Cyber Security Simulation Training: 11 Attack Types to Build Resilience

This guide will walk you through the most pervasive attack techniques currently being used so that you can incorporate them into your cyber security simulation training.

Post hero image

Table of contents

See Hoxhunt in action
Drastically improve your security awareness & phishing training metrics while automating the training lifecycle.
Get a Demo
Updated
September 7, 2026
Written by
Hoxhunt
Fact checked by

The short answer

Cyber security simulation training sends employees realistic, AI-generated phishing simulations so they learn to recognize and report real attacks safely. Run continuously against current attacker techniques, it turns awareness into measurable behavior change. Hoxhunt customers benchmark toward a 70%+ average reporting rate, drawn from 50M+ real and simulated threat reports across 4M+ users in 125 countries (Hoxhunt Phishing Trends Report 2026).

Cyber security simulation training works by mirroring current attacker techniques. As a result, employees learn to recognize and report a real attack instead of falling for one.

The hard part is deciding which attack techniques to use and how realistic each simulation needs to be, because recognizing a fake attack should teach employees to catch the real thing. This guide walks you through the most pervasive techniques in use right now so you can build them into your phishing simulation program.

How does cyber security simulation training work?

Cyber security simulation training uses fake phishing emails to test and train employees on how to identify real phishing attempts and respond to them quickly.

Here’s what to do:

  1. Send simulations: Send employees customized phishing simulation emails designed to mimic real-world scenarios, without prior notice.
  2. Monitor interactions: Track who opens, clicks links, downloads attachments, or reports each simulated email.
  3. Give feedback: Teach employees who miss a simulated phishing email how to spot phishing attempts next time.
  4. Report on posture: Use the results to report on your organization’s cybersecurity posture and pinpoint the vulnerabilities you need to address.
  5. Review, refresh and optimize: Review results regularly and refresh any simulation that has gone stale or predictable, so training keeps pace with new phishing tactics and stays challenging.

Awareness-based training doesn’t reduce risk

AI-built phishing surged almost overnight: a 14× jump at the end of 2025, from under 5% to 56% in a single month (Hoxhunt Phishing Trends Report 2026). That kind of change is why static content falls short: simulations only build resilience if they mirror attacks that now change week to week.

14×
jump in AI-built phishing that bypassed email filters, end of 2025
Source: Hoxhunt Phishing Trends Report 2026
56%
of detected attacks were AI-built by December, up from under 5% a month earlier
Source: Hoxhunt Phishing Trends Report 2026

Reducing risk means moving beyond traditional, compliance-driven security awareness training and toward changing your employees’ habits, which takes hands-on experience spotting and reporting real threats.

Cyber security simulation training gives you the ability to test employees in a controlled environment and give them a genuine feel for what real threats look like.

Want to measurably reduce cyber risk? Drilling best practices into employees won’t form habits; regular practice will. If you educate your employees on how to identify a wide range of simulated attacks, it will have a real, tangible impact on how they behave.

11 types of attacks to use in your cyber security simulation training

The human element is present in 60% of breaches (Verizon Data Breach Investigations Report, 2025). Across more than 50 million real and simulated threat reports from over 4 million users in 125 countries, phishing that bypasses filters and triggers malicious clicks remains the dominant social-engineering vector (Hoxhunt Phishing Trends Report 2026).

Employees within your organization access business-critical information, client data, financial information, and other confidential data every day.

When cybercriminals steal employees’ information, such as login details and account passwords, the result can be fraud, data breaches, and reputational damage.

Whether your employees work on-site, remotely, or in a hybrid setup, your anti-phishing training needs to cover the cybersecurity threats below 👇

The 11 attack types at a glance

Attack typeChannelWhat it is
Domain SpoofingEmail and webForged sender domains and lookalike websites that make a message appear to come from a legitimate organization.
Spear PhishingEmailA targeted attack tailored to a specific individual or organization instead of sent in bulk.
CEO FraudEmailAttackers impersonate the CEO so an employee acts on a fraudulent request without questioning it.
WhalingEmailSpear phishing aimed at executives and senior staff, the high value targets attackers call whales.
VishingPhone callVoice phishing, where attackers trick employees into sharing confidential information over the phone.
SmishingSMSText messages that push the recipient to give up information, open a malicious link, or install software.
Angler PhishingSocial mediaImpersonating a trusted brand’s customer service team on social media to extract information or action.
PharmingWeb and DNSTraffic is redirected from a legitimate website to a fraudulent copy without the user knowing.
Pop-up PhishingBrowser pop-upPop-up windows during normal browsing that prompt the user to hand over data or install malware.
Clone PhishingEmailA real email is duplicated and altered slightly so it carries a malicious link or attachment.
Invoice FraudEmail and paymentsA fake or altered invoice sent so a genuine payment lands in the attacker’s account.

