Skip to content
Knowledge base Updated: February 2, 2026

Phishing simulations and social engineering tests — how to conduct them ethically and effectively

How to plan a phishing simulation in 2026? ClickFix, QR phishing scenarios, test ethics, how to interpret results, and building a continuous awareness program.

An IT director at a logistics company once asked me whether it was really worth spending money on phishing simulations, since his employees were “already aware of threats” after the e-learning course they had completed a year ago. The answer was simple: after that conversation, we ran a phishing simulation. A message containing a crafted link — sent on a Wednesday at 10:15, in the middle of a normal working day — prompted a response from 38% of employees. One in three people at the company clicked, entered their credentials, or downloaded a file. Not one of those people was “careless” — the message simply looked credible and arrived at the right moment.

Phishing simulations and social engineering tests are today one of the most effective instruments for building an organisation’s resilience against attacks. Not because they frighten employees or catch them out in their mistakes. Because they deliver data where no other method can — because no security system will tell you whether your employee will click a fake link from “the CEO” at 8:50 on a Monday morning. This article explains how to plan such a test from start to finish, which scenarios matter in 2026, how to run tests while respecting employees, and how to move from a one-off campaign to a continuous programme that genuinely reduces risk.

Why are phishing simulations more effective than theoretical training?

Theoretical training imparts knowledge. A phishing simulation checks whether that knowledge changes behaviour in a stressful, realistic situation. This is a fundamental difference that I often explain to clients using a sporting analogy: you can listen to lectures on swimming technique for a year and still be unable to swim. Muscle memory is built through practice, not through listening.

Academic research from 2025 confirms that annual e-learning courses have “negligible effects” on click rates in phishing tests — this follows from an analysis of 12,511 employees conducted by the University of Chicago and UC San Diego, published at the Oakland 2025 conference. Verizon’s DBIR 2025 noted that the click rate in phishing simulations has been stuck for years at around 1.5% in well-managed programmes — but for organisations without active simulations, KnowBe4’s Phishing by Industry Benchmark Report 2025 puts the baseline as high as 33.1%. That is a gap no e-learning course can close on its own.

Why does a simulation work where training falls short? Because it engages emotions and context. An employee who clicks on a simulated message and lands on a page informing them that they have just “been caught” retains that lesson far better than a slide showing a picture of a suspicious email. What is more, a simulation reveals gaps specific to the organisation: who is susceptible, at what times of day, to what types of lure, and from which job roles. Training provides general knowledge — a simulation provides operational data.

An important point of context: simulations do not replace training, they complement and verify it. Organisations achieving the best results use a hybrid model — training builds knowledge, simulations test it, and each simulation is followed by a corrective micro-training. According to KnowBe4, this model reduces employee susceptibility by 86% over 12 months. That figure is not achieved by training alone or by simulations alone — it is the effect of combining both.

Key takeaway: Phishing simulations are the only method that measures actual employee behaviour under realistic threat conditions. Training builds knowledge — simulations test whether knowledge translates into a defensive reflex.

📚 Read the complete guide: SOC: Security Operations Center - czym jest, jak działa, jak wybrać

How to plan a phishing simulation campaign — from scenario to report?

In conversations with clients, the most common misconception I encounter is that a “phishing simulation” means a mass mailing of a suspicious email to all employees. This misunderstanding is worth clearing up at the outset of any planning. A well-planned campaign begins with a risk analysis and ends with a report containing recommendations — the email is only one element among many.

The first step is to define the campaign objective. Do we want to measure the general level of susceptibility (baseline measurement), or are we testing the effectiveness of a specific training course that has just been delivered? Are we interested in the entire organisation, or a specific department — for example accounting, HR or the help desk, which are statistically the most frequent victims of BEC (Business Email Compromise) attacks? Without a clearly defined objective, it is difficult to assess afterwards whether the test was a “success”.

The second step is to choose the scenario and difficulty level. At this stage, we decide how sophisticated the lure should be: whether we simulate a generic message about an alleged courier delivery (low difficulty, good for baseline measurement), or a message from “the CEO” to a specific person in finance requesting urgent confirmation of a bank transfer (high difficulty, good for assessing preparedness following training). In 2026, ClickFix and QR phishing scenarios have joined the arsenal — I cover these in more detail later in the article.

