Insights/Technical Deep-Dives
Phishing Simulations: What Your Click Rate Is (and Isn’t) Telling You
Published
Reading time2 minutes
FromTriad ICS Research

A single click-rate number hides more than it reveals. How to run simulations that actually reduce human risk.
Phishing simulations are one of the most common awareness activities, and one of the most commonly misread. Organisations run a campaign, report a click rate, and compare it with the next campaign. That number, on its own, says less than it appears to.
Why click rate misleads
- It depends heavily on the lure. A simulated salary revision email will be clicked far more than a generic delivery notice; changing the template changes the result.
- It rewards easy tests. Teams can improve the number by sending more obvious emails, without anyone becoming safer.
- It ignores what happens next. An employee who clicks and reports within two minutes has helped more than one who ignores the email entirely.
Better measures of human risk
- Report rate: the share of recipients who report the simulated phish.
- Time to first report: how quickly the organisation as a whole becomes aware of a campaign. In a real attack, this is what gives defenders time to act.
- Credential submission rate: the more serious failure, separate from a simple click.
- Repeat behaviour: whether the same people struggle across campaigns, so they can get more support.
Designing a fair simulation
- Vary difficulty deliberately and record it, so results can be compared honestly.
- Use themes relevant to India and to the role: GST notices, courier and UPI messages, vendor invoice changes, HR announcements.
- Never collect real passwords. Landing pages should record that a submission was attempted, not what was typed, which also keeps the exercise aligned with DPDP data-minimisation principles.
- Avoid lures that cause genuine distress, such as fake bonuses, layoffs or medical news. They damage trust more than they teach.
What happens after the click
The moment after a click is the best teaching opportunity. Show a short, friendly explanation of the signs that were missed. Do not shame or publicly name people. Offer extra support to those who repeatedly struggle, and remember that most successful attacks exploit processes, such as bank-detail changes by email, as much as people.
Connecting simulations to real defence
Make sure the report button that people use in simulations is the same one they use for real messages, and that real reports reach someone who acts on them. A simulation programme succeeds when a real phishing email is reported within minutes, and the security team has blocked it before most staff even see it.
This article is general information, not legal advice. Compliance services do not guarantee certification; certification bodies issue certificates.