The short answer
Phishing simulation best practices focus on learning over punishment: calibrate cadence to avoid fatigue, use realistic but ethical lures, deliver instant, educational feedback, and track reporting rate and time-to-report, not just clicks. Integrate simulations with micro-training and culture programs so employees feel like partners, not targets.
What is a phishing simulation?
A phishing simulation is a controlled, attacker-style exercise across email (and increasingly SMS, voice, or QR) that tests and teaches secure behavior. Strong programs pair every lure with a learning loop: immediate feedback, a concise explainer, and a 1-minute micro-lesson.
Looking to compare vendors? You can read our phishing simulation tool comparison guide here.
Core elements (and why they matter)
Design best practices (cadence, fatigue, comms)
What’s the right cadence? Who should receive what, and when? What happens when it becomes too much or too boring? Planning is the key here.
Phishing Simulation Cadence Planner
| Audience and trigger | Starting cadence | Why it works | When to adjust |
|---|---|---|---|
| Company-wide baseline | Monthly or quarterly | Reinforces recognition without alert fatigue; keeps habits alive between real incidents. | If engagement dips, refresh themes and personalize before adding volume. |
| High-risk roles (finance, IT, executive support) | Every 1-4 weeks (short micro-drills) | Higher exposure justifies a tighter repetition cycle; the micro-format minimizes disruption. | Tune by reporting rate and time-to-report; reduce if you see a spike in false positives or workload. |
| New hires or returners | Warm “welcome” benchmark (after initial training), then 30/60/90-day touchpoints | Builds trust early and avoids cold “gotchas”; adaptive difficulty prevents overwhelm. | Delay or soften during intense onboarding windows or feedback-flagged stress. |
| Repeat clickers | Weekly micro-sims and individual coaching | Practice helps, but change sticks with supportive, one-on-one guidance rather than punishment. | As the cohort shrinks, taper to monthly; escalate to manager check-ins only if patterns persist. |
| After incidents or new attack patterns | Focused follow-up drills in the next cycle | Converts lessons learned into muscle memory, and mirrors real threats like QR code scams, MFA-fatigue attacks, and vishing calls. | Don’t stack too many vectors at once; prioritize relevance over volume. |
| Sensitive periods (layoffs, restructures, crises) | Pause or soften campaign | Protects psychological safety and trust; avoids backlash from “cruel realism.” | Resume with transparent comms and gentle difficulty ramp. |
Tuning rules that prevent fatigue
- Start with a monthly baseline. Run company-wide simulations monthly or quarterly to start.
- Layer in risk-based drills. Add tighter, shorter micro-drills for high-exposure roles like finance, IT, and new hires, on top of that baseline.
- Measure to manage. Optimize cadence with reporting rate and time-to-report; click rate alone plateaus and can harm psychological safety.
- Refresh > repeat. If engagement stalls, change themes and personalize; cadence issues often mask repetition fatigue, not “too many emails.”
- Protect trust windows. During layoffs, restructures, or tense periods, pause or soften campaigns to avoid backlash and keep safety intact.
- Expect (and interpret) spikes. A short-term surge in reporting can be a good sign; calibrate rather than overcorrect.
- Avoid automated misfires. Security tools can “auto-click” links and enroll everyone in remedials; verify logs and workflows before big sends.
- Start easy, scale smart. Open with a “welcome” benchmark and let difficulty adapt per user so no one feels tricked or bored.

How do you create psychological safety?
Psychological safety means treating mistakes as part of the learning process, not something to punish. When someone reports a suspicious email, or admits to clicking one, how you respond in that moment decides whether they’ll get it right next time. Here’s how:
Design moves that increase safety
Psychological Safety: Dos & Don’ts
Build a culture where people report fast. That protects the org more than chasing zero clicks.
