27/08/2026
Would your team spot a convincing phishing email on a busy Friday afternoon?
A rushed invoice request. A Microsoft 365 password warning. A message that appears to come from a director...
Phishing simulations help you find out how people respond in the real world and where extra support is needed.
A few tips for making them genuinely useful:
🎣 Use realistic scenarios based on the emails your team actually receives
🔁 Run simulations regularly, not just once a year
🎯 Give short, targeted training straight after someone clicks
📊 Track reporting rates as well as clicks - spotting and reporting a threat is the behaviour you want to build
🤝 Support repeat clickers rather than embarrassing or punishing them
The aim isn’t to catch people out. It’s to help them recognise a real attack before it causes damage.
We’ve explained how phishing simulation training works, what a good programme should include and what to measure here:
🔗 https://lnkd.in/ez4xKY3H