Back to the glossary
    Human risk & behaviorCybersecurity glossary

    Phishing simulation

    A controlled phishing attack a company sends to its own employees to measure who falls, for which kind of lure, and how often.

    Full definition

    A phishing simulation is a controlled attack that an organization sends to its own employees to measure real behavior against deception: who clicks, who hands over credentials, who reports. It turns human risk into observable data instead of an assumption.

    The quality of the data depends on realism. A generic campaign identical for the whole company measures little; a simulation personalized by role, department, actual tools and previous behavior reproduces the conditions of modern spear phishing, which is the attack that matters. The lure category also counts: each template exploits a different instinct, such as authority, urgency or curiosity.

    A simulation is worth what it triggers afterwards: immediate microlearning for whoever falls, and a retest weeks later that verifies the change in behavior. Without that cycle, it is just a click metric.

    Related reading on the blogGo deeper into this topic

    Related terms

    From definition to data: measure your company's human risk

    Fensivo detects leaked credentials, simulates real attacks and validates with retests that behavior changed.