Phishing simulations are controlled, realistic phishing attacks that an organization conducts on its own employees to test their resistance to fraud attempts and teach them how to respond safely. The message looks like a real attack – it may have a fake link, impersonate a trusted sender or ask for login details – but it carries no risk to the organization. Cybercriminals build their campaigns on exactly the same mechanisms, so simulated attacks allow you to check how your team would actually behave in the face of a real attack.
What are phishing simulations?
A phishing simulation is a single, planned email, SMS or instant messaging campaign prepared to imitate the technique of a real attack, but without real consequences. The goal is always the same: to measure how a specific group of employees will react to a potentially dangerous message that may encourage them to click on a link, open an attachment or enter a password. And thus lead to a security incident.
Phishing simulations are an integral part of phishing tests. Because phishing tests cover the entire process: preparing a scenario, conducting simulations, measuring the response and reporting the results. The phishing simulation is the attack mechanism itself within the process – the specific scenario, channel and social engineering technique the message uses. Without a well-designed simulation, the test has nothing to measure, and its realism determines whether the result will show the true vulnerability of the team or only that employees have learned to recognize one repeatable template.
It is worth noting that phishing simulations are the most common, but not the only, form of social engineering tests. Social engineering tests also include telephone calls (vishing) or attempts to physically enter the building, and phishing simulations focus exclusively on digital channels: email, SMS and company messengers.
How is phishing simulation done step by step?
The phishing simulation takes place in several fixed stages: selection of the target group, selection of the attack scenario, sending messages and recording the reaction, and analysis of the results. Often, an employee who takes a risky action after receiving a simulated attack also receivesa short portion of knowledgeexplaining what the attack was – this allows employees to increase their awareness and immediately correct their reflexes. At SECAWA each simulation ends with a portion of knowledge that we call micro-training.
Selecting target users and risk profile
The training coordinator indicates the group of target users who will receive the simulation – the entire organization, a specific department or roles most exposed to attacks using social engineering techniques, such as finance, management or HR. Each employee’s action during the simulation is registered and associated with his or her risk profile, thanks to which subsequent campaigns can be adjusted to the real level of susceptibility of a given person or group.
Selection of attack scenario
At SECAWA, we conduct simulations according to four patterns:
- The basic scenario checks whether the employee clicks the link.
- The extended scheme leads to a false login page and checks whether the employee enters the data – the information collected in this way is anonymized or encrypted with the organization’s key, and never reaches SECAWA in an open form.
- The attached diagram teaches you how to verify files before malware infections occur.
- A pattern provoking a response checks your vigilance without clicking on anything – just replying to a crafted request is enough, just like in spear phishing attacks targeting a specific person.
Sending and registration of reactions
The message is sent to the employee by email or text message when he is absorbed in his daily duties, which makes it possible to measure the real reaction, not the declared security awareness.
The platform records every reaction: opening a message, clicking, entering data on the login page, opening an attachment, and – if an email client extension is implemented – a simulation reporting indicator.
Micro-training in the moment of failure
If an employee gets caught, they immediately receive assigned training. Depending on the scheme, it is an educational page displayed immediately after clicking or a short email with micro-training sent at a scheduled interval. As a result, employee awareness of social engineering techniques and safe response methods.
Result analysis
The analysis of the results shows how the group of target users reacted to the simulated attack: how many people clicked on the link, how many entered data on the login page, how many opened the attachment, and how many reported the message according to the procedure. Simulation reporting also includes the response time of the first report and the distribution of vulnerabilities by departments and roles, thanks to which you can see which teams need additional support.
For example, if the result indicates repeated violations of security or security procedures in a specific group, a team of experienced SECAWA specialists prepares security recommendations and adjusts the difficulty level of the next simulation – so as to actually strengthen the security of the organization’s data, and not just document statistics.
Types of phishing simulations
Phishing simulations differ primarily in the channel and degree of personalization of the attack, and not only in the scheme of operation described earlier.
- Email simulations (phishing) remain the most common variant – they imitate fake invoices, shipment notifications or messages from trusted institutions that are actually used by cybercriminals.
- Smishing transfers the same mechanism to SMS. The limited context of a text message – no preview of the sender, short content – makes employees react to it faster and less critically than to email.
- Spear phishing is the most targeted variant: a message prepared for a specific person or department, often based on publicly available information (position, team structure, recent events in the company). Spear phishing simulations test the resilience of the roles most exposed to CEO fraud and financial fraud – management, finance, purchasing department.
- Multi-channel simulations combine several vectors in one sequence – for example, an SMS announcing an “important email” that increases the credibility of a message sent moments later. Such a scenario checks how employees react when an attack comes from several sources at the same time, which increasingly reflects real campaigns of cybercriminals.
The library of scenarios should be constantly expanded to include new vectors that are just becoming widely used in attacks: simulations using deepfake video, vishing supported by AI-generated voice, USB drop attacks or phishing conducted via WhatsApp. Providing diverse phishing simulations in the organization, including these new techniques, translates directly into building real team resilience – especially since GenAI allows cybercriminals to generate increasingly reliable and personalized social engineering attacks (we wrote about it tutaj). The broader the repertoire of simulations and the faster they keep up with new techniques, the less risk that employees will develop a reflex to recognize only one, repeatable attack template.
Why is it worth conducting phishing simulations in your organization?
Phishing simulations give your organization something that no survey or cybersecurity theoretical training can provide: evidence of how employees will actually react to a fraud attempt. There are three specific reasons for them:
- Increased employee awareness (security awareness). A person who has once been confronted with a realistic simulation will more easily recognize another attack attempt – he develops the reflex to verify the sender, link or request for data, instead of just declaring that he knows what phishing looks like.
