An employee phishing test — also called a simulated phishing attack or phishing simulation — sends a fake phishing email to your staff to see who clicks, who submits credentials, and who reports it. Done well, it is the most effective way to identify who needs training and to drive measurable behaviour change. Done badly, it creates distrust and teaches nothing.
CERT NZ recommends simulated phishing as part of a layered security awareness programme, and NZ cyber insurers are increasingly asking whether organisations run them. This post covers how to run an employee phishing test that actually works.
---
What a Phishing Test Measures
A well-designed phishing simulation tracks three things:
- Click rate — the percentage of staff who clicked the link in the phishing email
- Credential submission rate — the percentage who entered a username or password on the fake landing page
- Report rate — the percentage who forwarded the email to IT or used a report button
Click rate alone is a limited metric. The report rate is the one that signals a healthy security culture — a team that actively flags suspicious emails is more valuable than one that just avoids clicking them.
Test Design Principles
Match the threat to your context. Generic "Nigerian prince" templates teach nothing. Use scenarios that look like the real attacks your industry faces. For NZ businesses, the high-value templates are IRD refund notifications, NZ Post parcel delivery failures, Microsoft 365 password expiry alerts, DocuSign document requests, and myIR credential prompts. These are the lures CERT NZ sees most often in the wild.
Vary difficulty across the programme. The first test in a new programme should be moderately obvious — this sets a baseline without humiliating people. Later tests should use targeted spear phishing scenarios that use the recipient's real name, manager's name, or reference a current business project.
Run tests at intervals, not once. A single phishing test is a snapshot. Quarterly simulations with tracked improvement over time is the programme. Behaviour change requires repetition.
Do not announce the test in advance. Pre-announcing defeats the purpose. Staff know to be careful that week and revert to old habits the week after.
What to Do When Someone Clicks
This is where most programmes fail. The user clicks, gets a message saying "this was a test", and the learning stops. What works instead:
- Immediate just-in-time training — a short module (3-5 minutes) that explains what cues the phishing email contained and how to spot the next one
- No public shaming — results are shared at aggregate level with management, not names to the whole company
- Follow-up within 48 hours — a brief refresher or team discussion while the experience is fresh
- Personal coaching for repeat clickers — someone who clicks on three consecutive tests needs one-on-one support, not another module
The email phishing test is a diagnostic tool, not a punishment mechanism. Framing matters.
The Report Button
The report rate is the underinvested metric. Every email client should have a one-click "Report Phishing" button that sends the email to IT. This serves two purposes:
- It gives employees a clear action when unsure, instead of leaving them to guess
- It feeds a real-time threat reporting pipeline — when five people report the same external email, IT knows a live campaign is running against the organisation
Microsoft Defender, Google Workspace, and most email security tools support a report phishing button. If yours does not have one, adding it is the highest-return 30 minutes you will spend on your awareness programme.
Compliance and Insurer Requirements
NZ cyber insurers are now including phishing simulation questions in their renewal questionnaires. Common asks:
- Do you run simulated phishing tests? How often?
- What is your current click rate?
- What training follows a failed test?
- Do you track improvement over time?
Having documented answers — backed by test records and trend data — puts you in a stronger position at renewal and can affect your premium. The overlap between insurer requirements and NCSC guidance on security awareness training is intentional.
What Good Looks Like After 12 Months
An organisation that runs a consistent phishing simulation programme for 12 months typically sees:
- Click rate drop from 20-30% at baseline to under 5%
- Report rate increase from near-zero to 20-40%
- Incident reports from staff identifying real phishing campaigns — the ultimate return on the programme
The click rate improvement is the easy metric. The culture shift — where staff treat suspicious emails as something to act on rather than ignore — is the real outcome.
Practical Steps
- Choose a phishing simulation tool with NZ-localised templates
- Run a baseline test with moderate difficulty before any training
- Set a quarterly simulation schedule with escalating difficulty
- Wire up a report phishing button in your email client
- Build immediate just-in-time training into the simulation workflow
- Track click rate, submission rate, and report rate over time
- Share aggregate results with management monthly, not just at incident
Start your free SecureAZ trial to run NZ-localised phishing tests with automated just-in-time training, click rate tracking, and insurer-ready reporting.
External references: