Tuesday, July 14, 2026
  • Subscribe
  • Advertise
  • Advertising Specifications
  • Editorial
  • Editorial Features
  • About Us
  • Contact
Data Centres Africa
  • Magazine Topics
  • Sectors
  • Magazine Issues
  • Editorial Features 2026
No Result
View All Result
  • Magazine Topics
  • Sectors
  • Magazine Issues
  • Editorial Features 2026
No Result
View All Result
Networking+
No Result
View All Result
Home Magazine

To Phish Sim or Not to Phish Sim: Why the Debate Needs to End

December 4, 2024
Reading Time: 2 mins read
To Phish Sim or Not to Phish Sim: Why the Debate Needs to End
Share on LinkedInShare on Twitter


I am still baffled by the continued use of phishing simulations, and even more so that we are still debating their value. If you are on the fence, let me explain why they do not work.

What is a phishing simulation?

A phishing simulation is a training exercise where employees receive fake phishing emails that mimic real attacks. The goal is to test their ability to recognise and report suspicious messages, helping to improve cybersecurity awareness and reduce the risk of falling victim to actual phishing scams.

The Results Are Flawed

Phishing simulations produce numbers, but those numbers are meaningless. You can manipulate the data to tell whatever story you want. Want to show progress over time? Start with an impossibly complex phishing email, then roll out progressively easier ones. The result will be a plummeting click rate that looks impressive on paper but says nothing about actual improvement.

Even worse, these exercises focus on negative metrics like click rates, which only tell us who failed. What about the people who did the right thing? Reporting and deleting phishing attempts are the behaviours we should encourage. Rewarding whistleblowers creates a culture where people feel confident to act. Penalising clickers only fosters resentment and fear.

In the real world, we want people to talk about scams and share their knowledge. Yet phishing simulations often discourage this, punishing employees for warning colleagues about a simulation. It is counterproductive and harmful.

The damage to culture

Cybersecurity teams already have to work hard to be seen as allies. Phishing simulations, which often “trick” employees, only worsen this perception. The result is predictable: less trust, less cooperation, and less willingness to follow cyber-safe practices.

In some unionised organisations, phishing simulations can even lead to disputes. Did you know that you often need union consultation before rolling one out?

The science behind the failure

Phishing simulations rely on pattern recognition, which primarily engages the occipital lobe, the part of the brain that processes visual information like shapes and patterns. While this can teach employees to spot phishing attempts, it does not help them develop deeper, transferable skills.

Anti-simulation training takes a different approach. It engages the prefrontal cortex, which handles abstract thinking, problem-solving, and planning. Instead of spotting phishing attempts, participants are asked to create them.

Why creating beats spotting

In our anti-simulation, employees step into the shoes of a cybercriminal. They are given phishing elements—like dodgy links, fake email attachments, and suspicious subject lines—and asked to craft the most convincing phishing email they can.

This challenges them to think critically and creatively. It helps them analyse the tactics used in real-world attacks, understand why they work, and internalise those lessons. Spotting relies on recognising existing patterns, while creating demands the synthesis of new ones. The result is a more engaging and rewarding experience, one that builds skills that actually stick.

A better way forward

Phishing simulations rely on outdated methods and reinforce negative behaviours. Anti-simulation turns the concept on its head. It is rewarding, engaging, and builds confidence and competence.

Related Posts

Former Chief of Joint Operations Sir David Capewell partners with Vodafone Business 
Magazine

Former Chief of Joint Operations Sir David Capewell partners with Vodafone Business 

May 20, 2026
High-profile filings prove world’s biggest stars will not wait for AI legislation
Magazine

High-profile filings prove world’s biggest stars will not wait for AI legislation

April 29, 2026
CableFree: 30 Years of Wireless Excellence and Innovation
Features

CableFree: 30 Years of Wireless Excellence and Innovation

April 21, 2026
How resilience keeps you in control, even when outages aren’t your fault
Magazine

How resilience keeps you in control, even when outages aren’t your fault

March 30, 2026

Subscribe

Get the latest networking news and insights delivered to your inbox.

SIGN UP

READ THE LATEST ISSUE

Networking+ is the premier independent resource for communications, network, IT, and data centre professionals. We provide an in-depth look at the rapidly evolving digital infrastructure landscape, covering everything from fixed and wireless LANs to complex enterprise WANs and MANs across both the public and private sectors.

By delivering breaking news, expert analysis, and strategic insights across our print publication, website, and e-newsletters, Networking+ offers a powerful, ‘one-stop’ media combination. Our multi-channel platform is dedicated to keeping industry decision-makers connected, informed, and equipped to future-proof their networks.

Follow Us

Content

  • Magazine
  • Sectors
  • Subscribe
  • Editorial
  • Advertise
  • About Us
  • Features List
  • Privacy Policy
  • Cookies Policy
  • Terms & Conditions

© 2026 Networking+ - A Denyan Media Ltd Publication.

No Result
View All Result
  • Magazine Topics
  • Sectors
  • Magazine Issues
  • Advertise
  • Advertising Specifications
  • Editorial
  • Editorial Features
  • About Us

© 2026 Networking+ - A Denyan Media Ltd Publication.

We use cookies to analyse site traffic and improve your experience with the latest data centre insights. By clicking 'I Agree', you consent to our use of cookies in accordance with our Privacy Policy.