Ask any business owner whether their team would click a phishing email and you will get the same answer: "most of them would spot it." Ask them how they know, and the room goes quiet. There is exactly one safe way to turn that guess into a number, and it is a phishing simulation: a realistic fake, sent by you (or your provider), that measures what a real attacker would have harvested — without the harvest.
This week is Cyber Smart Week, themed "find a scam before it finds you." A simulation is that sentence turned into a procedure.
What a simulation actually measures
A proper campaign gives you four numbers, and each one teaches something different:
- Open rate — mostly noise on its own, but a baseline for the rest
- Click rate — the headline number: who followed the link. Across industries, first-campaign click rates typically land between 20% and 35%. Whatever yours is, it is almost certainly higher than the guess you just made
- Credential submission rate — the number that matters most: who typed a password into the fake page. This is the "an attacker is now inside Microsoft 365" number
- Report rate — the one to grow: who recognised the fake and told someone. A rising report rate is the single best signal your culture is working, because reporters protect everyone, not just themselves
Run quarterly, these four numbers become a trend line — and a falling click rate across campaigns is the most honest evidence of training ROI that exists in security. It is the exact chart we show in our comparison of phishing simulation platforms.
What separates a useful simulation from a stunt
The difference between a programme that improves behaviour and one that breeds resentment is design, not software:
Realistic, local lures. A fake that mimics what NZ and Australian staff actually receive — courier notices, Microsoft 365 alerts, supplier invoices, IRD-season refunds — tests the real skill. Generic American templates test nothing.
Training at the moment of the click, not punishment after it. Whoever clicks should land on a short, calm "here is what you missed" module within seconds — the teachable moment. Naming, shaming or disciplining clickers is the fastest way to destroy the report rate, and the report rate is the asset. The psychology is the same one we describe in building phishing training that employees do not hate.
Everyone gets tested, including the C-suite. Senior staff are the highest-value targets and, campaign after campaign, among the most frequent clickers. Exempting them tells the team this is theatre.
Frequency over intensity. One ambush a year measures nothing and annoys everyone. Light quarterly campaigns build the checking reflex without fatigue.
"Is this a trick on my own staff?"
It is the objection every owner raises, so here is the honest answer: the trick already exists, and your team is already being tested — by people who keep the results. In the real test, a click costs you invoice fraud, a mailbox takeover, or the ransomware timeline we walk through in the first 24 hours. In the simulation, a click costs ninety seconds of training. You are not choosing whether your team gets tested; you are choosing who holds the scoreboard.
Run it with the right framing — announced policy ("we simulate, because everyone gets fooled eventually, including management"), blame-free, trend-focused — and teams end up competitive about their report rate rather than nervous about clicking.
What this looks like in SecureAZ
We built the simulation workflow to be an SMB-sized job, not a security-team project: pick from NZ/AU-localised templates, schedule the campaign, and the platform measures opens, clicks and credential submissions, auto-enrols anyone who clicks into a short remedial module, and gives you the before/after chart for the board, your insurer or your auditor.
The 45-day free trial is deliberately long enough to do this properly: train your team in week one, run a full simulation cycle, and see your click rate with your own eyes — up to 5 users, no credit card, NZ-built. Find out who would actually click — before someone less friendly does.