The great phishing simulation debate: Are both sides missing the point?
The debate about phishing simulations has been running for years, getting louder, and going nowhere.
Researchers publish studies. Practitioners push back with results.
Both cite evidence. Both dig in. And the argument circles, because nobody has stopped to ask whether they’re actually measuring the same thing. They are not.
The case against, and it’s a good one.
Multiple studies have found that phishing simulations alone, or paired with generic, one-size-fits-all, bolted-on training, don’t work.
In some cases, they even found they can leave employees more susceptible over time, reduce willingness to engage with the program at all, and push them toward silence for fear of reprimand.
The picture these studies paint is consistent.
When an employee clicks and the only thing that follows is a shame screen, they learn one thing: don’t get caught next time. Not here’s what to look for. Not here’s why your brain responded to that urgency cue. Just surveillance, a bruised ego, and a growing instinct to delete anything that looks like a test rather than report it.
This approach is not a real security program. It is more like a trap that ends with making employees feel ashamed.

So why do some organizations swear by them?
It is normally because they are doing something different than just running simulations, and their results show it.
The organizations showing sustained reductions in click rates aren’t just sending fake phishing emails and waiting. When an employee clicks, they see an immediate, specific breakdown of exactly what they missed: the sender address they didn’t scrutinize, the urgency language engineered to short-circuit their thinking, the domain that was almost right but not quite. The click becomes a teaching moment rather than a verdict.
And crucially, that moment doesn’t stand alone. It feeds into training that practices the actual skill. Not a compliance video, not a generic e-learning module, but real scenarios that build the cognitive habit of pausing, evaluating, and deciding.
Over time, employees don’t just know what phishing looks like; they also know how to spot it. They get better at catching it under pressure, in the moment, when it counts.
That’s a different program entirely. It just happens to start with the same mechanism.
Here’s what the argument has been missing all along.
Both sides have a point.
Researchers who say simulations do not work are looking at organizations that treat a click as the end of the process – a verdict, a statistic, or just a compliance step.
Practitioners who see success use the click as a starting point – a signal, a way to diagnose, and the first step in helping people learn.
They are not really disagreeing. They are talking about two very different things that happen to share the same name.
A phishing simulation on its own is just a test. Tests do not change behavior, but learning does. The value of a simulation depends on what it shows and what happens next. Show employees what they missed, explain why and offer personalized training that helps them build decision-making skills, not just awareness. They treat a click as useful information, not as a mistake to punish.
In the same way that a great pit stop is a terrible destination, organizations who treat the simulation as the whole journey will keep arriving at the same debate year after year: the same argument, the same studies, the same results.
Organizations that treat it as the starting point already know how this ends. The gotcha model is dead. The simulation, built into a real learning journey, is just getting started.
This article was written by Cywareness, a company specializing in cybersecurity awareness.
As part of its mission, Cywareness continues to monitor emerging trends, analyze real-world attacks, and share practical insights to help organizations stay ahead in today’s evolving threat landscape.