With permission, we sent fake phishing emails to employees at small businesses we work with. The click rates were humbling. Here's exactly what we found — and what actually moves the needle.
A few years back, a client called us in a panic. Someone on their team had clicked a link in what looked like a Microsoft email, entered their Office 365 credentials on a convincing login page, and handed an attacker the keys to their entire email account. The attacker sat quietly in that inbox for two weeks, reading emails, learning the business, and eventually used the account to redirect a vendor payment. It cost that client over $40,000.
After helping them clean it up, we started having a different kind of conversation with our clients. Not just "here's your firewall, here's your backup." But: do your employees actually know what a phishing email looks like? And if we tested them right now, how would they do?
So we started testing. With their knowledge and consent, we began running phishing simulations — fake phishing emails sent to real employees — to see how their teams would respond. The results taught us more about human behavior under pressure than we ever expected. Here's what we found.
Let's be clear about what this is: a phishing simulation is a controlled, ethical test. The business owner knows about it. The employees don't — at least not in advance. We send fake phishing emails using professional simulation software, track who clicks, who enters credentials, and who reports it. No real harm is done, but the results are very real.
We've run these with companies ranging from 5 employees to about 80. Professional services firms, retail operations, healthcare-adjacent businesses, construction companies. The common thread: almost none of them had done any kind of security awareness training before we started.
For each test, we designed the phishing emails to mimic the most common real-world attacks we see in the wild. We're not trying to trick people with absurd Nigerian prince emails — we use the same polished, convincing lures that actual attackers use. If it's not realistic, the test isn't useful.
We typically rotate between three categories:
All three work. That's the uncomfortable truth.
Before we ran the first simulation at any given company, we'd ask the business owner to guess their click rate. Most said something like "maybe 5 or 10 percent." A few said "I think our team is pretty savvy, probably under 5."
The first-round results were consistently higher. Across our simulations, the average first-test click rate ran between 25 and 35 percent. One company hit 48 percent — nearly half their employees clicked a fake Microsoft password reset email within 20 minutes of it hitting their inbox.
The credential submission rate — people who not only clicked but actually entered their username and password into the fake login page — averaged around 15 percent on the first round. One in six employees, across a typical small business, was willing to hand over their credentials to a convincing-looking page.
And the reporting rate — employees who forwarded the suspicious email to IT or reported it through any channel — was under 3 percent on average for untrained teams. Most people either clicked or deleted. Almost nobody raised a flag.
This part surprised us the most. We expected to see a pattern — newer employees, older employees, certain departments. What we found instead was that clicking was almost random across roles and tenure. We had a 62-year-old owner click within three minutes. We had a 28-year-old who had worked in tech before miss nothing. We had a bookkeeper who caught every test and an accountant who failed them all.
The only consistent variable? People who had received any prior security training — even informal, even just "hey, watch out for phishing emails" in a staff meeting — performed measurably better. Not perfectly. But better. That held true across every company we tested.
One of the most important things we do after a simulation is sit down with employees who clicked and talk to them about what happened. Not to shame them — that's the fastest way to guarantee nobody admits to clicking in the future. But to understand what was going through their head.
The answers are almost always the same.
"I was busy." They were in the middle of something else. They glanced at the subject line, recognized a familiar brand name, and clicked without really looking. The email arrived during a busy stretch and they processed it on autopilot.
"It looked completely real." Because it did. Modern phishing emails use the actual logos, fonts, and formatting of legitimate services. The "from" name shows as "Microsoft Security" even when the sending address is something completely different — and most people never check the actual address. The linked page looks identical to the real one.
"The subject line created urgency." "Your account will be locked in 24 hours." "Action required: verify your information." Urgency is one of the most effective psychological levers in social engineering. It bypasses deliberate thinking and triggers action. That's by design.
"I thought it might be real, but I didn't want to miss something important." This one is key. People often have a flash of doubt — but then talk themselves into clicking anyway because they're worried about consequences if the email is legitimate. "What if my account really does get locked?"
None of this is stupidity. It's human psychology. Attackers have studied it carefully, and they're very good at exploiting it. The defense isn't finding smarter people — it's building better instincts through repetition and training.