1. Domain Spoofing

What is it?

Domain spoofing is a tactic used by cybercriminals to manipulate email recipients into believing that a message is from a legitimate sender or organization. It’s one of the most common types of phishing attacks.

In 2025, gmail.com alone accounted for 20% of sender domains in malicious emails, and malicious Salesforce sender domains rose threefold over the year (Hoxhunt Phishing Trends Report 2026).

Bad actors will forge email addresses to mimic a trusted domain, often that of a well-known company, government agency, or financial institution.

Domain spoofing can be classified into:

  • Email spoofing: Cybercriminals send emails using false domain names that appear legitimate.
  • Website spoofing: They may also set up websites that look authentic by using attractive visual designs, branding, logos, and styling.

These emails and websites will usually ask users to enter their personal information, such as company login IDs, passwords or credit card details.

Here’s what the domain spoofing process looks like 👇

  1. Targeting a trusted domain: Attackers identify a target domain that is widely recognized and trusted by the intended recipients.
  2. Crafting a spoofed email: Attackers then craft the email to appear as if it’s from the target domain, spoofing the sender’s email address to make it look authentic.
  3. Adding malicious attachments or links: The spoofed email then prompts the recipient to take action, such as clicking on a malicious link, downloading an infected attachment, or providing sensitive information.
Domain spoofing example.webp
Source: Securelist

What should your training cover?

Besides implementing cybersecurity measures, such as SPF (sender policy framework), DKIM (DomainKeys Identified Mail), etc., you’ll need to train employees to identify and prevent spoofing attacks.

Recognizing spoofed emails: Your training program should teach employees how to spot the signs of domain spoofing in emails. These signs include discrepancies in sender email addresses, spelling and grammar errors, requests for sensitive information, and urgent calls to action.

Verifying sender identities: Employees must be trained to verify the authenticity of sender identities and scrutinize email content for signs of phishing or impersonation. Effective training programs must provide guidance on how to perform these verification checks effectively and accurately.

2. Spear Phishing

What is it?

Spear phishing is a targeted form of attack in which malicious actors tailor their phishing attempts to specific individuals or organizations. Its goal is to steal financial or sensitive information through social engineering.

In 2025, Hoxhunt’s own AI spear-phishing simulation agents became more effective than elite red teams at getting people to click. Attackers are moving just as fast: AI-enabled phishing and pretexting rose 34% in 2025 (Hoxhunt Phishing Trends Report 2026).

Unlike traditional phishing, which casts a wide net, spear phishing depends on careful research and customization to target victims precisely.

At its core, these attacks rely on social engineering tactics to manipulate recipients into taking a desired action, such as clicking on a malicious link, downloading malware-infected attachments, or divulging sensitive information.

Spear phishing attacks use targeted open-source intelligence (OSINT) to gain unauthorized access to the organization’s information via the website and social media.

Attackers also scour employees’ social media accounts for personal details like real names, job titles, email addresses, hometowns, and places they’ve visited.

They use these details to craft emails that look like they’re from a legitimate sender, sometimes even impersonating a colleague or friend to gain the target’s trust. That’s why employees should never share sensitive data (such as login details), even with someone who looks like a trusted colleague or friend.

Spear phishing.webp
Source: Norton

What should your training cover?

To protect your organization from spear phishing, you’ll need to implement strong email security protocols, such as multi-factor authentication (MFA) and email authentication mechanisms like Domain-based Message Authentication, Reporting and Conformance (DMARC).

And when it comes to your training content, it’ll need to include the following:

Knowing the red flags of spear phishing: Spear phishing attacks can be hard to detect, so teach your employees to watch out for suspicious-looking links and unexpected requests for sensitive data.

Scrutinizing sender email addresses: Employees should be taught to use additional verification methods when an email looks off, such as contacting the supposed sender through a known, trusted channel.

3. CEO Fraud

What is it?

As the name suggests, CEO fraud is an attack in which hackers impersonate the CEO. They send an email to new and low-level employees, to trick them into sharing their personal information and company login details.

CEO fraud typically begins with a reconnaissance phase: cybercriminals gather information about the organization and its key personnel.

They research company websites, social media profiles, and public records to identify potential targets and gather details about organizational structure, key decision-makers, and internal processes.

Armed with this information, attackers then create highly personalized emails designed to mimic legitimate communications from the CEO or other executives.

These emails often exploit a sense of urgency or authority, and they ask recipients to take immediate action, such as wiring funds to a specified account or providing sensitive financial information.

