markus.preinl • 22. Juli 2026

Phishing Simulation: Safely test employees and raise awareness

A phishing simulation is a controlled test in which employees receive realistic, but harmless, phishing emails. The goal is not to embarrass individuals, but to improve security practices in everyday work: Is a suspicious message recognized? Is a link clicked? Are login credentials entered? Is the email reported correctly?


This is important for companies because many cyberattacks begin with emails. Phishing affects not only IT, but also accounting, management, HR, sales, and all teams that work with external messages daily. Fake invoices, alleged Microsoft 365 logins, package notifications, job applications, or messages supposedly from executives are particularly dangerous.


This article shows how to plan a phishing simulation effectively, which rules for data protection and fairness are important, which key performance indicators (KPIs) are truly helpful, and how companies can derive concrete awareness measures from it. The focus is on a clear and practical implementation for SMEs and medium-sized businesses.


Table of contents

  • What is a phishing simulation?
  • Why is a phishing simulation useful?
  • How does a phishing simulation work?
  • How to plan a phishing simulation correctly
  • Data protection, transparency, and the works council
  • Which phishing scenarios are useful?
  • Which KPIs should be evaluated?
  • Typical mistakes in phishing simulations
  • Implementing a phishing simulation with FIGULI CONSULTING
  • Conclusion
  • FAQ about phishing simulations


What is a phishing simulation?

A phishing simulation is a planned security exercise. Employees receive realistically designed test emails that replicate typical phishing attacks. These messages might contain, for example, a link, a fake login page, a fake attachment, or a call to action.


The difference from real phishing: The simulation is controlled, harmless, and documented. No actual malware is sent, and no real login credentials are stored. Instead, the simulation measures how employees react and whether internal reporting channels function effectively.


A phishing simulation tests, for example:

  • whether suspicious emails are recognized
  • whether links or attachments are clicked
  • whether login credentials would be entered
  • whether employees report the message
  • how quickly a report is filed
  • whether the helpdesk or IT department reacts appropriately
  • which teams need additional training


The underlying principle is crucial: A good phishing simulation is not a test to "catch" employees. It is a learning tool to highlight risks, practice reporting procedures, and strengthen security awareness in everyday practice.

Why is a phishing simulation useful?

A phishing simulation is useful because it demonstrates how well employees react to realistic fraud attempts. While traditional training explains the rules, it doesn't always show whether these rules are actually applied in the hectic daily work environment.


Especially in SMEs, successful phishing attacks can have significant consequences. A compromised Microsoft 365 account, a manipulated invoice, or a fake login can lead to data leaks, payment fraud, malware, or business interruptions.


A phishing simulation helps companies:

  • measure the current level of awareness
  • identify typical risk situations
  • practice reporting procedures
  • plan training more effectively
  • improve response times
  • involve managers and specialist departments
  • better evaluate technical security measures


Most importantly: It's not just about reducing the click-through rate. Even more crucial is that suspicious messages are reported quickly and correctly. Because even in well-protected environments, a dangerous email can slip through.


Official phishing prevention measures provide additional guidance on how to check suspicious messages, report them, and supplement technical safeguards.


That's precisely why phishing simulation and email security go hand in hand. Technical safeguards such as spam filters, email security, multi-factor authentication (MFA), and secure devices are essential. Simulation complements these measures by training the human element and internal processes.


Employees examine a suspicious email as part of a phishing simulation.

How does a phishing simulation work?

A phishing simulation proceeds in several clear steps. First, the objective, target group, and scenario are defined. Then, the test email, landing page, tracking, reporting channels, and evaluation are prepared. Finally, the campaign is sent out, evaluated, and linked to brief training exercises.


A simple process looks like this:

  1. Define objective
  2. Determine target group
  3. Select scenario
  4. Create test email and landing page
  5. Clarify data protection and communication protocols
  6. Conduct technical testing
  7. Send campaign
  8. Evaluate clicks, reports, and response times
  9. Derive learning objectives and training materials
  10. Conduct a retest later


The most important point is the follow-up. A simulation without evaluation and training is of little use. The learning effect only occurs when employees understand which warning signs were overlooked and how to react correctly next time.

Properly planning a phishing simulation

A good phishing simulation doesn't start with sending a test email, but with planning. Companies should clarify beforehand exactly what is to be tested, which target groups are to be included, and what insights should ultimately be gained.


