Phishing simulation works. Done carelessly it also teaches your staff that the security team is something to be avoided, which costs you the thing that actually matters during a real incident: someone telling you quickly.
The goal is reporting, not a low click rate
A business where nobody clicks but nobody reports is more dangerous than one where a few people click and everyone reports within minutes. Real attacks are not stopped by perfect staff. They are contained by fast reporting, and that is a behaviour you either encourage or suppress.
Lures we will not use
- Salary changes, bonuses or payroll problems
- Redundancy, restructuring or anything implying job insecurity
- Health, family emergencies or bereavement
- Anything impersonating a named colleague in a way that damages that person's standing
- Visa, residency or immigration status, which in the UAE context is needlessly cruel
The argument for cruel lures is that real attackers use them. True, and irrelevant. The purpose of a simulation is to build a habit, not to prove people can be manipulated when distressed. You will get the same learning from a well-built invoice lure without the damage.
The HR test
If a simulation would upset someone enough to complain to HR, it is the wrong simulation regardless of how realistic it is.
Rules we agree before sending anything
- 1Difficulty starts moderate and escalates, rather than opening with something almost nobody would catch
- 2Results reported as team and organisation trends, never as a leaderboard of named individuals
- 3Anyone who clicks gets immediate, short, blame-free coaching showing the specific tells
- 4Anyone who reports gets acknowledged, including when the message turned out to be genuine
- 5Management agrees in advance that results will not be used in performance reviews
- 6Staff are told the programme exists, even if not when each test will arrive
The reporting button matters more than the training
Make reporting a suspicious email a single click in Outlook or Gmail. If reporting requires forwarding to an address nobody remembers, people will not do it. The easier reporting is, the faster your real incidents get contained, and that is the entire return on this programme.
What good looks like after a year
| Metric | Weak programme | Working programme |
|---|---|---|
| Report rate | Low and flat | Rising quarter on quarter |
| Time to first report | Hours or never | Minutes |
| Repeat clickers | Same names, unaddressed | Small, shrinking, supported |
| Staff attitude | Sees IT as a trap | Reports genuine mail without fear of looking foolish |
| False reports | Discouraged | Welcomed, because over-reporting is the safe failure |
Setting up an awareness programme?
We run simulation programmes with the rules agreed with management up front, and report on the numbers that predict whether a real attack gets contained.
Frequently asked questions
Is phishing simulation fair to employees?
It can be, and it depends entirely on how it is run. Avoiding cruel lures, reporting trends rather than naming individuals, and coaching without blame make it feel like practice. Publishing a leaderboard of who clicked makes it feel like a trap, and people respond accordingly.
Should we name people who click?
No. Naming individuals produces staff who conceal mistakes, which is precisely what you cannot afford during a real incident. Report by team and by trend. If a specific person is repeatedly caught, support them privately rather than exposing them.
How often should we run simulations?
Frequently enough to build a habit and not so often that people become suspicious of all internal mail. Quarterly is a common rhythm, adjusted once you see how your teams respond. Short reinforcement training between simulations matters more than the frequency of the tests.
What if staff complain about being tested?
Usually that signals a problem with the lure or the communication rather than with testing itself. Tell staff the programme exists before it starts, avoid emotionally exploitative lures, and make sure the follow-up is coaching rather than criticism.
Do we tell staff when a test is coming?
Tell them the programme exists, not the timing of individual tests. Announcing each test defeats the purpose. Announcing the programme builds consent, and it is the difference between staff treating it as practice and treating it as entrapment.
Usman K.
· IT Support LeadIT support lead at Azizi Technologies. Manages 24/7 helpdesk, Microsoft 365 migrations, server administration, and managed IT contracts for Dubai SMBs. Microsoft Certified. Mentioned by name in client reviews for fast resolution.
Need a quote for Security Awareness Training Dubai?
WhatsApp this article plus your device or site. We reply with next steps and a written quote.