Phishing test for employees: how to run and assess it
Short answer: A phishing test for employees is a safe phishing simulation: employees receive a realistic but harmless email, and you see who clicked the link and who entered their login details. Entered details are the most serious result, and only several tests in a row give a reliable picture, because one test shows behaviour on a single day.
Asked “would our people spot a phishing email?”, most managers guess. Some trust the team; others remember the colleague who once clicked. A phishing test replaces the guess with a number: you send a safe, realistic email and see how employees react on an ordinary working day.
Why a survey does not answer the question
In a quiz almost everyone correctly answers that you should not click a suspicious link. But a real phishing email does not arrive in a quiz. It arrives among twenty other emails, just before a meeting, from a sender who looks familiar. A survey measures what a person knows. A test measures what they do when they are in a hurry. The second is what matters to the company.
A quiz is still useful for learning the signs. In the free phishing quiz, for example, you go through ten emails in five minutes and see after each one what to look for. But it will not show how the same people behave when an email arrives unexpectedly.
How a phishing test works
- You choose an email scenario your employees could genuinely receive: a parcel notice, a password expiry warning, a shared document.
- You send it to the whole team or to selected departments.
- The link in the email leads to a training page. If the page has a login form, entered details are not stored; only the action is recorded.
- An employee who clicks learns that it was a training simulation and gets a short lesson on the signs they missed.
- You see the results: who clicked, who entered details, who finished the lesson.
How to prepare the first simulation is described in detail in What is a phishing simulation and how to run your first.
What to measure: four figures
- Clicked the link
- The main figure. It shows how many people took the email as real and acted on it.
- Entered details
- The most serious result. In a real attack it would mean a stolen password, so track this number separately.
- Finished the lesson
- Shows whether the mistake turned into learning. If employees who clicked do not finish the lesson, the test stayed a check and nothing more.
- Reported it to IT
- The best sign: the person did not fall for it and warned others. If your company has a clear way to report a suspicious email, count how many people used it.
Why open counts are unreliable
An email open is recorded with an invisible image. Many mail apps do not load images by default, while some load them automatically even if nobody opens the email. So opens can be both too low and too high. Draw conclusions from clicks and entered details.
Clicks have a similar problem: some email security systems open links in an email themselves to check them. Ask the vendor whether the platform separates these automatic clicks from people’s actions. Otherwise the report will contain clicks that no employee made.
How to run a test that gives a true result
- Do not announce the date. Tell people in advance that the company runs phishing simulations, but not when or which email you will send.
- Choose a realistic scenario in your employees’ language. Almost everyone spots an email full of machine-translation errors, so such a test tells you nothing.
- Avoid scenarios about salaries, bonuses or health. Emails like these damage trust in management more than they teach anything.
- Compare tests of similar difficulty. If the second email was much easier to spot, a better result does not mean progress.
How to read the results
The first test is a baseline, not a grade: it shows where you start. The real information appears after several tests, when you can see a direction: whether clicks are falling, whether fewer people enter details, whether more finish the lessons.
- Look at departments. If finance clicks more than others, it deserves more attention, because fake invoices reach finance first.
- Look for repeats. An employee who clicks several times in a row needs extra training, not a reprimand.
- Compare with other companies carefully. A market average is only useful if you know its source, year and company size.
What to do after the test
A test without follow-up only confirms the problem. For results to improve, you need three things:
- Lessons straight after the click. That is the moment a person best understands what they missed.
- No punishment. If a click is punished, employees stop reporting mistakes, and in a real attack that is what costs most.
- Regularity. A test every month or quarter, each time with a different scenario, keeps people alert.
Show management not the result of one test but the curve across several: what share of employees clicked, entered details and finished the lesson each time.
How to run a phishing test with Opsinel
Opsinel sends realistic phishing emails in Lithuanian and English. An employee who clicks learns straight away that it was a simulation and gets a lesson of about 15 minutes about that same email. You see each employee’s result, a comparison of departments and how results change from campaign to campaign. Entered passwords are never stored.
In a free account you can send a simulation to yourself and see what an employee would receive. More on how phishing simulations work, what the reports show and what it costs.
Try it yourself
Could you spot a phishing email?
10 realistic emails and an explanation after each answer. About 5 minutes, no sign-up.
Take the phishing quizCan scammers send email in your name?
A free SPF, DKIM and DMARC check of your domain. The domains you enter are not stored.
Frequently asked questions
Can we test employees without warning them?
Do not share the exact date or the content of the email in advance, or the test will show nothing. But it is worth telling the team in general, for example in an internal policy or a meeting, that the company runs phishing simulations for security training. If you are unsure about employment law or data protection requirements, ask a lawyer.
How often should we run a phishing test?
Once a month or once a quarter suits most companies. Rarer tests show only a single moment, while very frequent ones can start to annoy employees.
How many employees click in the first test?
It depends heavily on the scenario. An email about a parcel or an expiring password gets more clicks than a general newsletter. So compare the first result with your own later tests of similar difficulty.
Can a phishing test harm company systems?
No. The training email contains no malicious attachments, and the link leads to a training page. If an employee enters a password there, it is not stored.
What should we do about an employee who clicked several times?
Give them extra training and explain which signs keep recurring in the emails they missed. Punishment does not teach anyone to spot deception; it teaches them to hide mistakes.
Sources and further reading
Public guidance from security agencies and standards bodies.