- Preventing financial fraud and data leaks. Analysis of online fraud cases shows that the most costly incidents begin with one click on a link or providing data on a false login page. Regular simulations allow you to detect these weak points in controlled conditions, which actually reduces the risk of data leakage and malware infection.
- Reduction of security breaches. Companies that systematically conduct phishing simulations document a decrease in the number of security breaches resulting from employee error, and at the same time build material useful during audits and reporting to the management.
The security of an organization’s data depends not only on technology, but on whether employees recognize an attempted manipulation at the decisive moment – and this can only be trained in practice, not in theory.
Phishing simulations in self-service tools (Microsoft Defender)
Many organizations conduct phishing simulations themselves, in a tool built into their existing office suite – the most popular example is the attack simulation training available in Microsoft Defender for Office 365. In this model, it is the company administrator who configures, runs and supervises each attack simulation, without the support of an external team.
Configuration involves several steps, which in practice require a lot of time and competence of the IT department. The administrator selects target users from the list of employees or groups in Microsoft 365, and then selects a scenario – most often phishing for login details or clicking on a link. In a phishing scenario, Microsoft Defender shows the default login page, which must be manually adjusted to the appearance of the company’s internal systems for the simulation to be credible – without this configuration, the login page immediately reveals that it is a test.
After the campaign ends, the system sends default Microsoft notifications to participants and their superiors with information about the result. The administrator must manually assign training to employees who got caught from the built-in catalog – this is the training assignment, and the resulting assigned training must be separately monitored in the panel to check whether they have been completed.
The tool also gives technical control over the campaign itself: the administrator can cancel the simulation if the configuration turns out to be incorrect, although messages sent before cancellation remain in recipients’ mailboxes. It is also possible to exclude simulations from reporting, i.e. filter a specific campaign from general phishing statistics so that it does not distort data on real incidents – however, this setting must be configured manually for each simulation.
The self-service model works well in organizations that have a dedicated team to handle these settings.
In practice, however, this means that the entire burden of planning, personalizing the login page, assigning training and monitoring results rests with the administrator – which distinguishes it from a fully managed model in which these tasks are taken over by a team of experienced specialists from an external supplier, as in Practical Anti-Phishing Training SECAWA.
Phishing simulations as part of a long-term training cycle, instead of a one-time social engineering test
In addition to self-service tools, there is a second model for conducting phishing simulations – fully managed by an external supplier. The organization does not configure the campaign itself, does not personalize the login page and does not assign training manually – all this is taken over by a team of experienced specialists.
An example of such an approach is Practical Anti-Phishing Training – a Polish platform for simulating cyberattacks, in which the SECAWA team designs scenarios, plans a campaign schedule, analyzes the results and prepares reports, and the client’s responsibility is only to accept the materials. The training includes mass, industry, competence, company and spearphishing campaigns, tailored to the specificity of the organization and employee roles.
The difference from tools such as Microsoft Defender is primarily operational: when choosing SECAWA Practical Anti-Phishing Training, the client-side training coordinator spends a maximum of 3 hours per month, mainly on accepting scenarios and schedules, while in the self-service model, the entire configuration, assignment of training and monitoring of assigned training are burdened by the IT department.
Do you want to check what it looks like in practice in your own organization? Arrange a Free Phishing Test – one simulation on a selected group of employees, without costs and obligations.
Frequently asked questions about phishing simulations
What is the difference between phishing simulations and phishing tests?
The phishing simulation is the attack mechanism itself – a specific scenario, channel and social engineering technique. A phishing test is the entire process: preparing the simulation, conducting it, measuring the response and reporting the results. Simulation is therefore an inseparable element of the test, not a separate phenomenon.
Can phishing simulation include smishing and other channels, not just email?
Yes. Today, phishing simulations include not only email messages, but also smishing (SMS), and increasingly multi-channel scenarios in which SMS authenticates a message sent by email a moment later. In the SECAWA Practical Anti-Phishing Training, both channels are a standard element of the campaign.
What do phishing simulations look like in SECAWA Practical Anti-Phishing Training?
Phishing simulations are one of the four elements of the Practical Anti-Phishing Training – next to micro-training triggered in the event of a mishap, a button for reporting suspicious messages and measuring real employee behavior over time. They are conducted periodically, and their topics and level of difficulty increase with the resistance of the team.
What happens to the data entered on the login page during the SECAWA simulation?
Login forms used in SECAWA simulations are anonymized or optionally encrypted with the organization’s public key. Only the client has access to the collected data – the SECAWA team does not store or process employee passwords in a public form.
Can phishing simulations harm employees or disrupt their work?
No. SECAWA simulations do not violate the organization’s systems or data, and the scenarios are designed to teach threat recognition and not embarrass the employee. The entire training takes an employee only a few minutes per week, so phishing simulations do not interfere with the performance of current duties. A failure in the simulation is not an assessment of a single person – it is a signal that helps to adjust subsequent micro-training and training topics.
Who prepares phishing simulation scenarios in SECAWA?
The scenarios are prepared by a team of experienced specialists based on the analysis of the industry, organizational structure and current techniques used by cybercriminals – without ready-made, repeatable templates.
Where to report a real, not simulated, phishing attack?
It is best to report a real, confirmed phishing attack to CSIRT NASK – via the number 8080, the moje.cert.pl portal or the form on the CERT Polska website. Simulations are reported using an internal reporting button, without the involvement of external institutions.