Social engineering defense

Phishing Simulation & Security Awareness Training

Your firewall does not read email. Your people do. iFlock sends your team the same lures real attackers are using right now, measures who takes the bait, and trains them at the moment it happens — so the next one lands on a workforce that already knows the play.

Email simulation Vishing & smishing Point-of-failure training Reporting drills Board-ready metrics

62%

of breaches involve the human element.

Verizon 2026 Data Breach Investigations Report

33.2%

average phish-prone rate before any training — one in three employees clicks.

KnowBe4 2026 Phishing by Industry Benchmarking Report

4.2%

average phish-prone rate after 12 months of simulation and training.

KnowBe4 2026 Phishing by Industry Benchmarking Report

2x

increase in voice-phishing intrusions, first half of 2026 vs. second half of 2025.

CrowdStrike 2026 Threat Hunting Report

The 2026 picture

Why phishing still works — and what changed this year

Awareness training built on statistics from five years ago trains people for attacks that are no longer being run. Here is what the current data actually says.

It is not just email anymore

Verizon's 2026 DBIR found that 41% of social engineering breaches arrived through something other than email, and that phone-based lures are measurably more effective: a median click rate of roughly 2% for voice and SMS simulations against 1.4% for email. CrowdStrike recorded twice as many voice-phishing intrusions in the first half of 2026 as in the back half of 2025, plus a 15x jump in device-code phishing attempts over six months.

A program that only tests the inbox leaves the two fastest-growing channels untested.

The payload is your password

Microsoft blocked roughly 7.6 billion email-based phishing threats in the second quarter of 2026 alone, and credential theft accounted for 94–96% of payload-based attacks every month of that quarter. Attackers are not trying to drop malware on the endpoint; they are trying to log in as your staff.

That is why phishing defense and identity controls belong in the same conversation — see our managed security program.

The lure keeps changing shape

Through Q2 2026, HTML attachments carried 35–41% of malicious payloads and PDFs another 24–31%. QR-code phishing dropped sharply after a major kit takedown — from 18.7 million attempts in March to 8.3 million in June — while malicious calendar-invite files surged 277% in June.

Lures rotate on a quarterly cycle. Training content that does not rotate with them goes stale fast.

The bill lands on the business

The FBI's 2025 Internet Crime Report logged $20.8 billion in reported losses. Business email compromise alone accounted for $3.04 billion, and reported losses from phishing and spoofing jumped from $70 million to $215.8 million in a single year on roughly flat complaint volume — individual incidents are getting more expensive.

Not sure where you stand? Start with a free security assessment or the two-minute security self-check.

Sources: Verizon 2026 DBIR; KnowBe4 2026 Phishing by Industry Benchmarking Report; Microsoft Security, “Email threat landscape: Q2 2026”; CrowdStrike 2026 Threat Hunting Report; FBI IC3 2025 Internet Crime Report. Figures current as of August 2026.

What you get

What an iFlock phishing program includes

Simulation on its own is a scoreboard. The training attached to it is what moves the number.

Baseline simulation

A first campaign run before anyone is told, so you get an honest phish-prone percentage to measure everything else against.

Current-lure campaigns

Templates built from the tactics in circulation this quarter — credential harvesting pages, HTML and PDF attachments, calendar invites, MFA-fatigue prompts — not last decade's Nigerian prince.

Point-of-failure training

Click the link and you land on a short, specific lesson about the exact cue you missed. Teachable moments beat annual slide decks.

Vishing and smishing tests

Voice and SMS lures, run with the same rules of engagement, because that is where the growth is and where most programs have no data at all.

Reporting drills

We measure how many people report a suspicious message, not just how many click. A workforce that reports in minutes gives your responders a head start.

Metrics leadership can use

Phish-prone rate by department and over time, report rate, repeat clickers, and the trend line — the evidence insurers, auditors and customer questionnaires ask for.

The engagement

How an iFlock phishing campaign runs

1

Scope and authorize

We agree in writing who is in scope, which channels we will use, the date window, and who your named contact is. One page, signed before anything is sent.

2

Baseline campaign

A realistic lure goes to the agreed population with no advance warning. We capture opens, clicks, credential submissions and reports.

3

Train at the moment of failure

Anyone who takes the bait is redirected to a short lesson that walks through the specific tells in the message they just clicked.

4

Repeat with fresh lures

Campaigns continue on a regular cadence with new tactics and new channels. The published benchmark shows the average phish-prone rate falling from 33.2% to 20.1% within 90 days and to 4.2% at twelve months.

5

Report and adjust

You get a plain-language report with the trend, the departments that need attention, and what we recommend next — whether that is more training, tighter policy and controls, or a full penetration test that includes social engineering.

Questions

Phishing simulation FAQs

Will this embarrass or punish our employees?

No, and a program that does will fail. Results are reported to leadership in aggregate, and individual follow-up is training, not discipline. The goal is a workforce that reports suspicious messages quickly — people only do that when reporting feels safe.

How often should we run simulations?

Monthly is the pattern that holds gains. The published industry benchmark shows the average phish-prone rate dropping from 33.2% at baseline to 20.1% after 90 days and 4.2% after twelve months of continuous simulation plus training. Annual training alone does not produce that curve.

Do you test phone and text, not just email?

Yes. Verizon's 2026 DBIR put the median click rate on voice and SMS simulations at roughly 2% against 1.4% for email, and CrowdStrike recorded twice as many voice-phishing intrusions in the first half of 2026 as in the second half of 2025. Vishing and smishing are run under the same written authorization as email campaigns.

Is a phishing simulation the same as a penetration test?

No. A phishing campaign measures and trains human susceptibility; it stops at the click. A penetration test attempts actual exploitation and lateral movement with your permission. They complement each other, and many clients run both.

Will this satisfy our cyber insurance or compliance requirement?

Most insurers and frameworks ask for documented, recurring security awareness training with evidence of participation and results — which is exactly what the reporting produces. We can map the output to the framework you are working against; see compliance and risk management and audit readiness.

Can we try something before committing?

Yes. Play Spot the Phish, our free awareness game, or run the two-minute security self-check to see where your controls stand. When you are ready for real data, the free security assessment is the next step.

Find out who would click — before an attacker does

A baseline campaign takes days, not months, and it tells you something no scanner can: how your business actually behaves when someone convincing asks for the keys.

Schedule my consultation Get a free security assessment