For instance, the “CEO” might attach a vendor or supplier invoice in the email, using new account details, and ask the employee to pay for it.

Whaling.webp
Source: ResearchGate

What should your training cover?

Basic phishing email identification: CEO fraud emails will have the same tell-tale signs as any other kind of phishing attack. However, you’ll want to make sure your training emphasizes that employees should be vigilant no matter who an email is from, even if it appears to be from their CEO.

Verifying requests: Training should emphasize the importance of verifying requests for financial transactions or sensitive information, particularly when they come from high-ranking executives.

4. Whaling

What is it?

Whaling is a form of spear phishing in which cybercriminals specifically target an organization’s executives and high-level employees, whom attackers refer to as “whales.” Whaling attacks are generally characterized by their sophistication, customization, and attention to detail.

Since the targets are usually more aware of these attacks and better trained to resist them, cybercriminals use methods tailored to the victim, often referencing accurate details about the business.

Successful whaling attacks are especially dangerous as top executives often have greater access to company data, intellectual property, and financial systems.

Whaling attacks can take various forms, depending on the attacker’s objectives and the level of sophistication employed. Some common examples include:

  • Fake invoice scams: Attackers impersonate a company executive or vendor and request urgent payment for fictitious invoices or business expenses.
  • CEO impersonation: CEO fraud (covered above) is actually a type of whaling.
  • Credential theft: Attackers trick executives into disclosing their login credentials or other sensitive information by sending phishing emails disguised as urgent requests for password resets, account verification, or security updates.
CEO fraud.webp
Source: IT Governance USA

What should your training cover?

Any training program you implement should target high-level employees specifically and offer content tailored to their roles.

Executive awareness: Training should specifically target executives and high-level decision-makers, since they’re often the least aware of how prevalent and damaging whaling attacks are.

Trust-but-verify culture: Effective training will instill a verification procedure for high-risk transactions or requests initiated via email. For example, employees might call the CXO directly to confirm that the request for an online transaction or a funds transfer really came from them.

Role-based training sessions: Tailoring cybersecurity training programs to the specific roles and responsibilities of your employees is essential for mitigating targeted cyber threats like whaling attacks. Executives may receive training on the risks associated with whaling attacks, while finance and accounting staff must focus on identifying fraudulent payment requests and verifying the authenticity of financial transactions.

5. Vishing

What is it?

Vishing (short for “voice phishing”) is an attack in which hackers trick employees into sharing confidential information over the phone. Callback phishing, on the other hand, is a fast-growing variant of vishing where an email lures the recipient into calling a number instead of clicking a link.

Callback phishing campaigns rose 500% in Q4 2025, and 43% of business email compromise (BEC) attacks now carry a callback lure (Hoxhunt Phishing Trends Report 2026, citing LevelBlue and VIPRE).

Similar to traditional phishing scams conducted via email, vishing relies on social engineering techniques to manipulate victims and exploit their trust.

Vishing attackers usually pose as bank personnel to verify the account information and conduct a transaction. They might also impersonate an employee from the Internal Revenue Service (IRS) to validate the tax returns by requiring access to a Social Security number.

Below are a few of the tactics that attackers might use:

  • Caller ID spoofing: Vishing perpetrators often use caller ID spoofing techniques to mask their true identity and make their calls appear to originate from legitimate sources, often by displaying familiar or official phone numbers on the recipient’s caller ID.
  • Urgency and threats: Vishing scams rely on creating a sense of urgency or fear to prompt victims into taking immediate action. Callers may claim that the victim’s account has been compromised, that suspicious activity has been detected, or that legal consequences will ensue unless immediate action is taken.
  • Social engineering tactics: Social engineering is often used to build rapport with targets and establish credibility. Attackers may employ persuasive language, authoritative tones, or insider knowledge to gain the victim’s trust and credibility.

What should your training cover?

If you train employees on vishing, they’ll be able to verify the sender by evaluating the caller number, as scam calls usually have unusual country codes that differ from the regular ones. Here are a few extra factors to consider.

Critical thinking skills: Training should encourage employees to adopt a skeptical mindset when receiving unexpected or unsolicited calls. Employees can then be trained to question the validity of requests for sensitive information, especially when the caller exhibits coercive or manipulative behavior.

Security policies for phone calls: You may want to ensure your training reinforces any security policies and procedures related to handling sensitive information over the phone, such as never sharing passwords or account details, and reporting suspicious calls.

Simulated vishing exercises: While you’ll need simulations for all of the attacks in this list, vishing benefits from hands-on practice more than most, since it’s hard to learn to spot a scam call if you haven’t experienced one before.