| Do | Don’t |
|---|---|
Tell people that reporting a suspicious message is the goal. | Don’t over-index on click rate It never hits zero, so optimize for reporting and time-to-report instead. |
Stars, streaks, and shout-outs keep engagement high. | Don’t punish or shame Fear reduces reporting and slows real incident response. |
Close the loop the moment someone reports, and tell them what’s phishy and why. | Don’t assign hour-long remedials Use short, contextual micro-lessons instead. |
Open with a welcoming first simulation, then ramp difficulty per person. | Don’t run cold “gotchas” Skip surprise tests for new hires or during sensitive periods. |
Match your tone to their role, and skip the lecture. | Don’t lecture people as if they were students Speaking down to adults breeds resentment instead of trust. |
One obvious “Report phish” button is all you need. | Don’t make people hunt through menus If reporting takes more than one click, people will give up and just delete the email instead. |
Understand their role and workload, then set small, specific goals for them, based on their own mistakes. | Don’t treat every clicker the same A one-size drill misses why someone keeps failing. |
If someone slips on a real phish, reporting fast is still the right move. | Don’t leave amnesty unspoken If people aren’t sure they’ll be safe reporting a slip, they won’t. |
Pause or soften campaigns during layoffs, crises, or peak deadlines. | Don’t use creepy lures Skip highly personal or panic topics like medical results, layoffs, or finances. |
Some email security tools click links automatically before a person ever opens the message. That can register as a false “fail,” so check for it before you count anyone as having clicked.
What makes a simulation realistic and ethical?
A realistic simulation mirrors what attackers are actually doing right now, and that bar keeps moving: AI-generated phishing surged roughly 14× at the end of 2025, climbing from under 5% to 56% of detected attacks in a single month (Hoxhunt Phishing Trends Report 2026), so a simulation built on last year’s templates is already behind. Ethical is the other half: realism only earns its place when it never tips into fear, harm, or entrapment.
Reality that teaches (not tricks)
- Role-aligned pretexts. Choose scenarios people actually face, like an IT reset, finance urgency, or executive impersonation. These are the most common, and most effective, real-world hooks.
- Multi-channel where relevant. Modern attacks chain email and phone. Simulate vishing and deepfake voice carefully to build recognition without going too far.
- Match the end goal. If the pretext is a payment request, the fail is acting on it, not clicking. Design the path to match how attacks actually happen.
Ethical guardrails (program-level)
- Real but responsible. Don’t recreate the worst incidents or let simulations drag on. Respect people’s time, and stop before it starts to feel like a setup.
- Avoid “cruel realism.” If a scenario would genuinely upset someone in real life, it doesn’t belong in a simulation. Keep topics professional and relevant instead.
- Be transparent and legal. Announce that periodic tests occur, and check regional limits, since SMS or phone spoofing can cross telecom lines. Coordinate with Legal and HR on consent and data-handling expectations.
Design details that keep trust
- Use familiar context safely. Reference tools, logos, and workflows employees already use, but avoid exploiting sensitive inside information.
- Keep it short. If the pretext is something like a fake sales lead, cut the interaction short before someone wastes real time chasing it.
- Teach caller-ID skepticism. Attackers can spoof a number to look like an internal extension, which makes people trust the call more than they should. Teach them to hang up and call back on a number they already trust instead.
Rule of thumb: you don’t train soldiers in real firefights. Make it realistic enough to teach, and safe enough that no one gets hurt.
Which scenarios should you prioritize in 2026?
Prioritize simulations that mirror today’s phishing attacks: business email compromise (BEC), credential harvesters with realistic landing pages, QR “quishing,” MFA-fatigue, SMS phishing, and voice phishing (vishing), often chained in multi-channel pretexts. Match the fail action to the story (click, open attachment, act on a request).
Top scenarios to cover (with design notes)
- Business Email Compromise (invoice fraud, payroll diversion): Move it from email to voice calls or a chat follow-up. The fail is acting (e.g., paying a bogus invoice), not clicking. Teach verify-and-call-back procedures.
- Credential-harvesters (cloud or app logins): Use a landing page tied to the pretext, and a short microlearning module after failure. Measure credential-submission rate and time-to-report.
- QR “quishing”: Whitelist scanners to avoid false “auto-clicks” from integrated cloud email security. Track reporting, not just clicks.
- MFA-fatigue: Simulate rapid MFA prompts (bombarding someone with login approval requests until they tap “yes” out of frustration) and teach “deny and report” behavior. Keep the exercise short to protect morale.
- SMS phishing (smishing): Use delivery, bank, or account-update pretexts that lead to a mobile phishing site. Verify regional rules before running SMS tests.
- Voice phishing (vishing) and deepfake calls: Model the email-to-spoofed-call chain attackers actually use. Use this responsibly: keep it brief, and debrief fast.
- Attachment-based lures (malicious emails): Match it to the story (e.g., an “Updated HR policy” email), so the fail is opening the attachment, not clicking a link. Follow up with an “Oops!” landing page.
