# Phishing simulation

**What is the point of a phishing simulation?**

In a phishing simulation you send harmless test emails, announced to the workforce but without naming the moment. It shows you how your business actually reacts.

The most important number is not how many people clicked. The most important number is how many reported the message, and how quickly. A click is human. A report within minutes gives you the chance to contain the damage.

A simulation is a means of learning. It is not suited to exposing individual employees. Anyone who fears consequences reports a genuine incident late or not at all, and that is exactly what worsens your position.

Mind the legal frame. An evaluation that traces back to individuals is a form of monitoring behaviour. Evaluate in aggregate and involve any staff representation beforehand.

## Related terms
- [Phishing](https://vetosec.at/en/it-security/phishing/)
- [Security awareness training](https://vetosec.at/en/it-security/awareness-schulung/)
- [Social engineering](https://vetosec.at/en/it-security/social-engineering/)
- [CEO fraud and invoice fraud](https://vetosec.at/en/it-security/ceo-fraud/)

## Source
https://vetosec.at/en/it-security/phishing-simulation/ (vetosec, pruefung)