The third step is to agree on the scope and rules with management. This is a formal stage that is frequently skipped by organisations opting for a “surprise” test without the knowledge of senior leadership. Skipping it is a mistake — not only ethically, but practically. If an employee reports a “suspicious email” to the help desk and the help desk has no knowledge of the campaign, a chain reaction can follow: an IT alert, the sender being blocked, or a false security alarm. Every simulation should have written authorisation from a sponsor (CISO or board), a defined scope (which individuals are covered by the test), a schedule, and a procedure for handling escalation.

The fourth step is execution and monitoring. Professional platforms (KnowBe4, Cofense, Proofpoint Security Awareness, Hoxhunt) automate delivery and collect data in real time: who received the message, who opened it, who clicked the link, who entered their credentials, who downloaded a file, and — equally importantly — who reported the suspicious message to IT. This last metric is often more important than the click rate, because it measures an active defensive posture, not merely passive resilience.

The fifth step is the report and follow-up actions. The report should contain quantitative data (metrics), qualitative analysis (why a specific scenario proved effective) and concrete recommendations. It is not a list of employees who were “caught” — it is a map of awareness gaps across the organisation, indicating where to focus the next round of training.

Key takeaway: Planning a phishing simulation campaign is a five-stage process: objective → scenario → management authorisation → execution → report with recommendations. Omitting any stage reduces both the value of the data and the level of employee trust.

Which phishing scenarios should be tested in 2026 — classic phishing, ClickFix, QR codes?

The threat landscape in 2026 is far richer than it was five years ago. Classic email phishing remains the dominant vector, but attackers have added techniques that bypass both technical filters and the awareness built through traditional training. A good simulation should test susceptibility to current threats — not only to a “suspicious email with a link”.

Classic email phishing still dominates and remains effective. The scenarios that achieve the highest click rates in 2026 are: fake notifications from systems the organisation actually uses (Outlook, Teams, SharePoint, HR systems), alerts about password expiry or the need to verify an account, messages from “the CEO” or “finance” requesting confirmation of a bank transfer (BEC), information about deliveries and invoices, and notifications about “suspicious account activity”. The power of these scenarios lies in context — an employee who knows the company uses Teams is more susceptible to a fake Teams notification than to a generic email from an unknown sender.

ClickFix is a scenario that saw a 517% increase in detections in 2025 according to ESET’s Threat Report H1 2025. In a ClickFix simulation, the employee arrives on a page (via a link in an email, an advertisement, or a redirect) and sees a message suggesting a technical problem — a fake CAPTCHA, a message about the need to “verify the browser”, or an error that can be “fixed” in one step. The instruction tells them to open the Run dialogue (Win+R) and paste in a command. The ClickFix simulation is valuable because it tests behaviour that traditional anti-phishing training does not address at all. Employees trained to “not click suspicious links” have no defensive reflex against a request to open a system dialogue window.

QR phishing (quishing) is a technique that bypassed email anti-spam filters for more than a year. Instead of a link in an email, the message contains a QR code leading to a fake page. Because email filters scan text and URLs, not image content, QR codes went undetected into recipients’ inboxes for a prolonged period. In a quishing simulation, we test whether an employee will scan a QR code from an email or a poster (physical tests) without verifying where it leads. According to Cofense, quishing accounted for up to 2% of all phishing emails in 2025 — which, at corporate volumes, translates to hundreds of thousands of attempts per day globally.

Vishing (voice phishing) and smishing (phishing via SMS) are scenarios of particular relevance to organisations with large numbers of mobile employees or customer-facing roles. In vishing, the attacker calls and poses as an IT help desk, supplier, auditor or “bank”. In smishing, the lure arrives by SMS with a link to “verify” something or “collect a parcel”. Simulations of these techniques require somewhat different logistics than email tests, but they deliver valuable data on susceptibility to telephone-based attacks.

Spear phishing — highly personalised messages directed at a specific individual — is a scenario for advanced testing programmes. The attacker (or tester) gathers information about the target from LinkedIn, the company website and social media, then constructs a message that references specific projects, professional relationships or current events within the organisation. Spear phishing is many times more effective than mass phishing — and many times more difficult for the employee to detect.