‍6. Smishing

What is it?

Smishing is a technique that involves the use of text messages to deceive individuals into divulging sensitive information, clicking on malicious links, or downloading malicious software onto their devices.

In this kind of phishing attack, perpetrators will typically send fraudulent text messages to large numbers of recipients, posing as legitimate entities such as banks, government agencies, or well-known companies.

These messages often contain urgent prompts, like account suspension warnings or requests to verify personal details.

The text message will usually contain a link to a website URL which seems accurate, but clicking on it may install malware automatically in the background on the user’s device.

Smishing.webp
Source: Secure World

What should your training cover?

While there are steps you can ask employees to take, such as enabling spam filters, training is essential here, especially when employees use their personal devices for work, because organizations have limited or no control over them.

Recognizing warning signs: Employees well-trained in cybersecurity awareness will be able to distinguish between real and fake URLs by reviewing URL prefixes, sender numbers, and message content.

Skeptical mindset: Encouraging employees to question unexpected messages and confirm the sender through a separate channel, like a phone call to the company’s official number, will help prevent successful smishing attacks.

Best practices for mobile use: Your training program should teach employees how to manage text messages securely and how to respond to suspicious or phishing attempts. This should include not clicking on links or opening attachments from unknown senders, keeping sensitive information off text messages, and reporting suspected smishing attempts to your security or IT team.

Simulated exercises: Cybersecurity training programs, like Hoxhunt’s, incorporate smishing into their simulated attacks so employees learn to identify and respond to potential threats firsthand.

‍7. Angler Phishing

What is it?

Angler phishing is a sophisticated form of attack that usually impersonates a trusted brand’s customer service team on social media to trick individuals into divulging sensitive information or taking a harmful action.

Attackers monitor social platforms for public complaints about a company, then respond to the complaint by posing as that company’s support team in a direct message.

Because the victim is already expecting a reply, they’re less likely to verify the account before sharing sensitive information.

Angler phishing.webp
Source: IT Governance

What should your training cover?

Ideally your training should also be accompanied by measures such as spam filters, email authentication protocols, threat intelligence tools, and MFA.

Critical analysis of URLs and links: Your training should teach users how to critically analyze URLs and hyperlinks contained within emails to determine their legitimacy, even when the sender address looks safe.

Personalized content for most targeted employees: Angler phishing attacks often target specific individuals within organizations, such as executives, finance personnel, or IT administrators. Make sure any training you implement gets targeted resources to those who need it most.

Email security measures: Training should help individuals use email security features and tools effectively to mitigate the risk of angler phishing. This may include using email filtering technologies to block malicious messages, configuring spam and phishing detection settings, and implementing email authentication protocols like SPF, DKIM and DMARC.

8. Pharming

What is it?

Pharming is an advanced type of cyberattack that redirects internet traffic from legitimate websites to fraudulent ones without the user’s knowledge or consent.

Unlike phishing campaigns, which rely on social engineering, pharming operates at the DNS level (the system that translates web addresses into the server locations browsers connect to) and manipulates the resolution process in order to reroute users to malicious websites.

In a pharming attack, the attackers clone an authentic website and redirect its traffic to a fake website to steal important personal information.

For example, the hacker can spoof a website that the user regularly visits, such as an e-commerce site they trust, to make them enter their financial information. This might be done via a fraudulent link sent through email, by manipulating search engine results, or by hacking the domain’s DNS.

One common technique used in pharming attacks is DNS cache poisoning, where attackers plant false address records on DNS servers. This way, when users attempt to access a legitimate website, their requests are intercepted and redirected to the malicious site controlled by the attackers.

Another method involves compromising the user’s local DNS settings, either through malware or unauthorized modifications, to achieve the same objective of redirecting traffic to fraudulent domains.

What should your training cover?

Pharming may be slightly more sophisticated than typical phishing tactics. However, thoroughly trained employees should be able to successfully distinguish a fake website from a real one, as long as your training offers the following:

Education on DNS security: Employees should understand the risks associated with pharming attacks, including how DNS works, the potential vulnerabilities in the DNS infrastructure, and the techniques attackers use to manipulate DNS resolution.

Detecting suspicious redirects: Training should teach employees how to recognize signs of a pharming attack, such as unexpected website redirects or warnings from web browsers about invalid security certificates.

Verifying website authenticity: Employees should also be trained to verify the authenticity of websites before entering sensitive information, including checking for secure HTTPS connections, examining SSL/TLS certificates for validity, and comparing domain names and URLs to ensure they match the expected destination.

‍9. Pop-up Phishing

What is it?

