the specific tactics criminals actually use against UK businesses.
- A fake invoice or overdue payment notice styled after a supplier your business genuinely uses is one of the most common templates, since finance teams are trained to act on them quickly rather than question them.
- An IT password reset or account suspension warning, made to look like it’s come from Microsoft 365 or your internal helpdesk, plays on urgency and the instinct to fix an access problem before it disrupts the working day.
- Executive impersonation, where an email appears to come from a director or senior manager asking for an urgent transfer, document, or gift card purchase, targets the natural reluctance to question a request that appears to come from someone senior.
- A parcel delivery or courier notification, asking the recipient to confirm an address or reschedule a delivery, works because it’s mundane enough that most people click without thinking twice.
The best simulation programmes vary these templates and rotate them regularly, since staff who’ve seen one version of a test email will simply learn to spot that specific email rather than the underlying pattern an attacker would actually use.
Phishing Simulation vs Awareness Training: What’s the Difference?
These two terms get used interchangeably, but they measure different things.
- Phishing awareness training is the teaching side: sessions, videos or guidance explaining what phishing looks like, why it works, and what staff should do if they spot it.
- Phishing simulation is the testing side: it checks whether that knowledge actually holds up when someone is busy, distracted, or dealing with a convincing fake invoice at 4 pm on a Friday.
Awareness training without simulation is a guess, since you’re hoping the message landed. Simulation without awareness training is just a scorecard with no way to improve it. The two work best together, which is why managed cyber security built around both tends to outperform either one bought separately.
What Happens After a Simulated Phishing Test
Running the test is the easy part. What happens afterwards is what actually reduces risk.
Anyone who clicks gets immediate, specific feedback: what gave the email away, and what to check before clicking next time. This works best when it’s delivered immediately after the mistake, while it’s still fresh in the employee’s mind.
Repeat clickers get flagged for closer attention rather than punishment. Someone who fails three simulations in a row is a bigger operational risk than someone who fails once, and that pattern is only visible if results are tracked over time.
Results feed into the wider security picture. A department with a high click rate might need role-specific training, tighter email filtering, or closer monitoring through a managed SOC until the risk comes down.
Effective phishing simulation programmes also measure positive behaviours, like how many employees report a suspicious email rather than click it. Organisations should track how many employees report suspicious emails using the “Report Phishing” button in Microsoft Outlook or by notifying the IT team. Reporting rates provide valuable insight into how confidently staff recognise potential threats and whether security awareness is improving over time.
Here’s what that looks like in practice: After a simulated phishing campaign, a 120-person manufacturing business discovers that three members of its finance and procurement teams clicked a fake invoice email, and one employee entered their Microsoft 365 credentials on the simulated login page. That person gets immediate feedback on what gave the email away, their manager is notified so the pattern can be tracked, and the affected account has its password reset and Multi Factor Authentication checked as a precaution, even though the simulation itself was never a real threat.
Six weeks later, a second simulation using a different template is sent to the same teams. If the click rate has genuinely fallen, that’s evidence that the training is working. If it hasn’t, that’s useful information too, and points towards a different approach for that department.
The scale of the underlying problem makes this worth doing properly. Phishing was involved in around 85% of the cyber incidents UK businesses reported in the DSIT Cyber Security Breaches Survey 2025/2026, and KnowBe4’s 2026 Phishing by Industry Benchmarking Report found that organisations running continuous simulation and training over a full year cut susceptibility by an average of 87%, down to around 4.2%. The starting point for most businesses, before any training, is that close to a third of staff click on a phishing email without the attacker needing a particularly sophisticated approach.
While simulation testing helps you identify and train staff who might fall for a live attack, it doesn’t show you if your business credentials have already been compromised elsewhere. We often find that simulated click rates drop fastest when businesses combine training with proactive dark web monitoring, which alerts you the moment your team’s email addresses and passwords surface on criminal marketplaces, often long before an attacker has the chance to use them in a live phishing campaign.
Related reading: Ransomware Prevention Checklist 2026
Signs Your Business Needs Phishing Simulation Training
Every business with staff and email has some exposure here, but certain situations make regular phishing simulation a clear priority.
- You’re working towards or maintaining Cyber Essentials Plus, or a client’s supply chain requirements, where regularly testing staff awareness matters as much as delivering the training itself.
- Your cyber insurance renewal has asked whether you run regular phishing simulations, which a growing number of policies now treat as a baseline control rather than a bonus.
- You’ve had a previous incident that started with a suspicious email, even one that was caught before it caused damage.
