Phishing simulation
A controlled phishing attack a company sends to its own employees to measure who falls, for which kind of lure, and how often.
Full definition
A phishing simulation is a controlled attack that an organization sends to its own employees to measure real behavior against deception: who clicks, who hands over credentials, who reports. It turns human risk into observable data instead of an assumption.
The quality of the data depends on realism. A generic campaign identical for the whole company measures little; a simulation personalized by role, department, actual tools and previous behavior reproduces the conditions of modern spear phishing, which is the attack that matters. The lure category also counts: each template exploits a different instinct, such as authority, urgency or curiosity.
A simulation is worth what it triggers afterwards: immediate microlearning for whoever falls, and a retest weeks later that verifies the change in behavior. Without that cycle, it is just a click metric.
Related terms
Phishing
An attack that impersonates a trusted sender, such as a bank, a colleague or a vendor, to steal credentials, data or money, or install malware.
Retest
A new simulation of the same attack category, weeks after a failure and with a different template, to verify the person actually changed their behavior.
Click rate
The percentage of people who click a phishing simulation. Useful as a signal, misleading as the only metric of a program.
Report rate
The percentage of people who report a simulation or a real attack. It is the best early indicator of a security culture that works.
From definition to data: measure your company's human risk
Fensivo detects leaked credentials, simulates real attacks and validates with retests that behavior changed.