Build each scenario so it feels real (but responsible)
- Match channel and fail method to the story. Every scenario above follows the same rule: the fail should match how the attack actually plays out, not just what’s easy to click.
- Use multi-channel pretexts sparingly. Chaining channels builds recognition, but overdoing it overwhelms people.
- Keep lures professional. The goal is to teach, not to spring a “gotcha” moment.
- Use current templates and tools. Rotate phishing templates (including QR and AI-crafted lures). Many programs supplement with phishing simulation software like Microsoft Defender Attack Simulator or Hoxhunt, just whitelist scanners first.
Below, explore an interactive tour of what Hoxhunt’s phishing simulations look like for users.
How do you choose the “fail method” and design the landing page?
The fail method is whichever action counts as getting caught: a click, an attachment, or something bigger, matched to what the real attack would need.
Match the fail method to the attacker’s real objective, not whatever’s easiest to build. Close the loop instantly: a short explanation of what gave it away, plus a quick lesson.
Decision rule (works across channels)
Real attacks have “something after the click.” Make your victim flow coherent and educational, then close with a concise “Oops, that was a phish” page and a micro-lesson.
Fail Method & Landing Page Matrix
| Objective (social engineering) | Natural fail method | What your landing page teaches | Notes and security tools |
|---|---|---|---|
| Credential compromise attacks (account warning, SSO reset) | Enter credentials on a spoofed phish landing page | 3 cues (URL, sender, urgency), safe next steps, and where the “Report phish” button lives | Rotate phishing templates, and keep them up to date |
| Business email compromise (invoice fraud, payroll diversion) | Act on the request (approve payment or change IBAN) | Verified callback and dual-approval habit; how to escalate quickly | The fail is acting on the request (e.g., approving the payment), not just clicking the email |
| Attachment lures (policy update, delivery note) | Open a phishing attachment (PDF or Doc) | How to spot risky attachments (hidden macros, disguised extensions like .pdf.exe), preview safely, and know when to report | Use when the story fits; don’t overuse attachments |
| QR-triggered mobile drive-by (“quishing”) | Scan the code and land on a mobile phishing website | How to check a URL is real, even on a small screen, how to spot a fake app posing as a real one in the app store, and how to report from a phone | Whitelist link-scanners to prevent false “auto-click” fails |
| MFA-fatigue (push bombing) | Approve repeated prompts | Deny-and-report behavior; device hygiene basics | Cap how many prompts you send. Too many can trip real account-lockout policies |
| Vishing or hybrid (email and spoofed voice call) | Comply on the phone (share information or approve action) | Caller-ID skepticism; verified callback script; short debrief | Run these rarely, since a spoofed call feels more invasive than an email; debrief right away so it’s clear it was a test |
Landing-page & micro-lesson checklist
- Immediate feedback, not scolding. A short explainer plus a one-minute microlearning module, then back to work.
- Actionable next steps. “Report it, then delete,” and show where the Report Phishing button lives in the Outlook toolbar.
- Positive reinforcement notifications. A quick thank-you or progress update keeps people motivated.
- Measure whether it’s working. If someone repeats the same mistake, the landing page or micro-lesson isn’t working; revise it.
How do you tailor phishing simulations to your business?
Tailoring means mapping the attack surface to your actual roles and regions, not running the same scenario for everyone. Personalize the difficulty and the language, then wire the results into the security tools you already have.
Map attack surface → role-based scenarios
- Finance: BEC, vendor IBAN changes, invoice updates → design attack simulations where the “fail” is acting on the request; measure time-to-report.
- IT/admins: SSO resets, urgent password-check requests, and endpoint compromise attacks; prefer credential-harvest flows and phish landing pages that teach URL checks.
- Executive support or HR: business email compromise attacks, meeting changes, sensitive file shares; train people to verify by calling back on a known number, not by replying to the email.
Personalize content, not creepiness
- Adaptive difficulty by person and role. Tune the challenge to each person’s skill and risk level to keep them engaged.
- Personalize the reward, not just the difficulty. A finance team and a new hire don’t need the same “thanks for reporting” message.
- Localize the language. A pretext that reads naturally in one language can feel stiff or obviously translated in another, and that alone can tip someone off.
Wire simulations into your security stack
- Integrate with security tools. Trigger just-in-time nudges, and connect dashboards to your security operations center.