Key takeaway: A simulation programme in 2026 should cover at least four vectors: classic email phishing, ClickFix (fake system prompts), QR phishing (quishing) and vishing. Testing email alone gives a false picture of the organisation’s resilience.

How to conduct social engineering tests without undermining employee trust?

This is a question I hear from almost every client planning their first social engineering tests. The concern is legitimate: a poorly conducted test can destroy a security culture instead of building it. An employee who feels “monitored” or “accused of stupidity” will lose the motivation to report suspicious incidents — and that is one of the most valuable defensive mechanisms in any organisation.

Principle number one: the target of the test is the organisation, not the individual employee. Results should be reported at the level of departments, job roles and groups — not as a list of names annotated with “clicked”. A person who was “caught out” in a simulation should not fear disciplinary consequences. They should be directed to a micro-training that explains what to look out for and how to respond next time. This is the approach recommended by both NIST SP 800-50 (Revision 1, 2024) and the industry best practices of organisations such as the SANS Institute.

Principle number two: transparency towards employees — but at the right level. Employees should know that the organisation conducts regular social engineering tests (this is part of the security culture), but they should not know the date and details of a specific campaign (this would destroy the value of the measurement). Good practice is to describe the testing policy in the information security policy or employment regulations that employees sign, and to communicate regularly that tests form part of the security awareness programme — not a punishment or surveillance measure.

Principle number three: do not use scenarios that exploit traumatic emotions. In the history of phishing simulations, there have been cases of campaigns that simulated the “death of a loved one” or a “child’s accident” — such scenarios provoked justifiable outrage and were widely condemned by the security community. The lure may appeal to natural curiosity, business urgency or professional loyalty — but not to personal tragedies. This is a matter of both ethics and effectiveness: traumatic stress does not improve learning.

Principle number four: treat those who were “caught” with respect. When an employee clicks on a simulated message and lands on a “this was a test” page, the message should be educational and supportive, not shaming. “You have just taken part in a phishing simulation. Here is what could have told you this message was suspicious…” — that is the right tone. Not: “You failed to recognise the phishing attempt. Your action posed a threat to the organisation.”

Principle number five: provide support for employees who report. Every person who reports a suspicious message to IT — even if it was part of a real simulation — should receive prompt confirmation and a word of thanks. Building the habit of reporting is more important than measuring the percentage of people “caught”. Organisations in which reporting is rewarded achieve significantly better security outcomes than those where employees fear being seen as paranoid.

Key takeaway: An ethical social engineering test protects the dignity of employees, reports results at group rather than individual level, applies transparency at the right level and treats every result as a learning opportunity — not as disciplinary material.

How to interpret simulation results — what does a rate of 33% versus 5% mean?

In conversations with clients after a first phishing simulation, I most commonly hear two types of reaction: “it’s a disaster, 33% clicked” or “only 5%, everything’s fine”. Both readings are incomplete without context. Interpreting simulation results is a skill worth developing — because numbers without a benchmark and a trend tell you very little.

A click rate of 33% in the first simulation is a typical result for an organisation with no previous security awareness programme. The KnowBe4 Phishing by Industry Benchmark Report 2025 puts the average baseline at 33.1% across all industries combined. In the insurance sector it is 38.9%, in healthcare — 41.9%, in financial services — 32.4%. If your organisation records 33% in the first test, that is not a “disaster” — it is a starting point from which to measure progress. The disaster would be still having 33% after a year of an active programme.

A click rate of 5% after a year of active training and simulation is a good result — close to the KnowBe4 benchmark for organisations with mature security awareness programmes. But “only 5%” in the very first test, with no previous programme, should prompt questions rather than satisfaction. Possible explanations include: the scenario was too obvious (insufficiently realistic), employees warned one another through informal channels, or you have an organisation with a very low base of email users. A low click count is information that needs to be interpreted, not celebrated without analysis.

The click rate is only one of several key metrics. Equally important is the reporting rate — what percentage of employees who received the phishing message reported it to IT rather than simply ignoring or deleting it? In mature organisations, the reporting rate is 60–80%. A low reporting rate (below 10%) combined with a low click rate may mean employees are simply ignoring the message — which is not the same as recognising a threat and taking active defensive action.

The open rate and the credentials submission rate are further layers of analysis. A message that was opened but whose link was not clicked may indicate suspicion — or it may mean the employee had no time or motivation to act. Clicking a link without entering credentials represents a different level of risk from a full compromise involving submission of a username and password. Each stage of the funnel (open → click → credentials) provides different information about the level of risk.

Finally — interpretation should account for segmentation. A 15% average rate across the organisation may mean 5% in IT and 40% in customer service. These are not one organisation with one problem — they are two entirely different risk profiles requiring different interventions. A report that lacks segmentation by department and job role is incomplete.

Key takeaway: 33% clicks in the first test is the industry standard for organisations without an awareness programme. 5% after a year of active programme is a good target. What matters is tracking the trend, not assessing a single measurement — and analysing the reporting rate alongside the click rate.

How to communicate test results to management and employees?

The way simulation results are communicated has a direct impact on the security culture within the organisation. Poor communication can destroy what the test was meant to build. Good communication turns results into a risk management tool and builds engagement at all levels.

To management, I communicate results in the language of business risk, not technical language. The point is not that “33% clicked a link” — the point is that “one third of the organisation is susceptible to an attack that could result in a data breach and costs in the hundreds of thousands of zlotys”. Management needs to see results in context: what does this rate mean compared to the industry benchmark? What is the risk at the current level of susceptibility? How much does it cost to reduce this risk by 80%? The number “33%” without context will not motivate management to act — “33%” accompanied by a risk map and ROI already will.

Management also receives information about the trend. If this is the first simulation — I present the baseline and the plan. If it is a subsequent one — I show the change relative to the previous measurement. Management that can see the click rate has dropped from 33% to 12% over six months understands that the investment in a security awareness programme is delivering results. This is the argument for continued programme funding in the next budget cycle.

To employees, I communicate results in a way that is constructive rather than punitive. Instead of announcing “last week 38% of you clicked a phishing link”, I prefer the message: “We conducted a phishing simulation to see how our security awareness programme works in practice. Here is what we learned — and here is what we will change so we can all be safer together.” This is a subtle but significant difference: the organisation learns together, employees are not to blame.

Good practice is to create an “educational moment” directly after the simulation, before news of the results spreads through informal channels. Within 24–48 hours of the campaign ending, it is worth sending a brief message to all employees: “We have just completed a phishing simulation. If you clicked the link, you landed on an educational page — it was not a real attack. Here is what the threat looked like and how to recognise it next time.” Employees appreciate the fact that the organisation explains rather than conceals.

For departments with a noticeably higher susceptibility rate, dedicated training sessions or workshops are more appropriate than a general announcement. A finance department with a 50% click rate needs a different intervention to an IT department with 8%. Personalising post-simulation actions is one of the factors that distinguishes mature security awareness programmes from those that are merely ticking a regulatory checkbox.

Key takeaway: To management — the language of business risk and ROI. To employees — the language of learning and shared responsibility. Never publicly identify those at fault, and always explain what employees could have done differently.

How to move from a one-off test to a continuous programme?

A one-off phishing simulation is like a single medical check-up: it provides a valuable snapshot, but it does not build long-term resilience. Organisations that achieve the lowest susceptibility rates treat social engineering tests as a continuous process — not a project with an end date.

The transition from a one-off test to a programme begins with a change in the internal narrative. Phishing simulations stop being “checks on employees” and become “regular organisational training”. This change must come from leadership — if the CISO or IT director presents tests as a punishment for inattentiveness, employees will experience them as a threat. If they present them as “a security culture we are building together” — they build engagement.

A continuous programme is built on a cycle: simulation → analysis → corrective training → simulation. The frequency depends on the maturity of the organisation and the level of risk, but in conversations with clients the recommendation most commonly looks like this: two full phishing campaigns per year for the entire organisation, plus monthly “micro-tests” for the highest-risk groups (finance, HR, board). Micro-tests are shorter, more targeted simulations that maintain vigilance without creating test fatigue.

A key element of the programme is diversity of scenarios. Employees who see the same type of message in every test learn to recognise only that pattern — and remain susceptible to every other. A good programme rotates vectors (email, QR, vishing, ClickFix), difficulty levels (generic phishing vs. spear phishing) and topics (invoices, passwords, HR, executives, suppliers). Rotation prevents “immunisation to a single pattern” and maintains vigilance across a genuinely broad spectrum of threats.

