Easy Phishing Simulations Create False Confidence

Table of Contents

Executive Summary: Why Easy Phishing Tests Miss Real Risk

A client had been sending phishing simulations for years. The metrics looked good and the test emails were being identified. But real phishing emails were still getting clicks, even from the leadership team.

Virtuas introduced a custom phishing simulation for the client, one based on a plausible work-based scenario. Over half of the people clicked. While not the desired result, the problem was identified while still contained in a phishing campaign, without real-world consequences.

This is a solid case for custom phishing simulations. People have space to get it wrong before an attacker is the one sending the message. The organization can better identify what people know, what processes can be improved and what training needs improvement.

Repeated Phishing Templates Test Recognition, Not Judgment

The more people know about a test, the better they will do.

After repeated phishing simulations, employees start to recognize the patterns they are being tested on. Similarities between phishing templates allow employees to identify a message as a test before inspecting the sender or thinking critically about its content.

The click rate dips, which looks like improvement. But instead, it’s familiarity that’s been tested. For instance, if an employee gets a fake Dropbox file-sharing notification, but the company doesn’t use Dropbox, it doesn’t take much judgment to ignore it. If the request is for a service the employees do use regularly, it presents a more meaningful test.  An email that fits the company profile will tempt the recipient to act, just like they would during a real attack.

The NIST Phish Scale takes this into account, evaluating both the warning signs presented in the message and the plausibility of the premise. The more workplace-relevant a message is, the harder it can be to assess, especially when it fits within the recipient’s job function.

While a low click rate looks good on the surface, the real question remains. If they already have the answer key, what does a good score really tell you about how employees will react to a real-world experience?

Easy Phishing Simulations Create False Confidence - hand on a mouse next to a laptop | Virtuas.com

Realistic Phishing Simulations Reflect How Employees Work

How much would an attacker need to know about your organization to write a convincing phishing email? Unfortunately, most of the data they need is readily available.

Company websites identify the leaders of the company, their locations and what open roles are posted. LinkedIn shares an individual’s role, their coworkers, and even more information about the company they work for. Vendor logos on partner pages, articles about a service you use, and even DNS records will reveal what technologies are used in the stack. Add in basic business timing like benefits enrollment or annual reviews, and an attacker has enough information to create an email that looks credible.

A subtle lure isn’t necessarily the most technical. It’s the message that gives the recipient a reason to click. These emails encourage the recipient to act at the exact moment they should pause and investigate.

Warning signs will still be present. The sender name may be off, or there may be an obvious external email banner. But when the communication is credible and time-sensitive, an employee may stop paying attention to those subtle indicators and rush to act instead.

A realistic simulation gives employees the chance to have this experience safely and practice the pause an attacker would hope to avoid.

A Realistic Phishing Test Exposed Hidden Risk

For one client, Virtuas developed a scenario around compensation. The message claimed that updated salary information was available, giving employees an immediate reason to react and click through.

While the premise was plausible, the message could still be identified as false. It was sent from outside the organization with incorrect sender information. A careful reader still had a path to the right decision.

Over 50% of the recipients clicked.

No security leader wants to see that number. But the campaign was a success in one respect: it identified a vulnerability which prior phishing simulations hadn’t identified. A passing grade would have given the organization a false sense of security.

The click rate became a teachable moment. Employees were directed to additional training where the warning signs could be reviewed while the error was still fresh. The organization got valuable insight for the next campaign, and a better understanding of what cues needed reinforcement.

Why Phishing Platforms Need Business Context

Proofpoint has the tools to build, deploy and track phishing simulations. It can tell an organization who clicked, who reported it and how the campaign performed. But it can’t know which story will fly under the radar within the workplace.

Proofpoint’s guidance on turning phishing threats into behavior change makes the same point. Modern phishing attacks should be designed around business context and specific roles. Training is more useful when it reflects the lures and tactics employees are likely to encounter from real phishing attacks.

Knowledge of the company shapes the scenario, timing and difficulty of the simulation. The campaign design also influences what the metrics mean. Lower click rates on targeted, plausible tests are encouraging, and a higher reporting rate in the same campaign is even more meaningful.

The platform manages the campaigns, but the value depends on the customizations and scenarios implemented.

Easy Phishing Simulations Create False Confidence - user with mouse and laptop in a dark room | Virtuas.com

Build Phishing Awareness Without Punishing Employees

Phishing simulations often have an adverse effect. Employees feel like they’ve been tricked, the security team shares the poor click rate and people are frustrated by the outcome instead of wanting to learn from the lesson. There is a better way to create a memorable experience.

Bryan Perkola, Senior Vice President of Information Security at First Community Credit Union spoke at CYBR.SEC.CON. 2026 about an internal program that prioritizes continuous reinforcement and employee involvement. Campaigns are deployed on a randomized interval so employees can’t rely on the assumption that they’ve already been tested for the week. Difficulty increases as employees’ tenure continues, with realistic examples designed to hook the reader, tying the simulation to messages employees could receive outside of the training program.

Perkola’s program also focuses on reporting behavior, training engagement and changes over time as ways to illustrate when employees are building better habits. A case study from KnowBe4 reports that First Community Credit Union was able to drop its phish prone percentage from 30% to 1% while maintaining phish training completion rates over 90%.

A positive phishing education culture does not punish mistakes. It treats them as information, responds with useful education and makes it easier for employees to help defend the organization.

What a Phishing Simulation Should Actually Measure

The next time a low click rate appears on a phishing report, the first question should be, “What did employees have to identify to get this right?”

Was the message plausible enough to warrant attention, yet still identifiable as phishing by an alert employee? Did people report it, or was it irrelevant to them?

A successful simulation shows how employees respond when credibility and caution compete for a decision. The result may confirm that training is working or reveal a shortcoming that needs addressing. Either outcome gives the organization something specific to act on.

Virtuas designs phishing campaigns around how an organization’s employees actually work, with each scenario designed to be as realistic as possible. The goal is a practical approach to phishing campaigns, built to encourage learning and continually improve the next decision.

References

National Institute of Standards and Technology. (n.d.). The NIST Phish Scale: Considering user context in phishing awareness programs.

Proofpoint. (2026). Proofpoint ZenGuide: Transforming security awareness training into behavior change.

KnowBe4. (2026). How First Community Credit Union reduced phishing risk by 97%.

Facebook
Tweet
LinkedIn
Virtuas logo representing productivity enhancement and AI integration for modern business workflows.

Virtuas

Our team @Virtuas