- Prevent false fails. Some integrated cloud email security tools rewrite URLs (e.g., QR tests showing “1000% opens”). Whitelist or bypass those scanners to avoid noise.
- Use real-threat intel. Build scenarios from reported cyber threats (smishing, QR, credential harvesters) so simulated phishing attacks mirror what hackers are actually building.
Below you can see how we turn real reported threats into phishing simulations here at Hoxhunt.

What metrics actually prove behavior change?
The metrics that actually prove behavior change are reporting rate and time-to-report, on real threats as well as simulated ones, not click rate. Click rate plateaus and says nothing about learning. Reporting rate keeps climbing when a program uses positive feedback and timely micro-lessons, and that climb is the real signal of change.
The proof shows up in the data: the fastest 5% of employees report threats in 39 seconds, and reporting keeps climbing even as simulation difficulty rises over time (Hoxhunt Phishing Trends Report 2026, p.34 and p.39).
Your KPI short-list (definitions → why it matters → how to measure)
% of users who report suspicious messages.
A climbing rate is real behavior change, more people choosing to report instead of staying silent, and it gives the security team an earlier warning on a real threat.
Per campaign and as a monthly trend. Aim for continuous lift, not a fixed “good” number.
Minutes from receiving the email to reporting it.
The sooner someone reports a real threat, the sooner the security team can contain it, before it spreads or someone acts on it.
Median by role or team, and by channel (email, SMS phishing, voice phishing).
% decrease in users who fail two or more times across training campaigns.
A shrinking number over time shows that coaching people instead of punishing them actually works.
Cohort size over rolling 90 days.
It never hits zero, and focusing too much on failure makes people afraid to speak up. Reporting, on the other hand, keeps improving with positive reinforcement.
How should you handle repeat clickers constructively?
The constructive way to handle repeat clickers is to treat them as a signal to coach, not a reason to punish. Check the training itself first: a program that discourages reporting or buries feedback will keep producing repeat clickers no matter who’s in it. Whoever’s still struggling after that should get one-on-one coaching built around their specific motivations, since punishment only pushes people to hide mistakes instead of admitting them.
We unpacked one of cybersecurity’s most polarizing dilemmas: what should be done with repeat offenders in phishing simulations in a recent episode of the All Things Human Risk Management Podcast.
Playbook for dealing with repeat clickers
- Fix the program before the people. Low engagement and fear of “gotchas” are program symptoms, not personal failings. Redesign the training so success means reporting and feedback is instant, before assuming anyone needs individual coaching.
- Use positive reinforcement, not penalties. Reward correct actions (reports), pair misses with short microlearning, and keep tone respectful. This sustains behavior change better than reprimands.
- Shrink the cohort, then individualize. Group-level fixes shrink the number of repeat clickers over time. For whoever’s still left, find out why they keep clicking: overload, curiosity, or an unclear reporting process, and set a small, personal goal from there.
- Coach with empathy and relevance. Use examples from their own role to show that reporting fast limits damage, even after a mistake, until “report fast” becomes their default reflex.
- Leverage curious clickers. Some clicks might come from curiosity, not negligence. When that’s the case, give them harder simulations, and let them share what they find. That turns curiosity into free peer training instead of a wasted “click.”
- Keep HR as a culture partner, not an enforcer. Use HR to build psychological safety and craft humane communications, not to open a disciplinary file every time someone clicks a test email.
Why this works: Positive, individualized coaching drives real behavior change. Punitive “consequences” often create fear, underreporting, and productivity drag.
What legal, privacy, and ethics guardrails should you follow?
The core rule is simple: tell people testing happens, stay within legal limits for SMS and phone, and treat every mistake as something to learn from, not punish. Get any of those wrong, and the program will lose the trust it needs to build.
At-a-glance guardrails
- Announce the program (without spoilers). Tell employees that simulated phishing and other attack simulations may occur to support cybersecurity awareness training (the aim is learning, not entrapment).
- Keep lures professional and non-harmful. Complaints about a lure that goes too far can end up as an HR or legal matter, not just a bad review.
- Check regional telecom rules for SMS or phone. In some countries, simulating calls or texts can breach telecom regulations. Consult Legal and HR first, and exclude sensitive groups if needed.
- Design for dignity. Treat mistakes as teachable moments. Punitive programs backfire: people get resentful and just stop reporting.
Program communications you can copy
Plain-English program notice (pre-launch):
“We run periodic security exercises to help everyone spot phishing attempts and protect data. These are part of our cyber security program. If you’re ever unsure, report it. We’ll always provide quick feedback so we can learn together.”
Scope note for multi-channel tests:
“From time to time, exercises may include email, QR, text, or phone-based social engineering. We design them to be realistic but respectful, and to follow local rules.”
Red lines (don’t cross)
- No “cruel realism.” If it would be devastating in real life, it doesn’t belong in a test. No exceptions.
- No cold “gotchas” for new hires. Educate first. Surprise testing can create a hostile first impression of security.
- No spoofing of real external identities or numbers. Use safe stand-ins. Legal peers flag telecom and privacy risk in several regions.
“Click rate never goes down to zero… and focusing on click rates means we focus on failure. That can be really damaging to psychological safety; people become afraid to report mistakes.”
Phishing simulation best practices (Top 10)
These are the ten practices that matter most, the ones that make simulations feel real, stay ethical, and actually change behavior.
- Make reporting the win condition: Clicks won’t hit zero. Over-focusing on them damages psychological safety. Track reporting rate and time-to-report as your north-star metrics.
- Set a cadence without fatigue: Use a monthly baseline. Increase frequency only for high-risk cohorts and new hires, and refresh content before you add volume.
- Keep scenarios realistic and ethical: Prioritize BEC, credential harvesters and SMS phishing. Avoid panic-bait (layoffs, medical results, or personal finance). Keep exercises short and respectful.
- Match the fail method to the pretext: If the pretext is payroll change (BEC), the fail is acting; if it’s an account warning, it’s submitting credentials. Follow every failure with a one-minute micro-lesson.
- Fix the plumbing before the program: Unify to one report phishing button (e.g., Outlook add-in), and whitelist URL rewriters. QR tests often break from Microsoft link rewriting, skewing results.
- Give instant feedback, not hour-long remedials: Route simulated failures and real reports to concise, positive landing pages that explain the social engineering cues and next steps. Morale and learning both improve.
- Adapt difficulty, and keep templates fresh: Rotate phishing templates from current intel; tune challenge per user or role. That’s how you avoid plateaus and “template fatigue.”
- Train multi-channel safely (email, phone, and SMS): Simulate voice calls and SMS thoughtfully, especially deepfake-style vishing for executive support, then debrief fast to protect trust.
- Integrate with your SOC & Microsoft stack: Feed reports into the security operations center, and trigger just-in-time nudges.
- Be transparent, and track whether it’s working: Announce that periodic tests support cybersecurity awareness training. A short-term reporting spike afterward is a good sign, not a problem. Track it against real outcomes, fewer incidents, faster response, not just a lower click rate.
Learn how to design phishing simulations that build trust, boost engagement, and strengthen your organization’s security culture. In this video, we walk through the essentials, from creating realistic, fair scenarios to reinforcing psychological safety and delivering instant feedback.
Year-one rollout: cadence, difficulty ramp, and sample calendar
Q1 - Foundations (build trust)
- Program comms: simulations support cybersecurity awareness training, success equals reporting.
- Deploy a single report phishing button (e.g., Outlook) and instant feedback.
- Baseline send (easy simulated phishing) and a 1-min micro-lesson.
- Check integrated cloud email security (QR or URL rewrites) and whitelist to prevent “auto-click” noise.
Q2 - Calibrate by risk (adaptive difficulty)
- Move high-risk roles (finance, IT, executive support) to tighter micro-drills; everyone else stays at same cadence.
- Rotate phishing templates (BEC, invoice change, delivery updates).
Q3 - Multi-channel realism (responsibly)
- Add QR (quishing) and SMS phishing for appropriate teams; verify regional rules and keep lures professional.
- Pilot voice phishing for executive support (brief, debrief fast).
- Coach repeat clickers one-on-one with positive reinforcement, not penalties.
Q4 - Prove impact and harden operations
- Tie signals to incident response dashboards.
- Highlight reporting rate and time-to-report gains.
- Tune training campaigns for what’s working.
- Plan next year’s scenarios and ramp.
Templates & topics: what should you try vs avoid?
The best templates stay grounded in real, current attacks, not panic-bait, a badly timed lure during a reorg, or anything that’s gone stale. The table below breaks down what to use, what to skip, and why each one lands or backfires.
