CyberISolve

Penetration Testing

What a Phishing Simulation Actually Tests (and What It Doesn’t)

December 2, 2025 · 5 min read

Phishing simulations get requested a lot, usually with an assumption that the deliverable is a single number: what percentage of staff clicked the fake link. That number is in the report, but treating it as the headline finding misses most of what the exercise is actually useful for.

Why click-rate alone is misleading

A low click rate can mean genuinely well-trained staff, or it can mean the simulated email was too easy to spot and didn’t resemble what a real attacker would actually send. A single simulation is a snapshot, not a trend, and a snapshot from an unrealistic scenario tells you very little.

What actually matters more

  • Reporting rate — how many people flagged the email to IT/security, not just how many avoided clicking
  • Time-to-report — how fast a real campaign would get flagged and contained
  • Which departments or roles are more targeted patterns, so training can be scoped where it matters
  • Whether credentials entered on a simulated landing page would have actually worked, if it went further than a click

How we run these

We vary scenario realism and difficulty across a program rather than running one easy simulation and calling it done, and we treat results as a training input, not a punitive scorecard — the goal is a workforce that reports suspicious email fast, not one that’s anxious about every message. Recurring, varied testing over time tells you far more than a single high or low number ever will.

← All Blogs

Related reading

Dealing with something similar?

Tell us what's going on — active incidents get a same-day response, 24/7.