Reasonable goals include:

  • Increase the reporting rate
  • Reduce the click-through rate
  • Reduce the reporting time
  • Identify risks in specific roles
  • Strengthen secure processes for invoices or logins
  • Plan awareness training more effectively
  • Detect real incidents more quickly


Goals such as public rankings, exposing individuals, or creating the most difficult test possible are not advisable. Such approaches damage trust and can lead to employees later failing to report genuine suspected cases.


External support can be particularly helpful during the planning phase. FIGULI CONSULTING supports companies not only with individual phishing simulations, but also in developing effective IT security and awareness measures. This includes clear reporting channels, easily understandable training materials, technical email security measures, Microsoft 365 security, and reporting that reveals risks without embarrassing employees.


This way, a single test becomes not an isolated project, but a meaningful component of the overall security strategy.


Discuss IT security and awareness with FIGULI


Which target groups should be included?

Not all roles carry the same risk. Therefore, a phishing simulation should carefully select target groups. Teams that receive many external emails or handle sensitive processes are particularly relevant.


Typical target groups include:

  • Accounting and Finance
  • Management and Executive Assistants
  • HR and Recruiting
  • Sales and Customer Service
  • IT and Administration
  • Project Management
  • Shared mailboxes such as office@ or accounting@


Finance, HR, and management are often attractive targets for attackers because they process invoices, approvals, personnel files, and other confidential information.

How often should you run a phishing simulation?

For many SMEs, a quarterly cycle makes sense. This means an initial baseline campaign, followed by regular repetitions with comparable scenarios and short learning modules.


More important than the perfect frequency is consistency. A one-off simulation generates attention but rarely changes lasting behavior. A repeatable process with manageable campaigns, clear evaluation, and re-testing after training or process changes is better.

Data protection, transparency and works council

A phishing simulation must be implemented fairly and in compliance with data protection regulations. This primarily involves purpose limitation, data minimization, retention periods, access rights, and transparent communication.


Employees should be aware that the company conducts awareness campaigns and phishing simulations. It is not necessary to specify concrete dates or scenarios in advance. However, the purpose must be clear: to learn, improve reporting channels, and reduce security risks.


Key points include:

  • Document the purpose of the simulation
  • Collect only necessary data
  • Do not store real passwords
  • Define retention periods
  • Limit access to evaluations
  • Evaluate results in aggregated form whenever possible
  • Involve the works council or data protection officer early on
  • Do not create public rankings


If a works council exists, it should be involved early. This is especially important if personal behavioral data is being processed. Data protection officers, IT security, and HR should also be informed about the purpose, data fields, reporting, and follow-up procedures.


A sound implementation not only reduces legal risks but also improves acceptance. When employees understand that it's about learning rather than control, they are more willing to report suspicious emails.

Which phishing scenarios are sensible?

Good phishing scenarios are based on real work processes. They should be realistic, but not unfair or manipulative. The aim is a learning effect, not maximum uncertainty.


Examples of useful scenarios include:

  • alleged Microsoft 365 login
  • fake invoice
  • Alleged change of bank details of a supplier
  • HR document or policy update
  • Package or shipping notification
  • SharePoint or OneDrive sharing
  • Appointment change or calendar approval
  • alleged security warning
  • QR code in an email


A learning goal should be defined for each scenario. In the case of a fake invoice, for example, it's about confirmation and the four-eyes principle. A Microsoft 365 login is about URL checking, MFA behavior and reporting path.

What should be avoided?

Scenarios that unnecessarily create fear, shame, or personal pressure should be avoided. These include private topics, health information, threats of dismissal, salary promises, or highly emotional enticements.


Such campaigns may generate high click-through rates in the short term, but they destroy trust in the long run. Realistic, fair scenarios with a concrete connection to everyday work life are better.

Which KPIs should be evaluated?

Several key performance indicators (KPIs) are important for a phishing simulation. The click-through rate (CTR) alone is insufficient. While it shows how often a link was clicked, it reveals little about the overall resilience of the organization.


Important KPIs include:

  • Click-through rate
  • Entry rate on landing pages
  • Report rate
  • Time-to-report
  • Repeat rate
  • Report quality
  • Risk patterns by role or process
  • Development across multiple campaigns


Report rate and time-to-report are particularly valuable. If a suspicious message is reported quickly, IT or security can react before significant damage occurs.

KPI table for phishing simulations

KPI Meaning
Click rate Percentage of people who click on link or attachment
Input rate Percentage of people who enter data on a landing page
Reporting rate Percentage of people who report the message correctly
Time-to-Report Time until the first real report
Repeat rate Individuals or roles with repeated risky behavior
Reporting quality Quality of the message, e.g., original email, subject, sender, context

The trend is what matters. A single campaign can be distorted by its scenario, timing, or technical filters. Meaningful analysis only occurs when multiple campaigns are analyzed.