Templates & Topics: Try vs Avoid
| Use these (safe and effective) | Why they work | Avoid or caution | Why to avoid |
|---|---|---|---|
| Business email compromise (vendor IBAN change, invoice update) | Mirrors real losses; teaches verify-and-callback and out-of-band checks | Layoffs, medical results, or personal-finance bait | Makes people afraid to speak up, and drives complaints and under-reporting |
| Credential notices (SSO or session reset → phish landing page, e.g., “Password Check Required Immediately”) | Natural fail is credential submission; perfect for concise landing-page coaching | Salary or bonus rumor lures | Feels manipulative and personal; harms trust |
| Delivery, meeting, or policy update nudges, e.g., “Travel Perks,” “Google Play” receipt, “Canvas Teacher” invite | Everyday pretexts build the report-button habit without drama | Perks or benefits lures during tense periods | A cheerful “bonus” or “perks” email feels tone-deaf if it lands during a layoff round or reorg |
| QR (“quishing”) → mobile phishing website | Matches current attacker tactics; trains mobile URL scrutiny | Spoofing real external identities or numbers (SMS or phone) | Telecom and privacy risk; requires strict controls and approvals |
| SMS phishing (delivery or bank) where regionally permitted | Expands channel coverage; short micro-lessons land well | All-channels-at-once blitzes | Testing every channel at once overwhelms people and makes false positives more likely |
| Vishing (executive support; verify-and-callback drills) | Prepares for deepfake- or voice-led BEC chains, and it sticks with people when it’s short and debriefed right away | Punitive comms or public shaming of “clickers” | Suppresses reporting; damages morale and culture |
Keep lures professional, and match pretext to fail method to a teachable landing page. Rotate templates, and skip panic-bait.
Training techniques (micro-lessons, gamification, adaptive difficulty)
- Instant feedback > hour-long remedials: Route them to a quick landing page with a micro-lesson, right away.
- Positive reinforcement: Celebrate small wins instead of scolding mistakes.
- Adaptive difficulty: Ramp the challenge gradually, so it always matches each person’s skill level.
- Coach repeat clickers one-on-one: As the group shrinks, shift from general training to individual coaching.
What’s the right platform and tooling stack?
The right platform depends on how far you want to go, from a lightweight setup that covers the basics to a dedicated system built for scale. Either way, the same five criteria decide whether it actually works.
Minimum viable
- One channel
- A follow-up training moment
- A single report button
- Basic metrics
Advanced
- Multi-channel lures (SMS, voice)
- Adaptive AI-driven playbooks
- SOC integrations
- Automated reporting exercises tied to real-life cyber threats
Selection criteria (what actually matters)
- Channel coverage and realism: The platform must cover the channels attackers actually use, email, SMS, voice, and QR, otherwise simulations miss half of what people need to recognize.
- Learning loop and effectiveness: Every failure must end in an instant, teachable landing page and micro-lesson that turns it into actionable learning, otherwise the lesson doesn’t stick.
- Measurement and analytics that prove change: The platform must track reporting rate and time-to-report, not just click rate, otherwise you can’t tell if anyone is actually learning. It should also feed that data into the security tools you already use.
- Deliverability and safety: Simulations must work smoothly with your existing email security tools without triggering false fails, otherwise your data will be wrong.
- Scalability and localization: The platform must support multiple languages and target users by role or region, otherwise a global rollout won’t feel relevant to everyone.
Why choose Hoxhunt for phishing simulations?

Hoxhunt customers see fail rate and miss rate drop while reporting rate climbs, month over month.
Hoxhunt excels at adaptive, gamified phishing simulation that lifts reporting and eases SOC workload. It unifies the report phishing button, gives instant feedback on real phish, rotates content from current threats, integrates with Microsoft and EDR signals, and prioritizes psychological safety with an easy “welcome” benchmark and per-user difficulty.
What buyers told us (and how Hoxhunt answers)
These are the frustrations buyers described with their previous phishing simulation setup, before switching, not complaints about Hoxhunt itself.
“Training feels generic; engagement is low.”
Hoxhunt personalizes simulated phishing difficulty to each user’s skill and role and uses stars, streaks, leaderboards to keep people motivated. The result is higher participation in security awareness training that doesn’t feel like a “gotcha” test.
“We only see click and fail rates.”
Admins get real-time dashboards and user-level insights that go beyond clicks. The platform also provides threat heatmaps you can act on in training campaigns.
