← All articles
EXPLAINED

Phishing Simulations explained

Why testing beats than telling

Most businesses have told their staff, at some point, not to click suspicious links.

Fewer have ever actually tested whether that advice sticks when a convincing email lands in a real inbox, on a busy Tuesday, from someone who appears to be the finance director.

That gap is exactly what our Phishing Simulations are built to close.

What a phishing simulation actually is

A phishing simulation is a safe, controlled version of a real phishing email, sent to your own team to see how they respond.

Nothing is ever at real risk - no data is taken, no systems are touched - but the moment of decision is completely real.

Do they click? Do they enter details? Do they report it?

The results tell you something a policy document never can: what your team would actually do under real conditions.

Why phishing is still the way most attacks start

Phishing hasn't gone away, and the numbers explain why.

Sophos's 2026 State of Ransomware report found that malicious email and phishing together account for roughly half of all ransomware attacks - making them, combined, the single biggest way attackers get in.

Technical defences matter, but a well-crafted email that reaches a real person's inbox routes around many of them entirely.

That's what makes this such a persistent problem. It doesn't rely on a flaw in your software. It relies on someone, once, believing an email is what it claims to be.

Why telling people isn't the same as testing them

Security awareness in theory and security awareness in practice are two different things.

Someone can know, in principle, that they shouldn't click unexpected links, and still click one anyway when it's disguised well enough and arrives at the right moment. That's not a failure of intelligence - it's how convincing, well-timed phishing is designed to work.

Simulations close that gap by testing the real behaviour, not just the stated policy. And because nothing is actually at risk, a simulation that reveals a weak spot is a good outcome, not a bad one - it's how you find out before an attacker does.

What happens after a simulation

The value isn't in catching people out. It's in seeing where the gaps genuinely are, so training can focus on them directly.

Phishing simulations work best run regularly and paired with proper security awareness training. This is where the second habit - recognising the next phishing email - actually gets built.

Getting started

Phishing Simulations are an optional add-on to HackRisk, available exclusively to subscribers. You can learn more about our phishing simulations here or get in touch for more information.

In the meantime, you can get a free HackRisk Report any time you like. It's completely free, and arrives within 24 hours.