The team discusses IT security and awareness measures within the company.

Typical mistakes in phishing simulations

Many phishing simulations fail not because of technical issues, but because of communication problems, poor objectives, or a lack of follow-up. If employees feel monitored or exposed, acceptance decreases.


Common mistakes include:

  • unclear objectives
  • overly aggressive or unfair bait
  • no prior communication
  • lack of data privacy agreement
  • excessive personal reporting
  • no post-campaign training
  • focusing solely on click-through rate
  • running too many scenarios simultaneously
  • unprepared helpdesk
  • no repetition or retesting

A good simulation remains manageable, fair, and focused on learning. It shows not only where someone clicked, but also what can be improved in the process.

Implementing a phishing simulation with FIGULI CONSULTING

A phishing simulation only reaches its full potential when it is meticulously planned, communicated transparently, and integrated into an awareness program. This is precisely where FIGULI CONSULTING can provide support.


FIGULI CONSULTING helps companies implement practical phishing simulations: from defining objectives and selecting scenarios to developing data protection and communication concepts, as well as reporting, learning measures, and re-testing. This is not simply about employee testing, but about measurable improvements in email security, reporting channels, and security awareness.



Figuli CONSULTING helps companies implement practical phishing simulations: from defining objectives and selecting scenarios to developing data protection and communication concepts, and on to reporting, learning measures, and re-testing.


FIGULI can provide support, in particular, with:

  • Selecting suitable scenarios
  • Planning pilot and baseline scenarios
  • Coordinating data protection and reporting
  • Creating easily understandable learning materials
  • Evaluating KPIs
  • Deriving concrete awareness measures
  • Integrating with email security and endpoint security
  • Consistent re-testing


Especially when companies already use Microsoft 365, email security, or security solutions like Hornet Security, FIGULI can help to effectively combine phishing simulations with technical safeguards and awareness training.


Conclusion

A phishing simulation is an effective tool for measurably improving security awareness within a company. It demonstrates how employees react to suspicious messages in their daily work, whether reporting channels are functioning effectively, and which processes need improvement.


The key is proper implementation. A good phishing simulation is fair, easy to understand, compliant with data protection regulations, and linked to concrete learning measures. It measures not only clicks but also reports, response times, and risk patterns.


For SMEs and medium-sized businesses, a streamlined approach is usually best: clear objectives, a few realistic scenarios, simple reporting channels, short learning modules, and regular retests. This ensures that a simulation is not a one-off test but a continuous contribution to IT security.


If time, expertise, or suitable tools are lacking internally, FIGULI CONSULTING can help integrate phishing simulations into a broader security concept. This includes email security, Microsoft 365 protection, clear reporting channels, awareness measures, and technical safeguards that actually work in everyday use.


Discuss IT security and awareness with FIGULI


FAQ about the Phishing Simulation

What is a phishing simulation?

A phishing simulation is a controlled test using realistically designed, but harmless, phishing messages. The goal is to improve employee security practices, train reporting channels, and identify typical risk patterns.


Why is a phishing simulation useful?

A phishing simulation is useful because it shows how employees react to suspicious emails in their daily work. This allows companies to identify areas where training, reporting channels, or technical security measures need improvement.


How often should a phishing simulation be conducted?

For many SMEs, a quarterly schedule is recommended. Regular repetition, comparable scenarios, short learning sessions, and re-testing after training or process changes are crucial.


Which KPIs are important for phishing simulations?

Important KPIs include click-through rate, input rate, report rate, time-to-report, repeat submission rate, and report quality. Reporting rate and response time are particularly informative because they show how quickly a company can react to suspected cases.


Is a phishing simulation GDPR-compliant?

Yes, a phishing simulation can be implemented in compliance with the GDPR if the purpose, data scope, retention periods, access rights, and reporting are clearly defined. No real login credentials should be stored, and results should be evaluated in aggregated form whenever possible.


Which phishing scenarios are suitable for SMEs?

Realistic scenarios from everyday work are suitable for SMEs: fake invoices, Microsoft 365 logins, SharePoint shares, HR documents, package notifications, or changes to bank details. It is important that each scenario has a clear learning objective.


How can employees be protected from being exposed?

Companies should clearly communicate that the focus is on learning and risk reduction. Reporting should be aggregated whenever possible, and public rankings should be avoided. A short, respectful learning prompt should follow each click.