Programme metrics should be tracked over time and presented to management regularly — quarterly or twice a year. Key indicators are: click rate (a downward trend is success), reporting rate (an upward trend is success), time from simulation to report (a reduction in this time is success), and regulatory coverage (whether all scenarios required under NIS2/KRI are covered by the test). A programme without measured outcomes is a programme without accountability.

Human resources are often the bottleneck. Organisations without a dedicated CISO or security team have difficulty managing a continuous programme in-house. This is where managed security awareness services come in — external programmes in which the provider manages the platform, scenarios and reporting, while the organisation receives ready-made dashboards and recommendations. At nFlo, we run such programmes for clients who want continuity without needing to build internal competencies.

Key takeaway: A continuous security awareness programme is a cycle: simulation → analysis → corrective training → simulation. The minimum frequency is two campaigns per year for the entire organisation. What matters is diversifying scenarios and tracking trends, not just individual measurements.

What are the most common mistakes organisations make in phishing simulations?

In conversations with clients and through analysing the results of tests we conduct at nFlo, a recurring set of mistakes emerges. Some are execution errors — they can be corrected with better organisation. Some are conceptual errors — they require a change of approach to the programme as a whole.

Mistake number one: no management authorisation and briefing. A phishing simulation conducted without the knowledge of the board or CISO is a simulation without a sponsor. When an employee escalates a “suspicious email” to their manager and the manager knows nothing about the test, a chain reaction can follow — an IT alert, the sender being blocked, an external notification. I have seen cases where a company accidentally reported an “incident” to CERT because nobody in the management chain knew about the test campaign.

Mistake number two: using the same scenario year after year. Organisations that year in, year out send employees a “password expiry notification” as a phishing test are measuring not susceptibility to phishing, but employees’ ability to recognise one specific pattern. After two or three iterations, the click rate drops to almost zero — not because employees are secure, but because they have learned to ignore that one particular message. On ClickFix or quishing they might still respond with a 40% rate.

Mistake number three: no follow-up action after the simulation. A test without corrective training is a wasted educational opportunity. If 200 employees click a simulated link and receive no feedback or educational materials, test results will improve more slowly, and employees may feel they were “monitored” with no consequence. Every clicked lure is a moment when the employee is most open to learning — and that moment should be used.

Mistake number four: reporting without segmentation. An aggregate rate of “18% clicks across the whole company” conceals the information that the IT department has 2% while sales has 45%. Without segmentation by department, job role and location, you cannot direct corrective actions to where they are most needed. A simulation platform that does not offer granular reporting is an inadequate tool.

Mistake number five: penalising employees who were “caught out”. This is the most destructive mistake, one that undermines the security culture. An employee who opened a simulated phishing email, landed on an educational page, and is subsequently called in for a conversation with their manager will not report a real incident next time — because they fear the consequences. And reporting a real incident within minutes rather than hours can determine whether an attack is stopped before it spreads to other systems, or not.

Mistake number six: overlooking physical tests and vishing. Many organisations test only email phishing, assuming it is the only significant vector. Yet in the public sector, vishing (telephone pretexting) remains an effective technique, and QR phishing via posters in the office is a scenario increasingly encountered in corporate environments. A comprehensive programme must go beyond email.

Key takeaway: The six most common mistakes are: no management authorisation, the same scenario indefinitely, no follow-up after the test, no segmentation of results, penalising employees, and ignoring non-email vectors. Avoiding these mistakes is the difference between a programme that works and one that merely looks like it does.

What does a test-based improvement cycle look like?

A mature security awareness programme is not a collection of one-off tests — it is a closed improvement cycle in which each simulation generates data, data generates recommendations, and recommendations feed back into the programme. The table below shows an annual improvement cycle for an organisation running a continuous programme.