“Too many places to report a phish.”
Hoxhunt consolidates to one integrated button (for Outlook, Gmail), so users are no longer confused about which tool they should use, which leads to more consistency in reporting.
“Employees never get feedback on real phishing incidents.”
The platform provides instant, automated feedback on real reports, teaching in the moment so employees and the SOC don’t have to go back and forth as much.
“Microsoft integration is a nightmare, and simulations don’t reliably land in inboxes.”
Hoxhunt is designed to seamlessly integrate with Microsoft Defender and EDR signals for behavior-based training.
Differentiators that matter in 2026
- Psychological safety by design. A “welcome” benchmark and adaptive difficulty keep users challenged, but not overwhelmed, while making “report fast” the default reflex.
- Threat-led content rotation. Templates are updated from real-life phishing attacks (QR, credential harvesters, smishing), so attack simulations mirror today’s cyber threats.
- Vishing and deepfake training capability. Hoxhunt offers deepfake simulations to prepare for business email compromise chains that pivot to a phone call or a Teams meeting.
- Culture over punishment. Experts agree that punitive programs backfire and suppress reporting, so the platform emphasizes positive reinforcement and short micro-lessons instead.
Case Study: Bird & Bird transforms human cyber risk with Hoxhunt
Overview: Bird & Bird is a global law firm founded in 1846, headquartered in London, and active in 20 countries with around 3,300 attorneys and staff. Serving clients in sensitive sectors, especially finance, makes it a high-value target for cyber threats.

Reported threats jumped from 60 to 900 a month after the rollout, and 60% of users now report real threats on their own.
The Challenge: Building trust, not fear
- The firm needed to shift away from punishment-driven security awareness training that put people off and discouraged them from reporting.
- They wanted real behavior change, measurable risk reduction, and a people-first experience that users would embrace rather than resent.
The Hoxhunt Solution
- Hoxhunt’s human risk management platform was a natural fit. Individualized micro-trainings, gamified engagement (stars, leaderboards), adaptive difficulty, and instant feedback loops encouraged active learning, not just passive awareness.
- Leadership embraced it too, a rare positive reaction to a security program.
Bird & Bird case study: outcomes with Hoxhunt
| Metric | Before | After | Change |
|---|---|---|---|
| Real threat detection | 60 reports/month | 900 reports/month | +1,400% |
| Resilience ratio (success-to-failure) | 5.3 | 37.8 | +613% |
| Failure rate | 9% | 1.8% | −80% |
| Miss rate | 43% | 28.8% | −33% |
| Real threat detectors | N/A | 60% of users reported at least one real threat | N/A |
| Reporting time | N/A | 6 h 35 min average | N/A |
US benchmark: The same approach scales in the United States too. Copart, the Dallas-based global vehicle remarketer, ran 202,992 completed phishing simulations across 963 unique variants. It doubled its reporting rate from 24% to over 50%, after moving on from a legacy cadence of just one to three campaigns per quarter. A high-variety simulation library is what lets a US enterprise and an EU firm like Bird & Bird both sustain that climb.
Phishing simulation best practices FAQ
How do I run my first simulation?
Can I use Microsoft 365 Attack Simulation Training for best practices?
What’s a “good” click rate?
Should we tell employees about simulations?
Do we punish repeat clickers?
How realistic should scenarios be?
Is it OK to run “gotcha” tests without telling employees?
What’s the right way to onboard new hires?
Sources
Hoxhunt Phishing Trends Report 2026, Hoxhunt, 2026
Building an Information Technology Security Awareness and Training Program (SP 800-50 Rev. 1), NIST, September 2024
How To Recognize and Avoid Phishing Scams, FTC Consumer Advice, September 2022
Phishing attacks: defending your organisation, UK NCSC, February 2018 (reviewed February 2024)
Get started using Attack simulation training (Defender for Office 365), Microsoft Learn, February 2025
Payloads in Attack simulation training, Microsoft Learn, 2025
Phishing (Technique T1566), MITRE ATT&CK, 2025
Phishing Tests, the Bane of Work Life, Are Getting Meaner, The Wall Street Journal, February 2025
Improve end-user resilience against QR code phishing , Microsoft Defender for Office 365 Blog, September 2024
- Subscribe to All Things Human Risk to get a monthly round up of our latest content
- Request a demo for a customized walkthrough of Hoxhunt


.avif)
.avif)