- Your business has grown past the point where you know, informally, which employees would spot a scam and which wouldn’t.
- Staff regularly handle invoices, payments, or client data by email, which makes finance and admin teams a specific target for convincing fake requests.
If your business also handles personal data, remember that a phishing-driven account compromise involving personal data may still need to be reported to the Information Commissioner’s Office within 72 hours of you becoming aware of it, regardless of how the attacker got in.
Related reading: What Is a Managed SOC and Does Your Business Need One in 2026?
If you don’t currently know how your team would perform against a realistic phishing attempt, that’s worth finding out before an attacker does it for you. Request a free cyber security assessment, and we’ll help you understand where the risk actually sits.

How Nexus Delivers Phishing Simulation Training
Phishing simulation is already built into our managed cyber security service, run alongside wider protections such as Cyber Essentials support and vulnerability scanning, rather than sold as an isolated one-off exercise.
Our approach follows the same cycle outlined above: realistic simulated campaigns, clear reporting on who clicked and who reported it, and targeted follow-up training for anyone who needs it, repeated regularly rather than once a year.
Reporting dashboards allow organisations to track click rates, credential submissions, reporting behaviour and departmental trends, making it easier to demonstrate improvement to senior management, auditors and insurers.
Clear Reporting That Demonstrates Improvement
Running phishing simulations is only valuable if you can measure whether your organisation is becoming more resilient. Every campaign should produce clear reporting that highlights where risks exist and whether previous training is changing employee behaviour. Typical reporting includes:
- Overall click-rate trends over time
- Repeat clickers who may need additional support
- Department-by-department comparisons
- Email reporting rates
- Improvements across successive phishing campaigns
These reports help IT teams, senior management, insurers, and auditors understand how phishing risk is changing and provide evidence that security awareness efforts are delivering measurable results.
Phishing Simulation Training FAQs
Here are quick answers to the questions we hear most often about phishing simulation training.
What is phishing simulation training?
Phishing simulation training is a security service that sends realistic, fake phishing emails to staff to measure who clicks, opens attachments, or enters credentials, then provides targeted follow-up training based on the results.
How often should phishing simulations be run?
Ongoing programmes, run monthly or quarterly, produce far better long-term results than a single yearly test. Click rates typically fall sharply straight after training but drift back up within weeks without repetition.
What's the difference between phishing simulation and phishing awareness training?
Awareness training teaches staff what phishing looks like. Simulation tests whether that knowledge holds up under realistic conditions. Used together, one improves the other; used alone, either gives an incomplete picture.
What happens to an employee who fails a phishing simulation?
They receive short, specific feedback on what gave the email away and what to check next time. Persistent repeat clickers are usually flagged for additional support rather than penalised, since the aim is to reduce risk.
Is phishing simulation training required for Cyber Essentials Plus?
Cyber Essentials Plus doesn’t name phishing simulation as a mandatory control, but staff security awareness is part of what the certification expects, and regular simulation is the most direct way to demonstrate that awareness holds up in practice.
Do small businesses really need phishing simulation training?
Yes. Smaller organisations start from a lower baseline click rate than larger enterprises on average, but they typically have far less capacity to absorb a successful attack, which makes catching and correcting risky behaviour early more important.
How much does phishing simulation training cost for a UK business?
Cost depends on the number of staff covered and how frequently simulations run. It’s typically more cost-effective as part of a bundled managed cyber security service than as a standalone subscription.
Can phishing simulation training be customised?
Yes. Modern phishing simulation platforms allow campaigns to be tailored around your industry, common suppliers, Microsoft 365, finance processes and current phishing trends, making the exercises more realistic and more valuable.
Does phishing simulation training improve cyber insurance compliance?
Many insurers now ask organisations to demonstrate staff security awareness measures during cyber insurance renewals. Regular phishing simulation training provides measurable evidence that employees are being tested and supported over time.
Book a Phishing Simulation Training Assessment
Most businesses assume their staff would spot an obvious scam email. Most businesses are wrong, at least some of the time, and a single successful phishing email is often all it takes to get an attacker inside.
Book a Free Cyber Security Assessment, and we’ll review your current phishing resilience, identify where staff are most vulnerable, and show you how regular phishing simulation training can reduce your exposure to real-world attacks.
Article Sources
- Department for Science, Innovation and Technology. Cyber Security Breaches Survey 2025/2026. April 30th, 2026
- KnowBe4. 2026 Phishing by Industry Benchmarking Report. Accessed July 16th, 2026
- Information Commissioner’s Office. 72 hours: how to respond to a personal data breach. Accessed July 16th, 2026