Social engineering defense
Phishing Simulation & Security Awareness Training
Your firewall does not read email. Your people do. iFlock sends your team the same lures real attackers are using right now, measures who takes the bait, and trains them at the moment it happens — so the next one lands on a workforce that already knows the play.
62%
of breaches involve the human element.
Verizon 2026 Data Breach Investigations Report33.2%
average phish-prone rate before any training — one in three employees clicks.
KnowBe4 2026 Phishing by Industry Benchmarking Report4.2%
average phish-prone rate after 12 months of simulation and training.
KnowBe4 2026 Phishing by Industry Benchmarking Report2x
increase in voice-phishing intrusions, first half of 2026 vs. second half of 2025.
CrowdStrike 2026 Threat Hunting ReportThe 2026 picture
Why phishing still works — and what changed this year
Awareness training built on statistics from five years ago trains people for attacks that are no longer being run. Here is what the current data actually says.
It is not just email anymore
Verizon's 2026 DBIR found that 41% of social engineering breaches arrived through something other than email, and that phone-based lures are measurably more effective: a median click rate of roughly 2% for voice and SMS simulations against 1.4% for email. CrowdStrike recorded twice as many voice-phishing intrusions in the first half of 2026 as in the back half of 2025, plus a 15x jump in device-code phishing attempts over six months.
A program that only tests the inbox leaves the two fastest-growing channels untested.
The payload is your password
Microsoft blocked roughly 7.6 billion email-based phishing threats in the second quarter of 2026 alone, and credential theft accounted for 94–96% of payload-based attacks every month of that quarter. Attackers are not trying to drop malware on the endpoint; they are trying to log in as your staff.
That is why phishing defense and identity controls belong in the same conversation — see our managed security program.
The lure keeps changing shape
Through Q2 2026, HTML attachments carried 35–41% of malicious payloads and PDFs another 24–31%. QR-code phishing dropped sharply after a major kit takedown — from 18.7 million attempts in March to 8.3 million in June — while malicious calendar-invite files surged 277% in June.
Lures rotate on a quarterly cycle. Training content that does not rotate with them goes stale fast.
The bill lands on the business
The FBI's 2025 Internet Crime Report logged $20.8 billion in reported losses. Business email compromise alone accounted for $3.04 billion, and reported losses from phishing and spoofing jumped from $70 million to $215.8 million in a single year on roughly flat complaint volume — individual incidents are getting more expensive.
Not sure where you stand? Start with a free security assessment or the two-minute security self-check.
Sources: Verizon 2026 DBIR; KnowBe4 2026 Phishing by Industry Benchmarking Report; Microsoft Security, “Email threat landscape: Q2 2026”; CrowdStrike 2026 Threat Hunting Report; FBI IC3 2025 Internet Crime Report. Figures current as of August 2026.
What you get
What an iFlock phishing program includes
Simulation on its own is a scoreboard. The training attached to it is what moves the number.
Baseline simulation
A first campaign run before anyone is told, so you get an honest phish-prone percentage to measure everything else against.
Current-lure campaigns
Templates built from the tactics in circulation this quarter — credential harvesting pages, HTML and PDF attachments, calendar invites, MFA-fatigue prompts — not last decade's Nigerian prince.
Point-of-failure training
Click the link and you land on a short, specific lesson about the exact cue you missed. Teachable moments beat annual slide decks.
Vishing and smishing tests
Voice and SMS lures, run with the same rules of engagement, because that is where the growth is and where most programs have no data at all.
Reporting drills
We measure how many people report a suspicious message, not just how many click. A workforce that reports in minutes gives your responders a head start.
Metrics leadership can use
Phish-prone rate by department and over time, report rate, repeat clickers, and the trend line — the evidence insurers, auditors and customer questionnaires ask for.
The engagement
How an iFlock phishing campaign runs
Scope and authorize
We agree in writing who is in scope, which channels we will use, the date window, and who your named contact is. One page, signed before anything is sent.
Baseline campaign
A realistic lure goes to the agreed population with no advance warning. We capture opens, clicks, credential submissions and reports.
Train at the moment of failure
Anyone who takes the bait is redirected to a short lesson that walks through the specific tells in the message they just clicked.
Repeat with fresh lures
Campaigns continue on a regular cadence with new tactics and new channels. The published benchmark shows the average phish-prone rate falling from 33.2% to 20.1% within 90 days and to 4.2% at twelve months.
Report and adjust
You get a plain-language report with the trend, the departments that need attention, and what we recommend next — whether that is more training, tighter policy and controls, or a full penetration test that includes social engineering.
Questions
Phishing simulation FAQs
Will this embarrass or punish our employees?
No, and a program that does will fail. Results are reported to leadership in aggregate, and individual follow-up is training, not discipline. The goal is a workforce that reports suspicious messages quickly — people only do that when reporting feels safe.
How often should we run simulations?
Monthly is the pattern that holds gains. The published industry benchmark shows the average phish-prone rate dropping from 33.2% at baseline to 20.1% after 90 days and 4.2% after twelve months of continuous simulation plus training. Annual training alone does not produce that curve.
Do you test phone and text, not just email?
Yes. Verizon's 2026 DBIR put the median click rate on voice and SMS simulations at roughly 2% against 1.4% for email, and CrowdStrike recorded twice as many voice-phishing intrusions in the first half of 2026 as in the second half of 2025. Vishing and smishing are run under the same written authorization as email campaigns.
Is a phishing simulation the same as a penetration test?
No. A phishing campaign measures and trains human susceptibility; it stops at the click. A penetration test attempts actual exploitation and lateral movement with your permission. They complement each other, and many clients run both.
Will this satisfy our cyber insurance or compliance requirement?
Most insurers and frameworks ask for documented, recurring security awareness training with evidence of participation and results — which is exactly what the reporting produces. We can map the output to the framework you are working against; see compliance and risk management and audit readiness.
Can we try something before committing?
Yes. Play Spot the Phish, our free awareness game, or run the two-minute security self-check to see where your controls stand. When you are ready for real data, the free security assessment is the next step.
Find out who would click — before an attacker does
A baseline campaign takes days, not months, and it tells you something no scanner can: how your business actually behaves when someone convincing asks for the keys.
Schedule my consultation Get a free security assessment