Add Think Technology as a trusted source Phishing Simulation Programs That Work | Think Technology

Phishing Simulation Programs That Actually Work

An IT security professional reviewing phishing simulation program results on a dashboard, illustrating how phishing simulation programs build employee resilience.

A phishing simulation program works when it changes how employees behave under pressure, not just how they score on a test. Most Australian SMEs that run simulations measure one thing: click rate. A falling click rate feels like progress. In most cases, it is not. Employees learn to spot the test, not the threat. A program built around realistic scenarios, consistent cadence, and meaningful metrics can reduce your organisation’s susceptibility from above 30 percent to below five percent within twelve months. That outcome requires design, not just software.

Why most phishing simulations fall short

Most phishing simulation programs underperform because they are designed to produce a number rather than change a behaviour. The typical pattern: a batch of emails goes out once a quarter, the click rate comes back at 12 percent, leadership nods, the box gets ticked. Nothing changes about how staff actually handle suspicious email.

The deeper problem is that the threat has moved on while most templates have not. AI-generated phishing emails are now personalised at scale, using real organisational context, department-specific language, and sender details that match colleagues. Static templates based on generic “your password has expired” lures do not reflect what arrives in inboxes in 2026. When employees learn to recognise the simulation rather than the attack pattern, a low click rate means very little. Research from 2025 and 2026 consistently shows that programs relying on obvious templates produce better-looking metrics without improving real-world resilience.

There is also a cultural risk. Programs framed around catching people out, or that shame repeat clickers, reduce reporting rates. When employees feel punished for failing a test, they stop reporting things they are unsure about. That behaviour is the opposite of what you need during an actual incident, where early reporting is what limits damage.

What the evidence says about effective programs

Effective phishing simulation programs share three characteristics: they run consistently, they match real attack patterns, and they treat each simulated click as a teaching moment rather than a failure event. Verizon’s 2025 Data Breach Investigations Report found that employees trained within the previous 30 days were four times more likely to report a real phishing attempt. That finding points directly to cadence. Monthly simulations outperform quarterly ones because the training effect fades quickly without reinforcement.

Frequency data from multiple sources shows a consistent pattern. Untrained organisations start with a susceptibility rate between 33 and 34 percent. Consistent monthly simulations over 90 days reduce that to around 18 to 20 percent. Over twelve months, well-run programs bring susceptibility below five percent. The organisations that reach that outcome combine regular simulations with immediate follow-up training at the point of failure, role-specific scenarios, and a culture where reporting is recognised rather than dismissed.

The ACSC’s Small Business Cyber Security Guide makes clear that security awareness training “isn’t a once-off requirement and should be refreshed periodically.” That principle applies directly to phishing simulation: periodic is not enough. Continuous is what builds lasting instinct.

The click rate trap and what to measure instead

Click rate is the metric most phishing programs default to, and it is the metric most likely to mislead you. A low click rate can mean employees are genuinely improving. It can also mean simulations are too easy to spot, that employees are deleting suspicious email without reporting it, or that automated security tooling is pre-fetching links and inflating the numbers. None of those outcomes improve your actual risk posture.

The metrics that reflect real behavioural change are different. Reporting rate, the percentage of employees who actively flag a suspicious email through the correct channel, is the strongest indicator of a healthy security culture. Industry reporting rates typically range from 9 to 29 percent depending on sector. Moving that number upward over time shows employees are not just avoiding clicks but actively participating in defence. Credential entry rate matters more than click rate: clicking opens a page, but submitting a username and password is where real compromise begins. Dwell time, the gap between an employee receiving a suspicious email and reporting it, tells you how alert your team is under normal working conditions. A shorter dwell time means faster containment when a real attack arrives.

The target over time is a click rate trending down alongside a reporting rate trending up. Those two lines moving in opposite directions indicate a program that is actually working. A click rate falling while reporting stays flat usually means employees have learned the tells of your test format, not the tells of a real phishing attempt.

How to build a simulation program that changes behaviour

Building a phishing simulation program that produces lasting behaviour change requires decisions upfront about design, not just platform selection. The following principles consistently appear in programs that work.

