Skip to content
Aqvil

Research1 min readPublished Aug 24, 2026

Research 1 min read

The phishing simulation email that got the best (and worst) results

We ran the same simulation across 40 client companies. The results changed how we design every simulation since.

Over eight months we ran the same four phishing simulation templates across 40 client companies, roughly 6,000 employees in total, and tracked click rates by template rather than by company. The results were not what we expected going in.

The template with the highest click rate: an internal IT notice

A plain message claiming to be from internal IT, asking employees to re-confirm their password due to a "security update," had a 31% click rate, the highest of any template we tested. It had no urgency language, no threats, no unusual formatting — the kind of message security training usually says to watch for the absence of red flags on.

The template with the lowest click rate: an urgent CEO request

The classic "urgent wire transfer from the CEO" template, which we expected to perform worst on realism, actually had the lowest click rate at 6%. Employees at these companies had clearly been trained specifically on this pattern, likely from years of security awareness content focused on executive impersonation.

What this told us

Years of training content aimed at the dramatic, high-stakes scenario had made employees good at spotting exactly that scenario, and left them under-prepared for the boring, procedural one. Attackers do not need drama; they need plausibility.

  • We now weight our simulation library toward mundane, procedural pretexts, not urgent or high-stakes ones.

  • Click rate on the "boring" template is now our primary benchmark for a company's real exposure.

  • We re-test the same company on a mix of both categories, because performing well on one says nothing about the other.

Continue exploring

Explore this topic

Cybersecurity

All Cybersecurity content

Related experts