Metaluxo
← Blog

Phishing Simulations: What Not to Do

Phishing Simulations: What Not to Do

In 2023, a company sent a phishing simulation to employees offering a £500 bonus. Employees who clicked were publicly named in a company-wide email. The result: staff stopped reporting real phishing emails for six months.

This is what happens when phishing simulations are designed to catch people, not to teach them. At Metaluxo we design security awareness programmes for SMEs. The research on phishing simulation effectiveness is clear about what works and what does not.


What does not work

Trick emails. Simulations that use emotionally manipulative subjects — bonuses, layoffs, disciplinary action — create stress rather than learning. The lesson employees take away is not “how to spot phishing” but “the company tricks us.”

Public shaming. Naming clickers publicly or requiring them to attend remedial training damages psychological safety. Employees who fear punishment stop reporting incidents.

One-size-fits-all content. A phishing email designed for finance staff will not resonate with developers. Generic simulations have lower engagement and weaker learning outcomes.

No follow-up. A simulation without immediate feedback is just a test. Employees need to know why they clicked, what the red flags were, and how to spot similar emails in the future.


What works

Contextual scenarios. Use subjects relevant to the employee’s role. Finance staff see invoice fraud. Developers see fake dependency updates. Sales staff see fake CRM notifications.

Immediate, private feedback. When an employee clicks, show a brief explanation immediately — not a week later in a team meeting. Keep it private.

Positive reinforcement. Reward employees who report suspicious emails, even if they are simulations. Reporting behaviour is more valuable than click avoidance.

Graduated difficulty. Start with obvious phishing (poor grammar, wrong domain). Progress to more sophisticated attacks over time.

Regular cadence. Monthly simulations outperform quarterly ones. But keep them short — one email, one interaction, one minute of feedback.


The metric that matters

Phishing simulation click rate is the wrong metric. The right metric is reporting rate — the percentage of suspicious emails that employees report to security.

A company with a 5% click rate but a 2% reporting rate is less secure than a company with a 15% click rate and a 40% reporting rate. The first company has employees who do not click but also do not report. The second has employees who occasionally make mistakes but catch most attacks.


At Metaluxo we design phishing simulation programmes that focus on reporting behaviour, not click shaming. If your current programme is creating resentment rather than awareness, book a free 30-minute consultation and we will redesign it.

Roberto Arias — founder of Metaluxo. Virtual CISO work, ISO 27001 and incident response for small and medium businesses across the EU. Ask him a question →

Send us a message
Message us Book now