A badly designed phishing simulation does more harm than running none at all. You send a deliberately cruel lure, half the company falls for it, you publish the list of who clicked, and you achieve two things: embarrassed staff and a team that from that day forward would rather tell you nothing. The well-run version of the same exercise achieves the opposite, staff who report earlier and faster. The entire difference sits in the design.

What a phishing simulation is actually for

The goal is never the score. A phishing simulation measures how your company as a whole behaves in front of a fraudulent message, and it is also the highest-impact teaching moment you will get, because it lands the instant someone has clicked and the scene is still fresh in their mind.

That forces you to decide what you want to know before you send anything. How many people spot an impersonation of the bank? How long until the first alert reaches the internal channel? Does anyone report the message without clicking at all? Each of those questions calls for a different campaign design.

Designing the lure: believable, not impossible

A campaign full of spelling mistakes and an absurd sender measures nothing, everyone dodges it and the conclusion is falsely reassuring. A campaign indistinguishable from reality, using internal details only a colleague would know, measures nothing either: it only proves that a perfect attack works, which we already knew.

The useful point sits at the level of sophistication your company would genuinely receive. For a Spanish SME that means a handful of recognisable scenarios:

  • A parcel tracking notice from Correos, the Spanish postal service, with an outstanding fee to pay.
  • A notification claiming to come from the AEAT, the tax agency, about a refund or a deadline-bound request.
  • A message attributed to Seguridad Social about a procedure that needs confirming.
  • An alert from your bank asking you to validate an unrecognised transaction.
  • An internal email linking to a shared document that requires you to "sign in again".

Smishing deserves its own campaign

An SMS is not email with fewer characters. It arrives on a personal phone, gets read in seconds, rarely passes through any corporate filter, and the link opens in a mobile browser where checking the real domain is awkward. There is also a technical detail that catches many people out: fraudulent messages can appear grouped in the same thread as legitimate messages from the impersonated sender, so the context a person uses to decide whether to trust is already contaminated.

That is why a smishing simulation teaches something the email one cannot: the rule cannot be "be suspicious of strange senders", because the sender looks like the usual one. The workable rule is to never act from the link in the message and instead go to the official portal or the banking app the usual way.

The ethics of the exercise, and why naming and shaming backfires

Publishing names, joking about it in a meeting or tying the result to performance reviews destroys the one asset the simulation should be building: people reporting. An employee who fears looking foolish hides the click, and a hidden click is exactly the situation that turns a small incident into a large one, because nobody can respond to what they do not know about.

Some lures should also stay off the table even when they work. Fake communications about redundancies, payroll, bonuses or health matters generate genuine distress and a resentment that outlasts any lesson learned. A good exercise leans on curiosity and routine, never on personal fear.

Three ground rules hold up everything else: aggregated results to management, never named lists; advance communication that the company runs periodic simulations, without saying when; and a conversation with whoever handles data protection and with employee representatives before you start, because you are processing behavioural data about identifiable people under GDPR.

Metrics worth more than the click rate

Click rate is the metric everyone asks for and the one that tells you least, because it depends mostly on how aggressive the lure was. These hold up far better across campaigns:

  • Report rate: how many people raised it through the internal channel. This is the only metric you want going up.
  • Time to first alert: the minutes between send and first warning define your real response capability.
  • Report-to-click ratio: measures whether the team reacts more than it falls, the true maturity indicator.
  • Credential submission: clicking is a stumble, typing the password is the failure that matters.
  • Repeat susceptibility: who falls campaign after campaign, so they get individual and discreet support.
  • Coverage by department: finance, sales and management receive different attacks and their results are not comparable with each other.

Cadence, and what happens after the send

One campaign per quarter, with rotating scenarios and rising difficulty, holds attention without wearing anyone down. Sending monthly turns the exercise into noise; sending once a year measures a single day rather than a trend.

What happens afterwards is half the value. Anyone who clicks should immediately see a short explanation of the three signals that gave that specific message away, with no scolding tone. Anyone who reports should get an explicit thank you, because you are rewarding precisely the behaviour you want to multiply. And management should receive the aggregated reading alongside the decision it implies: tighten the filter, adjust the payment process, or take a specific scenario into the next security awareness session.

Our phishing and smishing simulations are built around local scenarios, aggregated results and immediate reinforcement after the click. If you are about to launch a first campaign, settle two things beforehand: which channel a suspicious message gets reported through, and who answers that report. Without those two answers, a simulation only produces a percentage.

Want to know how exposed your website is?

Ciphraverse's Security Assessment checks websites, portals and e-commerce with a professional external audit designed for SMEs.

Discover Security Assessment