QuarterActivitiesMetricsGoalsResponsible
Q1 — Baseline measurementFull phishing campaign for the entire organisation (generic scenario, medium difficulty). Audit of the current training programme.Click rate (baseline), reporting rate, segmentation by departmentEstablishing the starting point. Identifying high-risk groups.CISO / external provider
Q1 — TrainingE-learning training for groups with the highest click rates. Updating modules with new scenarios (ClickFix, QR). Organisation-wide communication about results (without identifying individuals).Training completion (% of employees), knowledge test scores after training90%+ training completion in high-risk groupsHR / training department
Q2 — VerificationControl campaign for high-risk groups (same scenario as Q1). Micro-tests for board and finance (BEC / CEO fraud scenario).Change in click rate vs. Q1 (target: -40%), reporting rateConfirming improvement following training. Assessing management preparedness.CISO / external provider
Q2 — ReportingQuarterly report for management: trends, industry benchmarks, recommendations. Planning the H2 budget.Programme ROI, comparison with industry benchmark (KnowBe4)Management decision on continuation and scope of the H2 programmeCISO / CFO
Q3 — New scenariosCampaign with a new vector (ClickFix or QR phishing) for the entire organisation. Practical workshops for groups with persistently high susceptibility.Click rate for the new vector, comparison with Q1Assessing preparedness for new attack typesCISO / external provider
Q3 — Culture”Security awareness week” — communications, posters, Q&A sessions. Rewarding active reporters of suspicious emails.Number of reports from the “phish alert” campaign, engagement in Q&A sessions20% increase in reporting rate vs. Q1HR / communications team
Q4 — Annual assessmentFull phishing campaign (analogous to Q1). Regulatory coverage audit (NIS2 / KRI). Assessment of the full-year programme.Click rate (target: below 5% for the entire organisation), reporting rate (target: above 60%)Confirming achievement of annual goals. Compliance validation.CISO / auditor
Q4 — PlanningAnnual report for management. Planning the next year’s programme: new scenarios, expanded scope, updated budget.Q1 vs. Q4 comparison, industry benchmark, programme cost vs. avoided riskGoals and budget for the following year approved by managementCISO / CFO / board

A few observations from practice: organisations going through such a cycle for the first time typically achieve a 50–60% reduction in click rate within a year. Organisations with a multi-year programme reach levels below 5% and focus on maintaining vigilance against new vectors. The critical point is that the cycle must not end at Q4 — every Q4 result becomes the baseline for a new Q1.

How does nFlo design and deliver social engineering tests?

At nFlo, we approach social engineering tests as a comprehensive advisory service, not as a one-off “product from a catalogue”. Over more than 500 completed security projects, we have developed an approach that combines technical precision with sensitivity to organisational culture — because we know that a poorly conducted test can cause more harm than no test at all.

Every engagement begins with a diagnostic conversation. Before proposing campaign scenarios, I want to understand the organisation: what training is currently in place, what the history of incidents looks like, what the security culture is, who is the programme sponsor, and what outcomes are expected. This diagnostic usually takes one meeting, but it determines whether the campaign delivers valuable data or merely statistics.

When designing scenarios, we draw on current threat intelligence — including ClickFix variants, quishing campaigns and BEC techniques that are being actively used by criminal groups in Poland and Central Europe. Our scenarios are not copied from SaaS platform templates — they are tailored to the industry, size and context of the client. A simulation for a local government office looks different from one for a logistics company, and both differ from one for a financial institution.

Campaign delivery is carried out in accordance with the ethical principles described earlier in this article: written authorisation from the sponsor, no personalisation of results down to the individual level in internal communications, and an educational rather than shaming message when an employee clicks on the lure. We monitor the campaign in real time and remain reachable by phone throughout its entire duration — in case the simulation generates an unintended escalation.

The post-campaign report is one of the elements clients most consistently highlight as valuable. It is not a table of numbers — it is a document that explains why a particular scenario proved effective, how the results compare to industry benchmarks, which departments require priority action, and what specific steps we recommend in the next 30, 60 and 90 days. The report also includes ready-made slides for management — because we know that the CISO needs to “sell” the results internally.

We respond to incidents in under 15 minutes — which means that if unexpected events occur during a campaign (an employee reports an “attack” to CERT, the help desk blocks our test server, a real threat emerges in the same time window), we are ready for immediate escalation and support. Across 200+ clients and 98% retention, we have learned that availability and speed of response build trust more than any certificate.

