Phishing simulation services — sometimes called spear phishing simulation — help organizations reduce exposure to ransomware, data breaches, and account takeover, since a huge share of those incidents start with a single employee falling for a phishing email.
Why this matters now
The Identity Theft Resource Center documented nearly 450 million compromised records in 2018 alone — an all-time high at the time. Attackers use phishing to install malware or harvest credentials, and sometimes target email credentials specifically to launch internal spear-phishing campaigns from an already-trusted address. The fallout increasingly goes beyond stolen data, into stolen intellectual property held for ransom — often more damaging than a conventional breach.
How the training actually works
Employees get tested with realistic simulated phishing campaigns. Anyone who fails gets targeted education on what to look for and additional training. Running this continuously — not as a one-time event — is what actually conditions people to scrutinize emails critically as a habit. As of 2018, 88% of Fortune 500 companies were already using services like this.
What to evaluate
- How closely emails can be customized to mimic your own organization
- How much setup and result-management effort falls on your team
- Variety of attack types tested — link clicks vs. attachment downloads
- Reporting on pass/fail metrics
- What happens automatically when an employee fails
- Whether training is bundled in, or a separate purchase