  • Run simulations monthly, not quarterly. Monthly cadence builds habit. Quarterly simulations create event awareness that fades before the next test arrives.
  • Use templates that reflect current attack patterns. Executive impersonation, invoice fraud, credential harvesting pages, and multi-factor authentication (MFA) bypass lures are the scenarios employees are likely to encounter in 2026. Generic templates that employees learn to recognise defeat the purpose.
  • Deliver immediate training at the point of failure. The moment someone clicks on a simulated phish is the highest-impact learning opportunity in the entire program. A short, contextual lesson shown immediately after a click produces more behaviour change than a separate training module assigned later.
  • Segment by role. Finance teams, executive assistants, and operations staff face different phishing threats. A one-size-fits-all campaign misses the specific lures most likely to catch high-risk individuals. Role-based scenarios improve both realism and relevance.
  • Measure reporting rate alongside click rate. Give employees a simple, one-click reporting mechanism. The easier it is to report, the more reports you get, and the faster your security team can respond to real threats.
  • Make reporting visible and recognised. Celebrating staff who correctly identify and report a phishing attempt builds a culture where vigilance is valued. Teams that see reporting rewarded report more. That matters in a real incident.

AI-generated phishing and why program design has to keep pace

AI-generated phishing attacks present a specific challenge for simulation programs built on static templates. AI-assisted lures use personalised details, match an individual’s writing patterns, and arrive with contextual business language that makes them genuinely difficult to distinguish from legitimate email. Research published in 2025 suggests that more than 80 percent of phishing emails are now AI-generated. Simulations that do not reflect this shift are training employees to spot attacks that are no longer the primary threat.

Effective programs in 2026 include scenarios that go beyond email. Voice phishing (vishing), SMS phishing (smishing), and deepfake-based attacks are moving into the threat landscape that affects Australian businesses. The 2024-25 ACSC Annual Cyber Threat Report noted that malicious actors use stolen personal information to improve the success rate of their campaigns, embedding realistic organisational context into lures. A simulation program that only tests email is preparing employees for part of the attack surface, not all of it.

The practical response for an SME is not to run sophisticated deepfake simulations immediately. It is to ensure that simulation templates are updated regularly, that at least some scenarios include realistic spear-phishing lures tailored to your industry, and that employees understand modern phishing does not look like the obvious “Nigerian prince” emails of a decade ago. Security training that actually sticks combines regular simulation with reinforcement that matches the real threat environment.

The role of an MSP in running phishing simulations

Running a phishing simulation program in-house requires time, security expertise, and consistent management attention. For most SMEs with 10 to 100 staff, that capacity does not exist inside the business. The program gets deprioritised, templates go stale, cadence slips from monthly to quarterly to occasional, and the results stop reflecting real risk.

A managed service provider (MSP) running phishing simulations on your behalf removes the operational burden without removing your visibility. TTA manages simulation programs as part of broader security services, handling template selection and updates, scheduling, reporting, and follow-up training delivery. You receive reporting that shows trend lines across click rate, reporting rate, and credential entry rate over time, rather than a single snapshot number. That data is what supports a real conversation about whether your human security posture is improving.

For businesses subject to cyber insurance requirements, simulation programs also produce documented evidence of ongoing security awareness activity. Insurers increasingly ask for proof that staff training is continuous rather than annual. A managed simulation program generates that documentation as a natural by-product of the work.

Our work with Huntress for managed detection and response means that where simulation training intersects with real threat detection, we have visibility across both layers. You can read more about how TTA approaches managed security with Huntress in their published case study.

A practical check for your current program

If your organisation already runs phishing simulations, these questions tell you whether the program is working or just producing numbers.

  • Has your reporting rate increased over the last six months, or are you only tracking click rate?
  • When was your simulation template library last updated to reflect current attack patterns?
  • Do employees receive immediate training when they click a simulated phish, or does training happen separately?
  • Are simulations segmented by role, or does everyone receive the same scenario?
  • Is your simulation cadence monthly, or has it slipped to quarterly or less?

If most answers reveal gaps, the program is checking a box without building resilience. The gap between a program that looks good in a report and one that actually reduces your risk is almost always found in design and consistency rather than platform choice.

Where do we start?

If you want to understand where your team currently sits, or if you are building a phishing simulation program from the ground up, TTA can help you design something that produces genuine behaviour change. We work with Australian SMEs across a range of industries to run simulation programs that are realistic, consistent, and tied to metrics that matter. Get in touch to start the conversation.

Get tech tips

Stay up-to-date with the latest in tech for small and medium business.
Subscribe to our newsletter and get tips and monthly updates.