The Google phishing quiz — built by Jigsaw, Google's technology incubator — is a free eight-question test that walks users through real phishing email examples and asks them to identify whether each one is legitimate or a phishing attempt. It has been taken by millions of people and remains one of the most widely shared free tools for building basic phishing awareness.
For NZ businesses, it is a useful starting point. It is not a training programme. This post covers what the phishing quiz actually tests, what the research says about quiz-based awareness, and what a programme that drives real behaviour change looks like.
---
What the Google Jigsaw Phishing Quiz Tests
The Jigsaw phishing test presents eight emails and asks users to classify each as legitimate or phishing. The scenarios cover spoofed sender addresses, urgent action requests, lookalike URLs, and credential harvesting pages. The answer explanations are clear and educational.
What it measures well:
- Awareness of common phishing indicators
- Ability to inspect URLs and sender addresses under test conditions
- Understanding of social engineering pressure tactics
What it does not measure:
- Behaviour under real-world time pressure
- Response to NZ-specific lures — IRD, NZ Post, myIR, local bank impersonation
- Whether staff will actually report a suspicious email rather than just delete it
- Improvement over time or knowledge retention
A staff member who scores 8/8 on the phishing quiz may still click a well-crafted IRD refund email three weeks later. Knowledge under test conditions and behaviour under real conditions are different things.
Other Phishing Quiz and Test Tools
Several platforms offer free or freemium phishing quiz and test tools:
- Google Jigsaw phishing quiz (phishingquiz.withgoogle.com) — the most widely known; eight scenarios, good explanations, no account required
- OpenPhish and similar feeds — used by security researchers, not end users
- Vendor-provided phishing tests — KnowBe4, Phished, and SecureAZ all offer sample phishing tests as part of their trial or free tier
- SANS Security Awareness — includes phishing awareness assessments in its commercial platform
The free tools are useful for self-service awareness. The simulation platforms — where your staff receive fake phishing emails in their actual inbox, under real conditions, without knowing it is a test — are what drive measurable behaviour change.
Why In-Inbox Simulation Beats a Quiz
The core difference between a phishing quiz and a phishing simulation is context. A quiz presents obvious choices in a deliberate educational setting. A simulation presents a convincing fake email in a busy inbox when the staff member is thinking about something else entirely.
The research is consistent: in-inbox simulations reduce click rates. Quizzes improve stated knowledge but have limited effect on actual click behaviour. The employee phishing test guide covers how to run simulations effectively.
NZ-Specific Lures the Global Quizzes Miss
The Jigsaw phishing quiz was built for a global audience. The scenarios use generic examples — a DocuSign alert, a Google Drive share, a password reset. These are real lure types, but they are not the campaigns CERT NZ sees targeting NZ businesses most often.
The highest-click lures for NZ staff in 2026:
- IRD tax refund and overdue payment notifications
- NZ Post parcel delivery failure messages
- myIR login credential prompts
- ANZ, ASB, BNZ, and Westpac security alert impersonation
- MBIE and government agency impersonation
- NZ Police infringement notice notifications
Staff who can identify a generic US-style phishing email often miss an IRD-themed one because the visual and contextual cues are more familiar. NZ-localised simulation templates are not a nice-to-have — they are the difference between a programme that measures real risk and one that measures performance on a generic quiz.
Using a Phishing Quiz as a Starting Point
The Jigsaw phishing quiz is a legitimate tool for:
- Initial awareness building before a training programme launches
- Self-service learning for individuals who want to test their knowledge
- A discussion starter in a team meeting or toolbox talk format
- Benchmarking general awareness before formal training begins
It is not a substitute for:
- Mandatory staff training with completion records
- Phishing simulations with in-inbox delivery and just-in-time follow-up
- Compliance documentation for an insurer or regulator
- Trend data showing improvement over time
Practical Steps
- Use the Google Jigsaw phishing quiz as an optional awareness starter, not a programme component
- Run an in-inbox phishing simulation to establish a real baseline click rate
- Use NZ-localised templates that reflect the actual campaigns your staff will receive
- Follow every simulation with immediate just-in-time training for those who clicked
- Run quarterly simulations and track click rate, submission rate, and report rate
- Use quiz results only as supplementary data — behaviour in the inbox is what matters
Start your free SecureAZ trial to move from phishing quizzes to in-inbox NZ-localised simulations with automated training and insurer-ready reporting.
External references: