You can tell your employees a hundred times not to click on suspicious links. It helps, a little. But research consistently shows that employees who receive only information forget most of it within weeks. What actually changes behavior is experiencing it firsthand. That is precisely what phishing simulation does.

What is a phishing simulation?

A phishing simulation is a controlled, fake phishing campaign, sent by you to your own employees. In collaboration with your IT partner or through a specialized platform, you send emails that look suspicious: a fake package notification, a "your password expires soon" message, or an apparently internal message from management.

Employees who click the link in the fake email are not sent to a malicious site. They are sent to an internal page that tells them they just participated in a security test and shows them exactly what they should have noticed. Immediate, contextual learning.

Why awareness training alone is not enough

Research has documented this: knowledge and behavior are two different things. An employee may well know that phishing emails exist and still click, because they are busy, because the email looks convincing, or because they are acting on autopilot.

Simulation breaks the autopilot. It creates a personal experience, "I clicked," which is far more effective than a PowerPoint presentation. Studies from KnowBe4 and Proofpoint show that companies running regular simulations reduce click rates from typically 30–40% to under 5% over 12 months.

Important: Simulation should never be used as a tool to punish or shame employees. It should be used to teach. An employee who clicks is not stupid, just human. The culture around simulation is decisive for whether it works.

How it works in practice

  1. Choose a platform: KnowBe4, Proofpoint, Cofense or Microsoft Attack Simulator (included in Microsoft 365 Defender) are all well suited for SMBs.
  2. Conduct a baseline test: send a first simulation without prior warning. Measure the click rate. That gives you your starting point.
  3. Run training modules: employees who click go through a short, contextual learning module. 3–5 minutes, not an hour-long course.
  4. Repeat regularly: run simulations 4–6 times a year. Vary the difficulty and type.
  5. Measure progress: compare click rates over time. Use the figures in your security reporting.

What does it cost?

A platform like KnowBe4 typically costs 15–30 DKK per user per month depending on license tiers and organization size. For a company with 20 employees, that is 3,000–7,200 DKK per year, and it typically includes a complete library of simulated phishing templates, training videos, and reporting.

Compare that to the cost of one successful phishing attack, and the math is not hard to do.