For clients who want a continuous programme, we offer managed security awareness — an annual engagement in which we plan, execute and report on regular campaigns, manage the relationship with the training platform, and deliver quarterly briefings for management. This model eliminates the need to build internal competencies while maintaining full control over results and the direction of the programme.

Frequently asked questions

No — employees do not need to give individual consent to participate in a simulation, provided that the obligation to conduct security tests is described in the organisation’s policies (information security policy, employment regulations or employment contract). What is essential is having written authorisation from the sponsor (board, CISO) and ensuring that results will not be used for disciplinary purposes.

How often should phishing simulations be conducted?

A minimum of twice a year for the entire organisation, with monthly micro-tests for high-risk groups (finance, HR, board). Under the requirements of NIS2, training must be regular — meaning a single campaign once every few years does not meet regulatory requirements.

Which platforms are best for phishing simulations?

The market offers: KnowBe4 (the largest scenario library, good industry benchmarks), Cofense (strong in detection and response), Proofpoint Security Awareness (good integration with email protection), Hoxhunt (gamification model, high user engagement) and Terranova Security (strong training component). The choice depends on the number of employees, the required scope of reporting and integration with existing infrastructure. At nFlo, we run campaigns on client platforms or with our own test infrastructure.

What is phishing resistance training and does it replace simulations?

Phishing resistance training is training focused on specific defensive mechanisms: checking URLs, verifying senders, using a password manager and FIDO2 keys. It does not replace simulations — it complements them. Simulations measure behaviour, training builds competencies. The most effective model combines both.

Do social engineering tests include physical tests?

Advanced social engineering tests can include physical tests: tailgating (following an authorised person through a security gate), testing the reaction to a “lost USB drive” found in the office, testing QR code phishing via posters in shared spaces, or checking how reception responds to an unknown individual claiming to be an IT technician. Physical tests require particularly careful agreement with management and a precisely defined scope.

How do you calculate the ROI of a security awareness and simulation programme?

Basic ROI model: cost of the programme (training + simulations + internal time) vs. avoided losses (probability of a successful attack × average cost of an incident in the given sector). For a 200-person organisation: annual programme cost of 30,000–60,000 PLN vs. avoided losses with 80% susceptibility reduction — assuming a 5% probability of attack and an average incident cost of 500,000 PLN, this yields an ROI of 4x–8x the invested amount.

Explore key terms related to this article in our cybersecurity glossary:

  • Phishing — Phishing is a social engineering technique involving impersonation of trusted entities…
  • Social engineering tests — Social engineering tests are a method of assessing organisational security by simulating…
  • Social engineering — Social engineering is a set of psychological manipulation techniques used by attackers…
  • Cybersecurity — Cybersecurity is the collection of techniques, processes and practices for protecting IT systems…
  • Security Awareness — Security awareness is the level of knowledge among an organisation’s employees regarding cyber threats…

Learn more

Explore related articles in our knowledge base:


Check our services

Need support with cybersecurity? See:

Sources

  • KnowBe4, Phishing by Industry Benchmark Report 2025 — click rate data and industry benchmarks
  • Verizon, Data Breach Investigations Report (DBIR) 2025 — analysis of attack vectors and click rates
  • ESET, Threat Report H1 2025 — 517% increase in ClickFix detections, share of global attacks
  • IBM Security, Cost of a Data Breach Report 2025 — average cost of a data breach: $4.44M globally
  • Proofpoint, Human Factor Report 2025 — ClickFix growth of 400% year on year, APT groups
  • Cofense, Phishing Defense Center 2025 — quishing data, QR phishing campaign volumes
  • NIST SP 800-50 Rev. 1 (2024) — guidelines for security awareness programmes
  • University of Chicago / UC San Diego, Security Awareness Training Study (Oakland 2025) — effectiveness of training on click rates

Need expert support? nFlo team can help secure your organization:


See also:

Share:

Talk to an expert

Have questions about this topic? Get in touch with our specialist.

Sales Representative
Łukasz Gil

Łukasz Gil

Sales Representative

Response within 24 hours
Free consultation
Individual approach

Providing your phone number will speed up contact.

Want to Reduce IT Risk and Costs?

Book a free consultation - we respond within 24h

Response in 24h Free quote No obligations

Or download free guide:

Download NIS2 Checklist