Pop-up phishing tricks users into divulging sensitive information or installing malicious software through pop-up windows that appear on their screens while browsing the internet.

Why would someone click on a phishing pop-up? These pop-up windows often masquerade as legitimate alerts, warnings, or notifications, aiming to create a sense of urgency or fear to prompt users to take action hastily.

In a pop-up phishing attack, hackers implant malicious code in pop-up windows that appear while users browse the web. Clicking the pop-up then installs malware on the user’s device.

The malware then spreads via the network to disrupt daily operations, corrupt critical information, and damage or delete it.

Pop-ups can also be used to collect credentials by imitating a login screen.

Pop-up phishing.webp
Source: Office of Information Security Washington

What should your training cover?

While there are steps you can take to protect employees’ devices, training is what builds the human firewall that serves as your first line of defense against these kinds of attacks.

Use of ad blockers: Employees should be encouraged to install and enable ad-blocking software or browser extensions to prevent malicious pop-up advertisements from appearing while browsing the internet.

Secure browsing practices: Training should cover safe browsing habits, such as avoiding clicking on suspicious links or advertisements, verifying website URLs before entering sensitive information, and being cautious when interacting with pop-up windows, especially those that request personal or financial details.

10. Clone Phishing

What is it?

Clone phishing is a phishing technique in which hackers take an existing email template and turn it into a malicious email by making small tweaks.

As the name suggests, clone phishing attacks use an original email sent from a trusted source and then make subtle changes to it, such as replacing genuine links or attachments with malicious links or attachments. Once the recipient clicks, either a virus (or other malware) installs on their computer, or an attempt to harvest their credentials is launched.

Clone phishing emails are usually sent from an address that impersonates the genuine email address the recipient expects from the original source. As a result, the attackers exploit the recipient’s trust to trick them into opening the malicious document.

Clone phishing.webp

What should your training cover?

Training plays a crucial role in protecting against clone phishing, since malicious emails can look just like the real thing.

Spotting cloned emails: Since cloning attacks can look very similar to legitimate emails, training should teach employees how to identify cloned emails by examining the URL, looking for inconsistencies or discrepancies, and verifying the legitimacy of the sender.

Avoiding suspicious links: Similarly to most other types of phishing, employees need to be trained to avoid clicking on links or downloading attachments from suspicious emails.

11. Invoice Fraud

What is it?

Invoice fraud occurs when a scammer sends a fake invoice or alters legitimate invoices to deceive a company into making payments to the wrong account.

Invoice fraud is very common and difficult to detect, since these attacks usually claim to come from a service provider (for businesses, at least), and attackers usually change their domain address to make the email seem legitimate.

Invoice fraud.webp

How to set up your simulation training program: best practices.

Ask yourself what the goal of your training is

This should always be the first step: think about what you want to achieve before building simulated phishing attacks.

  • What are your KPIs?
  • What types of threats is your organization exposed to?
  • How do you plan to test your employees?
  • What kind of simulation will you send out?
  • When will you send it out?
  • Would it be good to communicate to your employees that they might be tested every now and then?
  • Should you tell them how to deal with these attacks?

Use a wide variety of simulations

The types of cyber attack simulations you use should be tailored to your organization’s specific needs.

Do employees often download malicious attachments? Then you may want to send out simulated attacks with attachments. Are employees clicking malicious links repeatedly? If so, add a URL to the vector. You can even combine different types of attacks to train your employees for every possible scenario.

It’s also worth thinking about simulating more persistent cyber threats, since malicious actors in real life often send multiple follow-up vectors, such as a phone call after an initial phishing email, to add a greater sense of urgency and perceived credibility. Simulating these follow-ups can give employees a feel for these kinds of real-world attacks.

Keep phishing simulation campaign up-to-date

Attackers constantly develop new types of phishing attacks to get around organizations’ defenses, and the more sophisticated these attacks become, the harder they are to spot. That’s why you’ll need to make sure employees stay up to date with the latest attack threats and understand that modern phishing emails can be fairly hard to identify.

Ensure phishing simulations are frequent

Practice makes perfect: the more practice employees get, the better they’ll be able to spot suspicious emails, which is why your failure rate will generally improve with more frequent training. One or two cyber attack simulations per year probably won’t be enough to build that kind of practice.

Take the trend in QR-code phishing as an example. In 2025, malicious QR codes declined to under 2% of attacks in email bodies but re-surged hidden inside attachments such as PDFs (Hoxhunt Phishing Trends Report 2026). To see how training frequency affects detection, our Hoxhunt Challenge study (2024) tested over 600,000 employees across 125 countries using simulated QR phishing codes (both via email and physical fliers).

