Skip to main content
All lessons
Lesson 5Social Engineering Defense pathway

Run Phishing Simulations Safely

Test the click, not the person

Highlighted wordsare glossary terms — tap one for a plain-language definition.

A simulation is meant to measure and improve real-world resilience — not to trap or embarrass people. NIST and CISA guidance supports a scoped, non-punitive, well-documented exercise that strengthens reporting and response. [1, 2, 3, 4]

Scope it before you send anything

CISA's own Phishing Campaign Assessment is a defined, opt-in service: it targets a specific group of users, runs for a set period, and is set up through signed paperwork with the organization before a single email goes out. Treat any internal simulation the same way — written authorization, a defined target list, a fixed time window, and an agreed stop condition. [3, 4]

  • Get written sign-off from leadership, legal, and IT/security before launch.
  • Define exactly who is in scope, for how long, and who can pause the exercise.
  • Confirm a stop condition in advance if the simulation causes unexpected disruption.

Simulate the click, not the harm

NIST's Phish Scale exists to rate how difficult a simulated email is to detect — it is a measurement tool for training design, not a method for extracting real passwords or delivering working . Keep simulations to lookalike lures that log an action (click, report) rather than pages that store real credentials or payloads that actually execute. [1]

  • Never collect real passwords, codes, or other sensitive data through a simulated page.
  • Use a harmless landing page and disable any real malicious functionality.
  • Minimize what's logged about each person to what's needed for training metrics.
  • Avoid lures built around trauma, health, layoffs, immigration, or personal emergencies, and make the teaching page accessible.

Teach the moment it happens — don't punish it

NIST's guidance frames click rate and report rate as metrics to interpret in context — how hard the actually was — so results can drive better just-in-time coaching rather than blame. CISA's phishing guidance likewise treats reporting as the goal to reinforce, with a clear, easy channel for anyone to flag a suspicious message. [1, 2]

  • Deliver a short, friendly teaching moment immediately after a click, not a punishment.
  • Track and reward reporting behavior, not just avoiding a click.
  • Interpret results against the lure's difficulty, not as a simple pass/fail on each person.

Keep it separate from real incidents, and repeat it

A simulation must never weaken the response to a genuine threat: keep the real reporting channel active, brief the small response team that needs to know, and stop the exercise if it causes unexpected risk. Run assessments repeatedly (CISA's own service spans six weeks) so you can track improvement over time instead of judging from a single snapshot. [2, 3, 4]

  • Make sure responders can distinguish the simulation platform from real attacker infrastructure.
  • Give staff one unambiguous way to report anything that might be a real phishing attempt.
  • Re-run assessments on a regular cadence and compare trends, not one-off scores.

Brought to you by NorthBridge

Unfamiliar term? Open the Digital Safety Glossary