Here's the good news: training works. Not perfectly, and not immediately, but the data from repeated simulations over time is encouraging.
After a structured training program — a combination of initial awareness training, regular short refreshers, and monthly or quarterly simulated phishing tests — we typically see click rates drop from that 25–35% first-round baseline down to the 5–8% range within six months. Credential submission rates usually fall to under 3%. And the reporting rate — employees who flag suspicious emails — tends to climb to 15–25%.
That last number matters a lot. A team that reports suspicious emails gives your IT provider or internal IT person early warning. We've caught real phishing campaigns in the wild because a trained employee forwarded something suspicious before clicking. That's exactly how it's supposed to work.
We've tried a few approaches over the years. Here's what consistently works:
Short, frequent training beats long, annual training. A 45-minute annual cybersecurity training video is largely forgotten within a few weeks. Short 5-10 minute monthly modules that focus on one concept at a time are retained much better. People learn by repetition, not marathon sessions.
Just-in-time education is powerful. When someone fails a simulated phishing test, they should immediately see a brief explanation of what they missed and why it was a phishing email. Not a lecture, not a consequence — just a "here's what you clicked, here's the signs you could have spotted." That teachable moment, right after the failure, is one of the most effective learning opportunities in security training.
Make it specific, not generic. "Be careful about phishing" doesn't help. "Here's what a fake Microsoft password reset email looks like, and here's the three things that gave it away" does help. Use real examples, preferably ones that match the kind of tools your business actually uses.
Build a culture where reporting is celebrated, not stigmatized. If the only time employees hear about phishing is when someone gets in trouble for clicking, they'll hide their mistakes instead of reporting them. Celebrate the reports. Thank the person who forwarded the suspicious email. Make it clear that "I wasn't sure and I flagged it" is the right behavior, not a sign of weakness.
For more on the technical side of what modern attacks look like, see our Cybersecurity Essentials guide — it covers the full picture of what small businesses are up against beyond just phishing.
You don't need to hire us to get started. There are reputable simulation platforms that make it relatively straightforward to run your own tests. Here's what we recommend:
KnowBe4, Proofpoint Security Awareness, and Cofense are the main players. All offer free trials. Most small businesses will find more than enough in the entry-level tiers. These platforms include both simulation tools and the training content library, which is where a lot of the value comes from.
The single biggest predictor of success is whether leadership participates. If the owner or manager is exempt from the tests, or makes it clear they think it's "not for them," the training culture never really takes hold. The best clients we've worked with are the ones where the owner goes through the same training as the receptionist and is honest about what they found hard.
We've seen companies try the "gotcha" approach — naming and shaming employees who click, or tying failures to HR consequences. It doesn't work. It does reliably destroy trust and create a culture where nobody reports anything. Lead with education, not consequences. The goal is a team that reports threats, not one that hides mistakes.
A one-time phishing test tells you where you are. A recurring program — tests every month or quarter, paired with ongoing training — actually changes behavior. Think of it like a fire drill: the first one is awkward and people aren't sure what to do. By the sixth one, it's muscle memory. That's what you're building.
If you already have solid Microsoft 365 security settings and a password manager in place, a phishing simulation program is the logical next layer. The technical controls handle a lot, but the human layer is where most breaches actually start.
Every technical security layer we install — firewalls, email filtering, endpoint protection, MFA — reduces the chances that a phishing email reaches an employee at all. But some will always get through. Attackers are creative, and filters aren't perfect.
When that happens, your employee is the last line of defense. The question is: are they ready?
The companies we work with that have invested in ongoing security awareness training sleep better at night. Not because their employees are perfect — they're not, nobody is. But because their teams know what to look for, know who to call when something looks off, and have built the habit of slowing down for half a second before clicking.
That half-second habit is worth more than most of the security tools we sell.
If you want to know how your team would do right now, we're happy to set up a no-pressure phishing simulation with you. We'll send the emails, track the results, debrief with you honestly, and help you figure out what kind of training makes sense from there. No obligation, no hard sell. Just data you can actually use.