Skip to content

Cybersecurity Business

The 97% Failure Rate: What Custom Phishing Simulations Reveal That Templates Miss

A realistic phishing simulation produced a 97% failure rate because the message looked like a normal internal business request. That is exactly why templates alone are not enough.

Phishing email scam illustration
A 97% failure rate is not just a training result. It is a diagnostic.

The IT director was confident.

His team had been trained. They had seen phishing emails. They knew what to look for. They knew not to click strange links or enter credentials into suspicious pages.

Then the authorized simulation ran.

The failure rate was 97%.

That number is uncomfortable, but it is also useful. It reveals the gap between training familiarity and real-world readiness.

Templates are a good start, but they can create a ceiling

Most organizations start phishing training with templates. That is a good place to begin. Platforms like KnowBe4 make it easy to send simulated phishing emails on a regular cadence. Over time, employees start recognizing the patterns.

That repetition has value. It builds a habit of caution.

But templates can also create a ceiling.

Employees may learn what the training emails look like without learning how to evaluate risk in context. They get better at spotting the obvious and still remain vulnerable to the realistic.

What custom simulations actually test

A good custom simulation does not rely on sloppy mistakes or cartoonish red flags. It tests whether employees can identify an abnormal request when the message looks like it belongs inside the business.

In this case, the campaign was built around a believable internal initiative: a new website and updated sales process. The message explained that the company was moving more of the sales workflow online. Because the site was still in beta, it was password protected. Employees were asked to log in using their normal email credentials.

That is a dangerous kind of request because it does not feel random.

It sounds like a project. It sounds like a process change. It sounds like something a busy employee might reasonably expect from leadership, marketing, sales operations, or IT.

Public information is often enough

The simulation also reflected a reality many organizations underestimate: attackers do not need private information to look convincing.

Public information is often enough.

Names, roles, photos, phone numbers, leadership announcements, charity photos, company events, LinkedIn profiles, Facebook posts, news mentions, and public signatures can all help make a message feel authentic.

Employees were not failing because they were careless or unintelligent. They were failing because the message fit their environment.

A failed simulation is a diagnostic

A 97% failure rate is not just a training result. It is a diagnostic.

It can point to missing technical controls, unclear business processes, weak verification habits, or a culture that rewards speed over caution. It may suggest that employees do not know how new systems are announced, how login requests should work, or how to challenge something that appears to come from leadership.

The response to a failed simulation should not be blame.

Stay Ahead of Technology Risk

Practical, no-jargon insights on cybersecurity, resilience, and IT strategy - built for business leaders, not engineers.

Blame makes employees hide mistakes. Security needs the opposite. It needs fast reporting, psychological safety, and clear escalation paths.

What IT leaders should do next

First, reinforce the principle that employees should never enter company credentials into a new site just because an email tells them to. New tools should have a clear rollout process, trusted access path, and verification channel.

Second, teach out-of-band verification. If a message seems unusual, employees should confirm through a known channel – not by replying to the email or clicking the link inside it.

Third, make reporting easy. A report button, a clear inbox, or a simple internal process reduces friction.

Fourth, customize training around real workflows. Sales teams face different lures than finance teams. Executives face different lures than service teams.

Fifth, measure learning, not embarrassment. The purpose of simulation is not to catch people. It is to uncover where the organization needs better controls, better communication, or better habits.

Custom phishing simulations are powerful because they expose the gap between “we trained them” and “they are prepared.”

Templates are a useful baseline.

But realism is where the real learning happens.

Key Takeaways

  • Template-based phishing training builds a useful baseline, but it can train pattern recognition instead of contextual judgment.
  • Custom simulations reveal whether employees can detect risk when the message resembles a real internal process.
  • A high failure rate should be treated as a diagnostic for controls, communication, and verification habits.
  • Security teams should respond to simulation failures with system improvement, not blame.

FAQ

What do custom phishing simulations reveal?
They reveal whether employees can recognize risky requests when the email looks realistic, internal, and relevant to their work.

Why is a high failure rate useful?
It can diagnose gaps in technical controls, rollout communication, credential practices, reporting habits, and verification culture.

How should IT respond to failed simulations?
IT should improve processes, make reporting easier, train verification behavior, and avoid shaming employees.

Continue the Conversation

Review your awareness program and ask whether it tests real workflows, not just generic phishing templates.