phishing simulationsimulation realismsecurity awareness

    August 3, 2026 · 6 min read · By Fensivo Team

    What a phishing simulation measures once they recognize it

    Leer en español

    The bottom line: once your team recognizes the practice email, the simulation stops measuring judgment and starts measuring memory

    If your people spot the drill the moment they open it, the simulation is no longer measuring what you think it is. The most likely cause is that the template gives itself away: the same odd sender, the same clumsy wording, and it lands right after the annual training session. The person is not exercising judgment, they are recognizing a pattern ("here comes this month's trap email again") and hitting report out of habit, not because they paused under pressure. To confirm it, watch two signs: your click rate keeps dropping campaign after campaign while real incidents hold steady, or someone on the team jokes that "the test just arrived."

    What fixes this is not one more drill, it is making the simulation look like a real attack aimed at that specific person, and then validating the change with a retest, not with another identical email.

    The real trap almost always arrives by email. More than 90 percent of successful cyberattacks start with a phishing email, according to CISA, the United States cybersecurity agency, so the inbox is still where the test plays out. The problem is not measuring in email, it is measuring with an email that looks nothing like the one that will actually show up.

    Human risk is managed automatically.

    Turn human risk into your first line of defense.

    Book a demo

    Free demo · 30 minutes · No commitment

    Why your people recognize simulations: the generic template gives itself away

    An employee who has spent a year receiving the same kind of practice email learns the shape of the test, not the shape of the threat. And a generic template helps them learn it fast: it goes out identically to the whole company, it carries clumsy tells that a careful attack no longer makes, and it arrives on predictable dates. That is enough for the person to mentally file the message as "a drill" before reading it closely.

    The side effect is worse than no practice at all. The person does not come out trained to hesitate in front of a well-crafted email, they come out trained to spot your badly crafted one. Those are different skills, and the gap between them is exactly what gets billed on the day of the real attack.

    What a simulation the employee saw coming actually measures

    It measures recognition of the exercise, not judgment against a deception. When the click rate on a recognizable template collapses, the natural read is progress, but it is usually the opposite: it is the sign that the team memorized the style of the drill. That falling number creates a false sense of security in the board report, because it promises a resilience that does not exist outside the lab.

    The right question is not how many clicked the trap email. It is whether that person, on an ordinary busy day, with a full inbox and a message that presses a real instinct, would stop to verify. That is the behavior that matters, and a simulation that gives itself away never puts it to the test.

    Pattern recognition and judgment under pressure are not the same thing

    Recognizing a pattern is cheap: "this looks like last month's test." Exercising judgment under pressure is expensive: the person is busy, the message hits a nerve (an overdue invoice, an order from the boss, an account about to lock) and they still take the second to verify before acting. The first skill protects against nothing; the second is the one that prevents the breach.

    And the ground is getting harder, not easier. AI-driven phishing is now three times more effective than traditional campaigns, according to the Microsoft Digital Defense Report 2025, which means the real email arrives cleaner, more credible and harder to tell apart. A simulation the employee spots a mile away prepares them for a threat that barely looks like that anymore.

    What makes a simulation realistic: the person's real context

    A simulation stops giving itself away when it stops being generic, and it stops being generic when it is built from the context of whoever receives it: their role and department, the platforms their company actually uses, and their own credentials that have already turned up exposed in a breach. With those ingredients, the lure looks like the attack an adversary would craft for that particular person, not the mold that fits anyone.

    That is the difference between a practice email and a behavior test. Simulations that reproduce the trigger each person is most vulnerable to cannot be spotted by their clumsiness, because they have none; they force the person to exercise judgment, which is exactly what you want to measure. Cisco's 90-5-5 framework, which estimates that close to 90 percent of breaches involve a human factor, makes clear why measuring that behavior well is worth the effort: the risk surface sits in people, not in filters.

    Why a retest, not one more drill, proves behavior changed

    Even when the simulation is realistic and the person falls for it, a single data point still proves nothing. Someone failing, getting a training and passing it does not show they will hesitate next time. Resending the same email weeks later measures memory; testing the same category of attack again with a different template and context measures whether the lesson stuck. We call that a retest, and it is the only honest way to close the measurement.

    There is evidence behind this insistence. Peer-reviewed research (Ho et al., IEEE Symposium on Security and Privacy 2025; Lain et al., IEEE Symposium on Security and Privacy 2022) shows that completing a training does not by itself predict a reduction in real failures. What demonstrates change is exposing the person again to the same kind of deception and seeing whether this time they stop. A recognizable drill never even reaches that question; a serious program answers it again and again.

    At Fensivo we work on exactly that layer. Smart matching combines each person's role, their company's real stack and their already-leaked credentials so the simulation does not give itself away and truly measures judgment; whoever falls gets training specific to that attack within minutes; and weeks later a retest of the same category, with a different template, confirms whether behavior changed. That is the cycle that turns awareness into human risk management (HRM), and you can see how it works in our use cases.

    If you open your last simulation report tomorrow, is the click rate telling you that your team learned to defend itself, or only that it learned to recognize your practice email?

    Sources and references

    • CISA (Cybersecurity and Infrastructure Security Agency): more than 90 percent of successful cyberattacks start with a phishing email. https://www.cisa.gov/news-events/news/4-things-you-can-do-keep-yourself-cyber-safe
    • Cisco, The 90-5-5 Concept, 2025. https://blogs.cisco.com/security/the-90-5-5-concept-your-key-to-solving-human-risk-in-cybersecurity
    • Microsoft Digital Defense Report 2025. https://www.microsoft.com/en-us/security/security-insider/threat-landscape/microsoft-digital-defense-report-2025
    • Ho et al., Understanding the Efficacy of Phishing Training in Practice, IEEE Symposium on Security and Privacy 2025. https://sp2025.ieee-security.org/accepted-papers.html
    • Lain et al., Phishing in Organizations: Findings from a Large-Scale and Long-Term Study, IEEE Symposium on Security and Privacy 2022. https://www.ieee-security.org/TC/SP2022/program-papers.html

    Human risk is managed automatically.

    Turn human risk into your first line of defense.

    Book a demo

    Free demo · 30 minutes · No commitment