All insights
OffensiveApr 9, 20265 min read

Phishing simulations without burning employee trust

Phishing simulation is one of the most effective ways to measure human risk — and one of the easiest to do in a way that damages the security team's relationship with everyone else. The technique is the easy part. The framing is what separates a useful exercise from a morale hit.

Measure, don't entrap

The goal of a simulation is to learn how your organization responds to a realistic lure and to give people a safe place to practice. It is not to rack up a high click rate with a cruel pretext so the report looks dramatic. A campaign that dangles a fake bonus or a layoff notice will get clicks, but it teaches employees that security is something done to them, not with them.

Pair every test with training

The moment someone clicks is the moment they're most receptive to learning. A good program meets them there with a short, blame-free explanation of what to look for next time — not a public shaming. Over successive campaigns you're looking for the trend to improve, which means the exercise has to be something people can actually learn from.

  • Run with consent and leadership awareness, not as a gotcha
  • Use realistic but non-cruel pretexts
  • Deliver just-in-time training at the moment of the click
  • Report trends over time, never individual names for punishment
  • Make reporting a suspected phish easy — and celebrate it

What good looks like

After a few cycles, a healthy program sees click rates fall and report rates rise — people aren't just avoiding the bait, they're actively flagging it. That reporting muscle is the real prize: it turns every employee into a sensor for the genuine attacks that will eventually come.

Want this applied to your stack?

Every engagement starts with a no-obligation conversation about what you run and what worries you — the scoping is on us.

Talk to our team