Skip to main content
Meridian Grove IT
Cyber Security

Phishing simulation training that builds awareness, not resentment

Tom Fairweather · 9 March 2026 · 5 min read

Phishing simulation training has a reputation problem, largely earned. Run badly, it looks like IT setting traps for staff and then publicly announcing who fell for them. Run well, it's one of the most effective, and best-received, security controls a business can put in place.

What tends to go wrong

The most common mistake is treating results as a leaderboard of who clicked what. Naming individuals in team-wide communications, even with good intentions, teaches people to associate security training with public embarrassment, which makes them less likely to report a genuine suspicious email later for fear of the same exposure.

The second common mistake is running simulations that are either too easy to be useful or so sophisticated that they don't reflect anything staff would realistically encounter, teaching the wrong lesson either way.

What we do differently

Results are reported in aggregate to leadership, with individual follow-up handled privately and framed as a two-minute coaching conversation, not a disciplinary one. The goal is building the instinct to pause and check, not catching people out.

Simulations are also varied deliberately, some mimicking obvious mass-market phishing, others reflecting more targeted approaches relevant to the specific business, invoice fraud attempts for finance teams, credential harvesting pages that mimic tools the business actually uses, so training reflects real risk rather than a generic template.

The metric that actually matters

Click rate on simulations is useful, but the metric we track most closely is reporting rate: the percentage of suspicious emails, simulated or real, that get forwarded to IT rather than ignored, deleted, or worse, acted on. A team that reports suspicious emails confidently, even when they turn out to be false alarms, is a far stronger security control than a team that simply stops clicking a specific template of phishing email.

That shift, from fear of being caught to confidence in reporting, is the actual goal of a well-run programme, and it's achievable within a handful of quarterly training cycles for most teams.

Get one useful email a month

Security and infrastructure guidance, no sales fluff.