Social engineeringSecurity testingStaff training

Phishing Simulations: What a Drill Involves

8 min read

The company bought a firewall, turned on mail filtering, and put two-factor authentication on the admin panel. Then one afternoon somebody in accounts gets a message headed "please confirm this month's revised payment details", opens the attachment, and every one of those defences has been walked around at once. Among the small businesses we work with in Taiwan, and this is in no way particular to Taiwan, the way in is usually an email that looks completely ordinary landing with a person too busy to look at it twice. A phishing simulation gets there first. A consultant you have commissioned sends a harmless imitation before a real attacker sends the real thing, and measures how many people in your organisation open it, follow the link, and type their password into the page behind it. This piece covers what a drill involves in practice, which numbers to measure, how to use the report, and the legal boundaries that have to hold.

1. What a phishing simulation is

A social engineering drill, usually called a phishing simulation, is a commissioned security test with a fixed scope. Working from an agreed recipient list and agreed scenarios, the consultant sends mail that looks close to a real attack and records what people do with it. The links point to a logging page built for the drill. No malware is delivered and no data is taken. Anyone who clicks normally lands on a short page telling them what just happened and which details would have given the message away next time.

What it tests is people and process, which makes it the complement to a vulnerability scan rather than a substitute. A scan tells you which holes exist on your machines. A drill tells you under what conditions somebody opens the door themselves. Measure both once and you know which side your next security budget belongs on.

How the data gets handled has to be settled up front too. The simulated login page can be configured to log only the fact that somebody submitted the form, without keeping what they typed. All measurements and raw records belong to the commissioning organisation, and the consultant deletes them at the end of the agreed retention period. These are not points to explain after the fact. They belong in the paperwork before anyone is engaged.

2. Why human judgement decides more than the technical defences

A mail gateway blocks known bad domains, known attachment patterns and known sender blocklists. An attacker registers a domain that week, swaps the attachment for a cloud storage link, and the filter rules no longer match. A plain-text message with no payload at all is harder still to catch by rule, because there is nothing technical in it to compare against. Once the message reaches the inbox, the remaining defence is the few seconds of judgement the recipient gives it.

Trace an incident backwards and the starting point is often a single click, or one set of company credentials typed into a convincing login page. That link in the chain is usually the cheapest part of the whole security budget, and almost nobody has ever measured what state it is currently in.

Most organisations run their annual security awareness session, tick the box, and end up with no before-and-after figures and no idea which department took it in. With no measurement there is nothing to compare and no basis for deciding who needs attention first. That is the value of a drill: it turns staff security awareness from a subjective impression into a number that departments can be compared on.

3. What one drill involves, start to finish

A standard drill runs about two to four weeks from scoping to report, with the sending period usually somewhere between a few days and two weeks. There is nothing mysterious in the process. What decides the outcome is how carefully the preparation is done. If the list is not cleaned, the gateway is not opened, or the internal announcement is worded badly, the numbers at the end are distorted and the report is not worth reading.

Four things to settle before any mail goes out

  • Agree the scope. How many people, which departments and grades, the drill window, and whether senior managers and contractors are included.
  • Get written authorisation. Signed by someone who can commit the organisation, setting out the population, the dates, how data is handled, and who owns the results.
  • Design the scenarios and the lures. Base them on the mail this particular company genuinely receives, and grade them by difficulty. Without difficulty levels the report cannot tell a careless click apart from a convincing one.
  • Have IT allow the sending source through first. Mail gateway, endpoint protection and link-rewriting all need the drill allowlisted, or the mail is blocked, or a scanner clicks the link for the recipient and the data is wrong.

The sending itself has one detail worth getting right: split the population into several waves rather than sending to everyone at once. Send it all in one go and the first person to say "that one is fake" by the coffee machine makes the rest of the numbers meaningless.

Then comes the analysis and handover. Four figures get pulled together, meaning opens, clicks, submissions and reports, broken down by department and grade, delivered as a report plus a session to walk through it. Do not skip the session. Numbers only turn into action when somebody explains them.

4. The metrics to measure, and how to break them down

The core output of a drill is a handful of rates. Read any one of them alone and it is easy to draw the wrong conclusion. Put together, they show which stage the problem sits at.

MetricWhat it tells you
Open rateHow attractive the lure was. Many mail clients block tracking images by default, so this figure reads low. Treat it as a trend, not an absolute
Click rateHow many people followed the simulated link. It measures the first layer of judgement and is the number most often quoted
Submission rateHow many people entered data on the fake login page. Those are company credentials already handed over, so remediation starts with this group
Report rateHow many people flagged the suspicious mail to IT or a manager. The one metric where higher is better
Time to first reportThe gap between delivery and the first warning. It decides whether a real incident can be caught early

Beyond the headline figures, only a breakdown by department and grade shows where the weakness actually sits. Finance staff tend to be sharp on fake invoices. Sales people, who read external mail all day, are often less alert rather than more. Managers get high volumes and read fast, so their click rate frequently runs above the rank and file. Whether a role deals with customers regularly is worth pulling out as its own group.

