Phishing simulation testing sends a fake phishing email to your own staff. It also measures who clicks, who reports it, and how fast. It is a controlled exercise, not a trick for its own sake. So the results show exactly where your training and defences need work. You stop guessing and start measuring. Phishing is still the most common type of attack against UK businesses. That visibility matters more than almost any other routine security check.

Table of Contents
What is phishing simulation testing?
A phishing simulation is a mock attack. Your security team, or a third party working on your behalf, crafts an email that looks real. It might be a fake invoice or a spoofed IT alert. Or it might be a fake HR message, or a note that looks like it came from a supplier. It lands in staff inboxes at a time nobody expects.
But nobody loses money or data. Instead, the platform behind the simulation tracks what happens next. It logs who opens the email and who clicks the link. It also logs who types a password into a fake page, and who reports it to IT instead. Those figures become your baseline, so every later test gets measured against it.
How does a phishing simulation actually work?
Most phishing simulation testing programmes follow a similar sequence. This holds whether the test runs in-house or through an outside provider.
- Scoping: agree which teams get tested, how many emails go out, and which lure themes are fair game. Finance fraud, a fake IT alert, HR, and a fake supplier are common choices.
- Sign-off: leadership and HR agree the exercise first, since it affects staff and their data.
- Sending: the simulated emails go out. They are usually staggered, so one department does not tip off the next.
- Tracking: click rates, credential entry, and reporting rates get logged automatically.
- Feedback: anyone who clicks gets a short, quick note on what gave the email away. Nobody gets a telling-off from a manager.
- Reporting: results go to managers as a summary by team. Staff are never named to the whole firm.
The strongest programmes repeat this cycle every few months, so the business can see whether the numbers are really moving.
Why UK businesses are running them
The case for testing sits in the numbers. The government’s Cyber Security Breaches Survey 2025/26 found that 43% of UK businesses reported a breach or attack in the last year. Phishing was by far the most common route in, hitting 38% of all businesses surveyed. Among the businesses that were breached, just over half faced phishing alone, with no other attack type involved.
Verizon’s 2026 Data Breach Investigations Report backs this up on a global scale. The human element featured in 62% of breaches. Mobile phishing now gets a 40% higher click-through rate than the same lure sent to a desktop. A small screen hides warning signs that a full browser window would show. Attackers know staff are the weakest link. Testing that link directly makes sense.
What NCSC says you should watch out for
This is where a lot of businesses get phishing simulation testing wrong. The National Cyber Security Centre publishes its own guidance on phishing. It takes a more careful line on simulations than most firms selling the tools. NCSC warns that punishing staff for clicking a simulated email “starts to resemble entrapment”. Besides, nobody can be expected to spot every phishing attempt. A reprimand after every failed test just teaches people to hide mistakes instead of reporting them.
The guidance also makes a simpler point. No simulation programme, however well run, can teach staff to treat every single email with total suspicion. After all, email is how people do their jobs. So checking every message that closely leaves no time for anything else. NCSC’s advice is to build a culture where reporting a suspicious email is rewarded, even when it turns out to be nothing. A bad click should never get someone named in front of their manager.
Data protection and consent: what UK GDPR requires
A phishing simulation tracks named people. That means employers need a lawful basis to run one. They should also be open with staff about the fact that testing happens, even if the exact timing stays secret. The Information Commissioner’s Office treats this kind of activity as employee monitoring. Its guidance requires a data protection impact assessment (DPIA) before high-risk monitoring goes ahead. That covers any monitoring likely to put workers’ rights at risk.
In practice, that means three things. Tell staff, in a policy document, that phishing tests happen periodically. Agree the programme with HR first. Keep results at team or department level instead of naming people in a way that could feel harsh. Skip these steps, though, and a phishing test can create the exact legal and morale problems NCSC warns about.
How often should you test?
There is no single correct cadence. Benchmark data published by phishing simulation platform Hoxhunt gives a solid starting point. Organisations with no ongoing programme typically start with roughly a third of staff clicking a lure. Quarterly testing is the practical minimum for real gains. Monthly testing works faster. It often cuts the click rate nearly in half within a year.
Match frequency to risk. Finance and IT staff are higher-value targets for real attackers, so test them more often than the rest of the business. New starters benefit from an early test in their first three months, before habits set in. The same logic applies to your wider penetration test frequency. Risk should set the calendar, not a fixed annual date.
Phishing simulation testing vs a social engineering penetration test
The two get confused, but they measure different things. Phishing simulation testing checks one channel, email, against a large group. Its main output is a set of percentages: who clicked, who reported. A social engineering penetration test is narrower and deeper. A tester tries to actually get in. That might mean a targeted phishing email, a phone pretext call, or an attempt to walk into your building. The report shows exactly how far the tester got and what let them through.
Running both gives a fuller picture. The simulation shows how your whole workforce behaves at scale. The penetration test shows whether a determined, skilled attacker could still get past your best-performing staff. If that question matters to your business, Aardwolf Security’s penetration testing team can scope one alongside your existing awareness programme. Feel free to get in touch to talk through what that would look like.
Frequently asked questions
Is phishing simulation testing legal in the UK?
Yes, provided it runs fairly and transparently. Employers need a lawful basis under UK GDPR. They should tell staff that testing happens as a matter of policy, and avoid using results to discipline people. Running tests in secret raises the legal risk and the risk to trust by a lot, since no staff know they happen at all.
How much does phishing simulation testing cost?
Cost depends on staff numbers, how often you test, and the type of programme. A self-service platform costs less. But a security firm that also handles reporting and training costs more, and needs less of your time. Either way, a small business will pay far less than the cost of cleaning up after a real phishing attack. That is the comparison that matters most.
What counts as a good click rate?
There is no universal target. Chasing zero is the wrong goal, since a small share of people will always click under enough pressure. After all, a determined attacker only needs one. The trend over time matters more, and so does the reporting rate. An organisation where more staff report suspicious emails each quarter is improving, even if the click rate never reaches nothing.
Can phishing simulations replace security awareness training?
No. NCSC is clear that simulations are just one layer. They are not a substitute for wider training on passwords, multi-factor logins, and safe handling of sensitive data. Used alone, a simulation only measures a problem. Still, it does not fix it.
Do phishing simulations need HR sign-off?
Yes. The exercise involves monitoring named staff. It could affect morale or trigger a grievance if handled badly. HR, and ideally staff representatives too, should agree the programme before it launches.
Subscribe to our newsletter
Honest updates, straight to your inbox. Unsubscribe any time.