CONTACT

Phishing Simulations for UK Businesses: How They Work and What They Cost

phishing simulation

A phishing simulation is a fake phishing email your organisation sends to its own staff, to find out who clicks, who reports it, and where the gaps sit. It measures behaviour rather than teaching it. That distinction matters, because a test on its own changes nothing, and the way most providers sell these quietly ignores it.

The case for running one is not subtle. The government’s Cyber Security Breaches Survey found phishing remained the most prevalent type of breach or attack by far, experienced by 38% of businesses. In the same survey, only 19% of businesses had provided any form of staff training. Twice as many are being attacked as are being prepared.

The NCSC is blunt about this: since nobody can be expected to spot every phishing email, punishing people for clicking one you sent them starts to resemble entrapment.

What Is a Phishing Simulation?

A controlled, consented test. Someone, usually your provider, sends a harmless email designed to look like a real phishing attempt. The platform records who opened it, who clicked the link, who entered credentials on the fake page, and, most usefully, who reported it. Nobody is actually compromised.

The point is the report, not the catch. A test that produces a click rate and nothing else has told you one number. A useful one tells you which departments are exposed, which lures work on your people specifically, and whether anyone followed the reporting process you think exists.

It is not the same as training, and the two get sold as one thing. Training teaches. A simulation measures. Transputec covers the teaching side separately in our post on security awareness training, and the honest sequence is usually train first, then test, rather than the other way round.

How Does a Phishing Simulation Actually Work?

Four stages, and the last one is where most programmes fall down. You agree the scope and the lures. The platform sends to a defined group, usually staggered over days so nobody warns the next desk. It records opens, clicks, credential entry and reports. Then somebody has to do something with what came back.

Scoping is where to spend your attention. A lure impersonating your actual payroll provider will beat a generic parcel-delivery template every time, which is useful to know and uncomfortable to run. Agree in advance what is off limits: fake redundancy notices and fake bonus emails generate spectacular click rates and lasting resentment.

The reporting step is the one that matters. If your staff have a report button and a process behind it, the simulation tests that process as well as the people. If they do not, the exercise measures clicking and nothing else, which is half a test.

Transputec runs simulations two ways: as a feature of ThreatSpike, and through Mimecast awareness training and human risk management, where the microlearning that follows is targeted by each user’s risk score rather than sent to everyone.

Want to Know Where Your Real Gaps Are?

Transputec delivers phishing simulations through ThreatSpike and through Mimecast awareness training and human risk management, with microlearning targeted by each user's risk score and dashboards that show whether behaviour actually changed. That is the difference between a click rate and a programme. Talk to our team about the security work behind your phishing numbers.

Get a Strategic Consultation

What Does a Phishing Simulation Cost in the UK?

It is priced per user per year, almost always bundled with awareness training rather than sold alone. There is no published UK benchmark, and the range quoted online is too wide to be useful, so the honest answer is to compare what you are buying rather than the headline figure. Three things move the price.

What you buyWhat it includesWho it suits
Self-serve platformTemplates, scheduling, a dashboard. You scope it, send it and interpret it.An in-house security or IT team with time to run the programme
Simulation bundled with trainingThe above plus awareness modules, often assigned automatically to people who clickMost mid-sized businesses, and the usual starting point
Managed programmeSomeone else scopes the lures, runs the schedule, interprets the results and reports to the boardBusinesses with no internal owner, or a regulator or insurer asking for evidence

Beyond the tier, the drivers are user count, how often you run it, and whether anyone is paid to think about the results. The third is the one people cut, and it is the one that makes the difference between a programme and a line item.

Worth saying plainly: if the budget only stretches to one thing, buy the training. A test with no training behind it produces a number nobody can act on.

What the NCSC Says About Phishing Simulations

The UK’s national cyber authority is more sceptical than most providers will tell you. Its guidance on defending against phishing is blunt that blaming users for clicking does not work, because people click for reasons including being busy or stressed, and threatening punishment does not change that.

Two of its points are worth reading before you buy anything. No training package, phishing simulations included, can teach users to spot every attempt, and expecting that is unrealistic because examining every email in depth leaves no hours for the actual job. And since nobody can spot them all, punishing people for clicking an email you sent them starts to look like entrapment.

The consequence is practical rather than philosophical. Employees who are afraid for their jobs will not report mistakes, and reporting is the thing you actually want, because staff who report are a valuable early warning system. A programme that drives the click rate down while driving the report rate down with it has made you less safe, not more.

The NCSC also offers a genuinely good alternative worth stealing: ask staff to craft their own phishing emails. It teaches the influence techniques from the inside, and a friendly competition between teams avoids the us-and-them dynamic that simulations create when handled badly.

How Often Should You Run One?