5. Scenarios that work, and ones to avoid

Scenarios have to resemble the mail this company genuinely receives, otherwise the difficulty means nothing. Test people with a typo-ridden message from an unknown free mail address and the resulting figure tells you nothing you can use.

Four families of scenario cover most drills. Fake system notices (mailbox full, password about to expire, a shared document waiting for approval) test the reflex click on routine operations. Fake invoices and payment requests (invoice notifications, changed bank details, purchase order confirmations) are aimed mainly at finance and procurement. Fake HR mail (annual review forms, insurance record updates, handbook sign-offs) covers everybody. The fake login page is what produces the submission rate: it looks like an internal system and shows the drill explanation page the moment anything is submitted.

A single drill normally mixes two or three difficulty levels, so the report can separate "anyone should have spotted that" from "even the IT staff had to look twice".

6. After the report: turning the numbers into a training plan

The report exists to order the training. Whichever department has the high submission rate gets the first small-group session. Whichever scenario type concentrated the clicks is the one the training should spend its time on, working through what would have given it away.

Say all of this before the drill, and put it in the written drill policy. When staff know the results are used to schedule training, the report rate goes up. Run it the other way, and one public dressing-down of somebody who clicked is enough to stop anyone reporting again. That costs you the most valuable metric you have. Internal presentations should show aggregate figures only, meaning rates and trends by department and grade.

Individual open and click records can technically be traced back to a named recipient. That data belongs to the commissioning organisation, and in practice access should be limited to a named contact, with the permitted uses written into the authorisation document in advance.

Timing matters for the follow-up as well. The group that submitted credentials goes first, ideally within two weeks of the drill closing, while the memory is fresh. Retest the same group three to six months later and compare the movement. That comparison is far more use than benchmarking yourself against an industry average.

7. Authorisation, personal data, frequency and budget

This kind of exercise sits in a sensitive place, so the boundaries need drawing first and they need drawing on paper. The written authorisation is signed by someone who can commit the organisation, and one line saying "we agree to the test" is not enough.

Five things the authorisation has to pin down

  • Who is in scope. Company-issued mailboxes only. Not personal addresses, not partner companies, not customers.
  • The window and the scenario types. So nobody argues afterwards over whether a particular message was part of the drill.
  • Which fields get collected. Under the minimum collection principle in Taiwan's Personal Data Protection Act, keep personal data to the minimum the metrics require, and have the simulated login page store no password contents.
  • Retention and deletion. How long raw records are held, who deletes them, and how deletion is confirmed.
  • Ownership of results. All measurements and raw records belong to the commissioning organisation.

On cadence, run a baseline drill first, then repeat quarterly or half-yearly, adjusting difficulty gradually so the figures stay comparable. The first set of numbers is usually poor. That is not a bad outcome, that is the baseline.

On budget, a social engineering drill starts at NT$30,000 for up to 300 people, covering scenario design, sending, measurement, the report and one session to present the results. Larger populations, multilingual scenarios, or work that pairs the drill with a physical exercise are quoted separately.

Whether your staff would click that message today is a measurable number, and once you have measured it you know which department the training should start with. Run one baseline drill, get the breakdown by department and grade, and you have something far more useful than another all-hands session. The condition is that the process is run cleanly: written authorisation, a scope that is stuck to, and results used to plan training.

Common questions

Do employees have to be told about a phishing simulation in advance?
The policy should be announced in advance, so staff know the company runs these and that results are used to arrange training. The specific timing and scenarios are not announced, otherwise the reactions you measure stop meaning anything. That split keeps the exercise transparent while keeping the data honest, and it is the easier position to defend in any discussion with staff or their representatives.
Does the drill collect employee passwords?
The simulated login page can be set to record only the fact that a form was submitted, without keeping what was typed. Write that into the authorisation document and the technical specification before anyone is engaged, and confirm it on both sides. Every record collected belongs to the commissioning organisation and is deleted at the end of the agreed retention period.
We only have twenty or thirty staff. Is a phishing drill worth it?
Yes, but the focus shifts. With small numbers the rates carry little statistical weight, so the value moves to finding the gaps in the process, for example a change of bank details with no second person checking it, or no channel for reporting a suspicious message at all. A small organisation is usually covered by one drill plus one debrief session, and the cost is far below what handling an actual incident runs to.

Read next