Why phishing simulations don't reflect how real attacks happen
A phishing simulation teaches people to recognize the simulation, and it almost always arrives by email. Real attacks have moved to SMS, QR codes, chat apps, and the browser. So your click rate can fall quarter after quarter while real-world resilience barely moves.
A phishing simulation is a controlled fake attack. You send employees a test message, see who clicks, and train the ones who fail. It is a useful way to surface risk and give people realistic practice. But there is a gap built into the method, and it is worth naming before you build a whole program on it.
The problem: phishing simulations correct mistakes after the fact
Simulation-based training works backward from failure. The teaching moment is the landing page after a misclick. The feedback comes after the click, not before it. Nothing in that loop teaches someone to recognize a threat in the moment they are deciding whether to act. It records the wrong decision and explains it afterward.

That is a problem on its own. It becomes a bigger one when the test does not look like the threat. Most simulations are email, and they lean on familiar templates: the password reset, the invoice, the shared document. Employees learn the shape of the test. They get better at passing simulations without getting better at handling the messages an attacker actually sends.
Why it matters: the attack surface outgrew the inbox
Real phishing no longer stops at email. Attackers now work across SMS, QR codes, voice calls, and the chat tools people use all day, Teams, Slack, Zendesk, and the rest. These channels often skip the email security stack entirely, and they reach people on mobile, where a small screen hides the usual warning signs.
The numbers back this up. In Verizon's 2026 Data Breach Investigations Report, mobile-centric attacks like voice and text produced median click rates 40% higher than email. And exposure is uneven across a workforce: in their first three months, new hires are far more likely to click a malicious link and to fall for social engineering, which is exactly the population a quarterly email test is slowest to reach.

So when a program is built on email simulations alone, two things happen at once. The test trains people on a channel attackers are moving away from, and it stays silent on the channels they are moving toward. You can tighten the lures and push the email click rate down a point, and a quishing message or a malicious Teams link still walks straight past everything that training built. The dashboard improves. The real exposure does not.
This is why "we run simulations" and "our people are resilient" are not the same statement. A simulation measures behavior on one channel under test conditions. Resilience is how people decide across every channel, on a normal Tuesday, when no one has told them they are being watched.
Cadence makes the gap wider. Most programs run simulated phishing campaigns on a fixed rhythm, once a quarter or once a month, while exposure never pauses. A new hire can spend their entire first quarter, the period when they are most likely to click, without seeing a single test. And between campaigns, the program is blind: a wave of quishing messages in March leaves no trace in a report built on February's email test. The tempo of the test does not match the tempo of the threat, and the people who need practice most wait the longest to get it.
How we build: guidance at the moment of risk, on every channel
If the gap is that simulations correct mistakes after the fact and only on email, then the fix is guidance that reaches people before they act, wherever the message arrives. That is the principle the Phished platform is built on.
The Phished Assistant puts real-time analysis at the point of decision. When an employee is unsure about an email, a link, an attachment, or a QR code, the content opens in an isolated digital silo: a separated environment where nothing can reach your infrastructure even if the link is malicious. Inside that protected space, AI analyzes the content and gives the employee clear, contextual guidance on how to proceed. It works across the channels attackers actually use, not just the inbox, because the moment of risk is not confined to email. That turns an ordinary interaction into a learning moment, and it reaches the people who were merely unsure, not only the ones who already clicked.
Simulations still have a job in this model. They surface risk and create realistic practice, and when you do run them, making them mirror real attacks (across channels, with current lures, not just a recycled invoice template) makes that practice worth more. But practice under test conditions was never going to build resilience on its own, because it only ever describes the mistake after it happens, on one channel, to the people who fail. Reaching everyone, at the moment they are unsure, on whatever channel the threat arrives, is what moves real-world resilience.
"A realistic simulation is good practice. It is not a substitute for guiding someone in the moment they are unsure, on the channel the attack actually uses. Resilience comes from reaching every employee where the risk is, not from a better test."
Jo Vandebergh, CEO, Phished
Frequently asked questions
What is a phishing simulation?
A phishing simulation is a controlled fake attack: a test message is sent to employees to see who clicks, and those who fail receive training. Most simulations are email-based and reuse familiar templates, so employees learn to recognize the test, while real attacks increasingly arrive through SMS (smishing), QR codes (quishing), voice, and chat apps.
What happens if you fail a phishing simulation?
Typically, a short lesson appears after the click. That is the core limitation: feedback lands after the decision, on one channel, and only for the people who failed. Failing a simulation flags risk. It does not, by itself, build the recognition that prevents the next real attack.
Why do employees pass simulations but still get phished?
Because a simulation trains recognition of the simulation and gives feedback only after a click. It does not coach someone in the moment they are deciding whether to trust a message, and it rarely covers the non-email channels where many real attacks now land.
How do you measure the success of a phishing simulation?
Most programs measure click rate, but a falling click rate mainly shows employees learned the test. Better measures are reporting rate, behavior across non-email channels, and how quickly employees flag messages they are unsure about.
What is a realistic phishing simulation?
One that reflects how attackers actually operate today: varied channels beyond email, current lures rather than recycled templates, and difficulty matched to the audience. The goal is practice that teaches recognition, not a test employees simply learn to pass.
See what reaches every channel
See how the Phished Assistant guides employees in the moment, across email, chat, mobile, and the browser, not just the inbox.
Request a demo