We found that a longer-term training approach improves performance over time: those who participated over a period of 18 months scored better than those who had only trained for a short amount of time. Moreover, employees with more training experience reported the suspicious QR code 3x more than employees new to the training.

600,000+
employees tested with simulated QR phishing across 125 countries
Source: Hoxhunt Challenge study, 2024
3x
more likely to report a suspicious QR code after 18 months of training vs. new starters
Source: Hoxhunt Challenge study, 2024

With time, continuous practice leads to behavior change, which means employees are able to spot and report actual attacks. Our data here at Hoxhunt shows that testing users at least a few times a month, as long as it doesn’t interrupt their workflow, is the most effective cadence to change behavior.

Hoxhunt simulation outcomes.webp

Give constructive feedback and use positive reinforcement

However your employees perform in simulated cyberattacks, it’s absolutely critical that they receive feedback. First, let them know that the email they just received was part of a training scenario, not an actual phishing attack. Then, include short pointers on what they should pay attention to when they receive emails.

Criticizing employees doesn’t work. Instead, you should always use positive reinforcement and reward systems in your feedback if you want to boost motivation and engagement.

Implement adaptive phishing training to drive behavior change

Cybersecurity simulation training works best when it’s tailored to employees’ specific performance and current skill level. This adaptive approach means employees receive simulated cyberattacks tailored to their specific roles, past behaviors, and known vulnerabilities. For example, employees in finance should receive phishing emails related to invoice fraud, while executives should be targeted with spear-phishing attempts.

To effectively change behavior and lower potential risks, employees need to be engaged, which only happens when the content matches their skill level. That’s why a one-size-fits-all approach to security awareness training just doesn’t work.

Here at Hoxhunt, our training also uses personalized learning paths: if an employee fails simulations, they’ll be sent easier phishing threats to identify, and then, once their confidence and motivation increases, they can be sent more difficult simulations.

Hoxhunt learning paths

Elements to consider adding to your attack simulations

To make simulated attacks feel realistic, they need to reflect the same tactics real attackers use, from psychological triggers to personalization and timing. Here’s what to consider:

Think like a real attacker

Your simulations must look like real-life attacks: think about how an attacker would scam your employees, then simulate that.

Use psychological triggers in your simulations

There are several emotions that scammers use to trigger employees to make the wrong decision, often relating to greed, curiosity, urgency, fear, or helpfulness. You can imagine that receiving an email with any of these triggers could be quite challenging to ignore, but the goal is for your employees to stay rational with every email they receive, no matter what the psychological triggers are.

Take into consideration the difficulty level

Adjusting the difficulty level to your employees’ progress lets them gradually advance and stay motivated to spot and report threats. That matters because very advanced attacks, and constantly failing from the start, can discourage employees to the point where they become inactive.

Use of call-to-actions (CTAs) in emails

Real attackers want your employees to click or do something harmful, and to achieve that, they use CTAs like “click here,” “sign in,” and “activate account” that redirect users to malicious downloads or landing pages.

The context of your simulation is very important

If the email is completely out of context (a service email from a bank they don’t even use), it will be much easier for employees to spot as fake. Make sure you use relevant content for each employee, since that’s how most real tailored attacks work too.

The design of the email

If you opt for an HTML template, you can make realistic looking copies of service emails, including logos and other design features. The more realistic it looks, the more difficult it will be for employees to spot. That said, a simple plain-text message can also be highly effective.

Personalization

When you personalize the email with simple things like your employee’s first name, it already becomes much more challenging for them to identify it as a simulation. Attackers can personalize their emails more than ever, with everyone’s life publicly available on social media. That’s why, at Hoxhunt, we automatically personalize every simulation to each individual based on their role, department, location, language, colleagues, and technical solutions they use.

Impersonation

Impersonation is one technique that scammers use consistently. If your colleague sends you an email, what harm can it do? In cybersecurity, we know the answer: it could easily be a business email compromise in disguise. But imagine receiving an urgent email from your “CEO” with all of the elements described above… That’s difficult to detect for anyone.

Timing

Timing can play an important role in why employees may fail a simulated attack: if they’re in a rush or under stress, they may have their guard down. You want your employees to recognize attacks at any time.

What metrics should you be measuring?

If your simulation training is focused on behavior change (as it ideally should be), reporting rate is the most important metric, because it tells you how many people actually reported simulated threats.

A quality reporting process is 100% mandatory: the more user-friendly and simple it is, the lower the barrier is for reporting phishing emails.

When employees are reporting simulated threats, you know that they’re engaged, learning, and acquiring the knowledge and skills needed to spot potential attacks. But if employees aren’t reporting simulations, you won’t know whether they identified the threat, or even noticed it at all.

