Phishing Simulation

A phishing simulation is a controlled campaign, run by the organisation itself, in which employees receive messages modelled on genuine phishing attempts. Its purpose is to practise recognising and, above all, reporting suspicious messages. In Germany the design has to be assessed under employment and data protection law before the first campaign.

ISMSLast reviewed:

Two things typically bring an English-speaking reader to this page. Either the simulation programme is running and the numbers are not persuading anyone, or the programme is running everywhere except Germany, where it has been sitting with the works council for months. The two problems have more in common than they look: both come from designing the campaign around the click rate.

What a simulation can and cannot do

A simulation creates a realistic decision situation. That is what separates it from training: employees are not reciting knowledge, they are reacting under everyday conditions: between two meetings, with a full inbox, without warning.

What it cannot do is assess individuals. The probability of a click depends heavily on time pressure, role, message type and the design of the lure. A single click supports no defensible statement about a person; many clicks support one about the organisation.

The metric that matters is the reporting rate

The common fixation on the click rate leads nowhere useful. In a real campaign a single click is enough to establish access, so the click rate can never be driven to zero. What makes the difference is the time to the first report: it determines whether the security function can act while the attack is still running.

Run the reporting rate and the time to first report as your headline metrics, and the click rate as a secondary one. That also changes the message inside the organisation: reporting is what is wanted, not being faultless.

The German employment law question

Phishing simulations touch two areas that have to be settled in Germany before the first campaign, and neither is resolved by a group-wide policy signed elsewhere.

  • Employee data protection. A simulation processes data about employee behaviour. Purpose, legal basis, the extent of the data collected, retention, who may access it and the use of external providers all have to be settled. Involve the data protection officer from the start rather than at sign-off.
  • Co-determination. Measures capable of monitoring the conduct or performance of employees can be subject to co-determination by the works council. Where a works council exists, bring it in early; an agreement covering purpose, the depth of analysis and the exclusion of individual sanctions gives both sides clarity.

Both points depend on how the campaign is designed. Have the specific approach reviewed legally rather than relying on general statements about permissibility. Usefully, the design choices that reduce the legal difficulty are the same ones that improve the programme: aggregate reporting, no individual league tables, no consequences attached to a single click.

Analysis: aggregated rather than personal

What works is an approach that limits the analysis from the outset: evaluation at the level of the organisation or of larger units, no rankings of individuals or small teams, no employment consequences from a click, a defined and short retention period for the raw data, and feedback that follows immediately on the click and explains what would have given the message away.

Run individual analyses instead and you get better numbers in the short term and fewer reports in the long term.

Designing a campaign

Raise the difficulty over time rather than opening with a lure almost nobody could spot. Spread campaigns across the year rather than bunching them. Announce the programme as a programme, not the individual wave. Avoid lures that exploit personal exposure: salary, bonus, redundancy, health matters or bereavement. Those lures work, and they cost the trust the reporting rate depends on. Agree the reporting path with the service desk beforehand, so the reports are not treated as noise.

One more point for multinational programmes: a lure that reads as ordinary in one country can read as intrusive in another, and the same wave landing in several jurisdictions at once will be judged by the strictest of them. Localising the lure is cheaper than defending it.

Embedding

A simulation without an accompanying programme is a test with no learning attached. It belongs inside an awareness concept with basic training, recurring prompts and a known, low-threshold reporting path. The value comes not from the campaign but from what happens between campaigns.

Browse all entriesBack to top

Frequently asked questions

See compliance run on your real assets

Rizzqo turns framework requirements into owned tasks on the assets you already have, and prices the risk in real money.

Made in GermanyEU-hostedMulti-framework