Quarterly suits most businesses, with the first one treated as a baseline rather than a result. Monthly is usually too often: staff start warning each other, the exercise becomes a game, and you measure gossip rather than susceptibility. Annually is too rare to show whether anything you changed actually worked.

Vary the difficulty rather than the frequency. A generic lure and a tailored one aimed at your finance team measure completely different things, and running the easy one four times a year produces a flattering chart and no insight.

Tie the schedule to changes rather than to the calendar where you can. A wave of new starters, a move to a new finance system, or an acquisition all shift your exposure more than three months of nothing happening does.

What Should Happen When Someone Clicks?

Short training, delivered immediately, and nothing else. No name on a list, no email to their manager, no league table. The person who clicked has just demonstrated the exact gap the exercise was designed to find, and the response decides whether they tell you next time something looks wrong.

Report the aggregate, not the individuals. A board wants to know whether the click rate moved and whether the report rate moved with it. It does not need names, and circulating them converts a security exercise into a performance issue.

Measure the report rate as the headline number. Click rate going down is pleasant. Report rate going up is the one that shortens the time between an attack landing and somebody noticing, and it is the number that predicts how a real incident will go. When one does get through, the response is a separate discipline, covered in our post on the phishing playbook.

And treat repeat clickers as a scoping problem rather than a people problem. If the same team keeps failing, the lure is probably indistinguishable from their actual daily email, which is information about your processes rather than about them.

What Should the Report Tell You?

Four numbers and one list. Click rate, report rate, time to first report, and the proportion who did nothing at all. Then a breakdown by team, because an organisation-wide average hides the department that will actually be targeted. Anything beyond that is usually dashboard decoration.

Time to first report is the one most providers bury. It is the gap between the email landing and somebody raising a hand, and in a real incident it is the number that decides how much damage happens. A programme that improves it has done something measurable.

The people who did nothing deserve their own line. They did not click, which looks like a pass, but they did not report either, which means a real attack would have sat in their inbox unflagged. That group is usually the largest and the least discussed.

Ask to see a sample report before you sign anything. If it leads with a league table of individuals, you are looking at a product built to produce blame rather than information.

Your Checklist Before You Commission One

Work through these before you commission one.

  • Train before you test, so the exercise measures whether the training landed.
  • Agree in writing what is off limits. Redundancy, bonuses and anything about pay.
  • Check staff have a report button, and that somebody actually receives what it sends.
  • Decide who sees individual names before the first send, not after the results arrive.
  • Treat round one as a baseline and say so internally before it goes out.
  • Ask the provider for a sample report and look at what it leads with.
  • Agree who interprets the results and who takes them to the board.

Conclusion

A phishing simulation is worth running, and worth running properly. It measures who clicks and who reports, it is priced per user per year and usually bundled with training, and quarterly suits most UK businesses. None of that is complicated.

What decides whether it works is the response. Run it to find gaps and the reporting culture improves. Run it to catch people out and, as the NCSC puts it, staff who are afraid stop telling you things. Transputec delivers simulations through ThreatSpike and Mimecast, with the training that makes the numbers mean something. Talk to us about the security work behind your phishing numbers.

FAQs

There is no published benchmark. It is priced per user per year and almost always bundled with awareness training rather than sold on its own. The variables are how many users, how often you run it, and whether you are buying a platform to run yourself or a managed programme where somebody else scopes the lures and interprets the results.

Quarterly works for most businesses. Monthly is counterproductive because staff warn each other and you end up measuring gossip. Annually is too infrequent to show whether a change worked. Vary the difficulty between rounds rather than running the same easy lure four times a year.

Short training straight away, and nothing punitive. No names to managers, no league tables. The NCSC is explicit that blaming users does not work and that employees who are afraid for their jobs will not report mistakes, which costs you the early warning that makes reporting valuable.

No. A simulation measures behaviour; training changes it. They are usually sold together and the sensible order is to train first and test afterwards, so the test shows whether the training landed rather than simply confirming that untrained people click links.

Only when paired with training and a reporting process. On their own they produce a click rate and no mechanism for change. The number worth watching is the report rate rather than the click rate, because it predicts how quickly a real attack gets noticed.

This article was drafted with AI assistance and reviewed by the Transputec team. Featured image: AI-generated.

Ready to experience the Transputec difference?

Turn IT headaches into operational strength. Book a free consultation and see exactly what we can streamline inside your business. 

Get a Strategic Consultation
Sonny Sehgal

Sonny Sehgal

CEO & Co-Founder

Since co-founding Transputec, Sonny has guided hundreds of enterprises through every major shift in technology- from the birth of the PC to the rise of Global Cloud and now Generative AI. Known for his "straight-talking" approach to cyber security and IT strategy, he provides the bridge between complex technical infrastructure and boardroom-level business outcomes.

Share Blog »

← Blogs

Contact

Get in Touch