Average simulation reporting rate per employee

Average simulation reporting rate tracks each employee’s own progress over time. It tells you how many simulated attacks they correctly identify and report. The higher an employee’s rate, the less likely they are to fall for a real attack. At Hoxhunt, we recommend aiming for at least an average of 70% across your organization.

This metric is only representative if you engage every employee, not just those who have previously failed a test. People-first training keeps everyone in the program regardless of past results, so the reporting rate reflects the strength of your entire human firewall, weak links included.

The real threat reporting rate

Real threat reporting rate measures how many genuine phishing emails, the ones that make it through your email filters, employees actually catch and report themselves.

That’s the truest proof a training program is working: no simulation can substitute for how employees perform against a real attack. Tracking and improving this rate is what helps you catch attacks before they cause harm and prevents real breaches.

You improve this rate by motivating employees to spot and report threats, which will:

  1. Reduce the chance of successful attacks.
  2. Lower recovery costs if an attack is successful, since even successful attacks should still get caught sooner.
  3. Give you insight into attacker behaviors, techniques, and tactics, since more reports mean more real-world data to feed back into training.

Dwell time

Dwell time is the period between a threat entering your network and an employee reporting it. Why does dwell time matter? It introduces a measurement of speed: the shorter it is, the less damage an attack can do.

Most platforms don’t track dwell time at all. Only a few adaptive phishing training platforms, like Hoxhunt, do, which means most organizations have no visibility into how fast their own employees actually catch real threats.

Here are some of the outcomes organizations using Hoxhunt tend to see 👇

Hoxhunt training outcomes

What about failure rate?

Failure rate is simply the percentage of employees who fail to recognize or report cyber attack simulations. It’s what most training solutions are based around, and many organizations heavily rely on it.

However, a low failure rate doesn’t necessarily mean your training is effective: it might be impacted by other factors, like the difficulty level of simulations, the variety of the content, how individual employees interpret a borderline email, timing, and frequency.

You don’t need to ditch failure rate completely, but remember that it doesn’t give you the full picture. Tracking failure rate can be useful, but only once your threat reporting and engagement rates are high enough to provide a sizeable data sample.

Failure rate is not the best metric for gauging your success if simulations are infrequent and follow a one-size-fits-all strategy. It’s also a volatile, easily gamed metric: send out easier simulations and it drops; send out harder ones and it jumps right back up. Neither move actually reflects a real change in your organization’s security.

Can you run cyber security simulation training manually?

The short answer is yes: you can absolutely set up a simulated attack program in-house. But should you?

Running a phishing simulation program manually requires significant work from your security team. Ideally, you’d want your phishing simulations to be personalized to employees, but for organizations with more than 100 employees, that isn’t a scalable approach.

Challenges of manual simulations:

  • Scalability: Manual simulations can be time-consuming and difficult to scale, especially for larger organizations.
  • Consistency: Ensuring consistency and realism in phishing emails can be challenging without automation and templates.
  • Latest threats: Keeping up with all of the latest attack types can be a daunting task.
  • Tracking: Manually tracking responses and analyzing data can be cumbersome and prone to errors.
  • Resource intensive: Manual simulations require significant time and effort from IT and security staff.

Bottom line: Manual simulations can work for a small pilot group. But past a few hundred employees, running simulations manually becomes a full-time job for your security team: personalizing them, scaling them up, and keeping up with the latest attack techniques, all at once. That’s exactly what automation is built to take off their plate.

What features should you look for in attack simulation tools?

The following criteria should give you an idea of how to evaluate your options when comparing cybersecurity training simulators. We’d recommend looking for a human-first phishing training that can tangibly reduce risk in a way you can track and measure.

User experience

As you’d expect, employees generally don’t appreciate having their regular workflow interrupted for long periods of time. Instead of dragging them away from their work, opt for a phishing awareness training solution that incorporates interactive content into an employee’s regular workflow, ideally in 5-7 min chunks.

Personalization

Personalization is absolutely necessary if you want your employees to feel like training is actually relevant to them. When shopping around for vendors, be sure to compare how much personalization they offer, starting with factors like employee cybersecurity knowledge, role, department, and the language training is delivered in.

Personalized learning paths also make for an effective solution: if an employee keeps failing simulation exercises, your training should adapt accordingly and send easier attacks that gradually increase in difficulty to meet their skill level.

Reporting

If you want to showcase the real impact of your training, you’ll need a vendor whose analytics go beyond basic simulation pass and fail rates. Most vendors stop there, and that alone rarely tells the full picture.

