Join our Newsletter — 33% off our NHI Course

Why does simulated phishing usually produce better insight than posters or newsletters when measuring employee susceptibility?

Simulated phishing creates observable behaviour, so teams can measure who clicks, who reports, and whether susceptibility declines after training. Passive materials mainly raise awareness, but they do not reliably show changed behaviour. That makes simulations more useful for baseline assessment, trend analysis, and proving whether awareness efforts are reducing real-world exposure to phishing attacks.

Why simulation gives you a truer measurement

Simulated phishing is stronger because it produces a measurable action, not just a message exposure. Posters and newsletters can help with awareness, but they mostly test recall or familiarity. A simulation lets you observe a decision in context, which makes it much better for establishing a baseline, comparing groups, and checking whether training changes behaviour rather than just recognition.

That difference matters because susceptibility is a behaviour problem as much as an awareness problem. If someone sees a poster about phishing, you only know they may have noticed the warning. If they are presented with a realistic lure, you can see whether they click, submit credentials, ignore the message, or report it. Those outcomes are directly comparable across time and across teams.

Simulations are also more useful when you need evidence of change. A campaign can show whether click rates fall, reporting rates improve, or risky responses decline after awareness work. That makes the result actionable for security and privacy controls, because the programme can be judged on observed behaviour instead of campaign attendance.

What posters and newsletters can tell you, and what they miss

Passive materials are still useful, but they answer a different question. They can reinforce policy, keep phishing top of mind, and support a broader awareness programme. What they do not do well is separate genuine understanding from passive exposure. Someone may remember the message and still fail under pressure, because the real test is whether they recognise and resist a live lure.

That is why passive content is weak as a measurement tool. A newsletter may be read, skimmed, or ignored, and a poster may be visible without changing behaviour. Even good messaging has limited diagnostic value unless it is paired with an observable exercise. In practice, awareness content works best as a support layer around a measurement method such as simulation, not as the measurement method itself.

For organisations that want phishing-resistant measurement, the control point is not “did the message go out?”, but “did the recipient behave more safely when it mattered?”. The distinction is important for phishing-resistant authentication guidance, because good awareness and better authentication reduce risk in different ways. One changes human judgement, the other reduces the damage a phish can cause.

How to interpret the results without overreading them

Simulation results are only useful when they are measured consistently. A click rate, report rate, and credential submission rate mean more when the lure type, audience, timing, and scoring method stay stable enough to compare over time. If you change too many variables at once, the trend becomes harder to trust.

You should also read the results as exposure indicators, not as a full security verdict. A low click rate can still hide weak judgement if the lure was unrealistic. A high report rate may reflect strong instinct, but it does not guarantee resilience against more convincing attacks. The best programmes use simulations to identify where susceptibility is concentrated, then use that evidence to target coaching, process changes, or authentication hardening.

Simulation data becomes even more useful when combined with actual incident or near-miss observations. If a team repeatedly fails a style of lure that mirrors real attacker tradecraft, that is a signal to adjust the awareness strategy and the technical controls together, rather than treating training as a standalone fix. The same logic is reflected in MITRE ATT&CK Enterprise, where behaviour and technique mapping help teams understand how phishing fits into a broader attack path.

Risk and Threat Considerations

Simulated phishing is not just a training exercise, it is a visibility mechanism for one of the most common human attack paths. The risk is that organisations rely on awareness materials that measure sentiment or exposure, while attackers exploit the gap between knowing about phishing and resisting a convincing message under pressure.

Failure mechanism: Passive materials can create a false sense of readiness because they do not force a real-time decision. Simulation closes that gap by revealing who is likely to click, who escalates, and whether unsafe behaviour persists even after awareness efforts.

Impact: Teams get a defensible baseline for susceptibility, can track whether risk is improving or stagnating, and can identify populations that need stronger controls or more targeted intervention before a real phish succeeds.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK addresses the attack and risk surface, while NIST SP 800-53 Rev 5, NIST SP 800-63 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
NIST SP 800-53 Rev 5 AU-6 — Audit Review, Analysis, and Reporting Phishing simulations produce measurable behavioural evidence that supports control review.
IA-5 — Authenticator Management The question concerns susceptibility to phishing of credentials and authentication behaviour.
IA-2 — Identification and Authentication (Organizational Users) Employee phishing susceptibility directly affects organizational user authentication risk.
Recommendation — Review simulation outcomes to identify weak points and track improvement over time. Use simulation results to harden credential handling and rotation practices. Strengthen user authentication controls where simulations show repeated unsafe responses.
NIST SP 800-63 Phishing-Resistant Authentication The topic contrasts awareness with measuring real-world phishing resistance.
Recommendation — Adopt phishing-resistant authenticators where simulation shows exposure remains high.
MITRE ATT&CK T1566 — Phishing Simulated phishing measures exposure to the same adversary technique used in real attacks.
Recommendation — Map failed simulations to phishing techniques and target the weak response patterns.
CIS Controls v8 CIS-14 — Security Awareness and Skills Training The page explains why simulations measure training effectiveness better than passive awareness.
Recommendation — Use simulations as the measurement layer for awareness training effectiveness.

Practitioner Guidance

What to prioritise: Measure the behaviours that matter most to your risk model, usually click, credential entry, and report rate. If reporting is the desired outcome, weight it explicitly so teams do not optimise only for “not clicking.”

What to verify: Make sure the simulation method is stable enough to compare over time. If the lure complexity, audience, or scoring changes every cycle, you are measuring campaign variation more than susceptibility.

Common mistake: Treating awareness attendance as evidence of reduced exposure. Training completion is an input; only observed behaviour shows whether the control is working.

Practitioner takeaway: Use posters and newsletters to support awareness, but use simulation to measure whether people actually behave more safely when confronted with a believable phish.