Two of the main KPIs in anti-phishing training are:

  • Reporting rates: When employees are engaged in training, reporting rates for both simulations and real-world threats tend to rise.
  • Failure rates: Broken down by vector type, they show you exactly where employees need additional training; tracked over time, they show how effective that training actually is.

Behavior change

Positive reinforcement and repetition are the two key drivers of turning a new behavior into a lasting habit.

Scaring people into action doesn’t work. Instead, reinforce the right behavior with a reward: employees who are rewarded for reporting simulated phishing attacks become more likely to report real-world incidents too.

Repetition matters just as much: check how many attack campaigns a vendor sends per employee each year, since ongoing training is what actually changes behavior in a measurable way.

Automation

The level of automation on offer varies from vendor to vendor. The two most important things you’ll want to automate are:

  • Delivery of personalized, frequent training: sending each employee simulations tailored to their role and skill level, on an ongoing basis.
  • Potential threat identification, classification, and escalation: automatically flagging a reported email as a likely threat, sorting it by type, and routing it to your security team.

Many of the organizations we work with were building their simulations and training content manually before switching to Hoxhunt. This approach made it costly and time-consuming to keep training up to date with the latest real-world scenarios. A vendor that regularly updates its content and automates the delivery of simulated attacks takes that work off your hands.

Personalize cyber attack simulations at scale with Hoxhunt

Want to drive tangible results with realistic simulations? Hoxhunt uses a mix of gamification and AI technology to automatically assign realistic, personalized phishing simulations that dramatically increase engagement and reduce risky behaviors. The results speak for themselves:

United States

Copart

Global vehicle auction & remarketing company

  • 202,992 completed simulations, with 963 unique variants
  • 24%→50%+ reporting rate, more than doubled
Read the Copart case study →
Europe

Ramboll

Global engineering consultancy

  • 100,000+ simulations run
  • 17,000 employees across 35 countries
Read the Ramboll case study →

Copart alone draws from 963 unique simulation variants, which is what lets simulations keep pace with attacks that change week to week, instead of relying on a handful of stale, recycled templates.

Why choose Hoxhunt’s phishing simulations?

Personalize phishing simulations at scale with AI

Hoxhunt’s AI engine generates a unique profile for every user and automatically delivers the most relevant phishing simulations based on skill, language, department, and more.

Simulations are crafted by experts in 30+ languages and can be customized to fit your needs.

Maximize phishing engagement with gamification

Hoxhunt rewards users with stars and badges, and a company-wide leaderboard encourages fun competition that dramatically increases engagement.

Train users with instant, bite-sized lessons

Hoxhunt delivers quick, in-the-moment phishing training that reinforces good behavior and transforms failures into fun and engaging learning opportunities.

More than just phishing simulations

Hoxhunt identifies what’s working well and where you can improve. That way, you know exactly where to focus, and your phishing simulations get more effective over time. Here’s how Hoxhunt helps you get there:

  • Quantifying your risk with a single number: Our scoring model benchmarks your phishing simulation performance against other organizations.
  • Tracking phishing simulation metrics over time: It shows the real impact of your training and helps validate your risk reduction efforts.
  • Identifying where to focus your efforts: Your scoring breakdown gives you context on what’s working, so you always know your next priority.
Hoxhunt platform.webp

Sources

Cyber security simulation training FAQ

What is cyber security simulation training?

Cybersecurity simulation training simulates real-world incidents like ransomware and phishing attacks.

It provides hands-on training in a controlled environment so that cybersecurity teams can prepare employees for potential cyberattacks.

What are the benefits of cyber security simulation training?
  • It helps develop practical skills, improving cyber defense, readiness for incidents and overall security culture in your organization.
  • Teams gain deep insights into attack vectors, learn incident response processes, and enhance their cybersecurity posture.
  • Organizations can track and measure how employees respond to realistic scenarios and tweak their training to address any weaknesses.
How does simulation training improve incident response?

By practicing with attack simulators, employees experience real-world incidents in a safe environment and can refine their incident response plans, reducing the risk of reputational damage and business loss from cyberattacks.

What makes Hoxhunt’s cyber security simulation training unique?

With Hoxhunt, simulations are easy to prepare, deploy, and scale across your organization. A variety of simulation templates lets you assess your vulnerability to common phishing tactics, and in just a few clicks, you can deliver simulations that are personalized to every employee.

For a side-by-side look at how the leading platforms compare on simulation realism and variety, see our guide to the best phishing simulation tools. You can also dig into whether phishing tests alone are enough and how an AI spear-phishing agent generates attack variants at scale.

Want to learn more?
Be sure to check out these articles recommended by the author:
Get more cybersecurity insights like this