Small businesses face phishing as the top cyber-attack vector across every jurisdiction — NCSC, CISA, and NIST all point to phishing simulation training as a core control. This guide covers the enterprise platforms (KnowBe4, Proofpoint, Hoxhunt), free alternatives (Gophish, King Phisher), what compliant simulation actually looks like, click-rate interpretation, GDPR/CCPA/DPDP compliance, and how a 5-15 person business runs a first simulation this quarter.
Authoritative sources across jurisdictions align on phishing as the top cyber-attack vector: NCSC (UK National Cyber Security Centre), CISA (US Cybersecurity and Infrastructure Security Agency), NIST (National Institute of Standards and Technology, US), ENISA (European Union Agency for Cybersecurity), Verizon Data Breach Investigations Report, and the Australian Cyber Security Centre all consistently identify phishing as the initial-access vector in a majority of successful attacks against organisations of every size.
NCSC 10 Steps to Cyber Security — the UK government's foundation framework for organisational cyber security. Step 8 (Threat Intelligence) and the Awareness element in Step 4 (User Education and Awareness) directly reference phishing simulation as a recommended control. NCSC's Cyber Essentials scheme (basic certification for UK organisations) requires user access management, malware protection, patch management, secure configuration, and firewall/gateway — phishing simulation training complements these technical controls with a human-layer defence.
CISA Cyber Essentials — the US equivalent starting-point framework. Multiple elements reference phishing awareness training, incident reporting culture, and testing. CISA also publishes free phishing awareness resources and a Phishing Guidance document accessible at cisa.gov.
NIST Cybersecurity Framework (CSF) 2.0 — the widely-adopted risk-based framework. The Protect (PR) function includes PR.AT (Awareness and Training) as a category with subcategories for role-based training and testing. Phishing simulation directly maps into PR.AT-01 through PR.AT-05 outcomes.
Why simulation, not just training. Awareness training without simulation is materially less effective at behaviour change — employees complete slides or videos, click 'I understand', and continue with previous behaviour under real conditions. Simulation exposes employees to controlled phishing attempts in the actual work environment, measures actual click-behaviour, and provides just-in-time training for those who click. Multiple longitudinal studies (KnowBe4 baseline reports, ProofPoint annual State of the Phish, industry academic research) demonstrate that click rates drop materially over 12-24 months of consistent simulation programme.
Small business specificity. Enterprise organisations run large security teams with sophisticated simulation infrastructure. Small businesses (5-100 employees) typically have no dedicated security team, use general-purpose IT (Google Workspace, Microsoft 365, occasional MSP support), and have no simulation budget. Phishing simulation for small business needs different tooling, cadence, and interpretation than enterprise programmes — the frameworks (NCSC, CISA, NIST) apply universally, but the operationalisation is size-appropriate.
Phishing simulation is a controlled programme where the organisation sends simulated phishing emails (crafted to look like real phishing attempts) to its own employees on a defined cadence, tracks which employees click through, reports at scale, and provides just-in-time training to those who click.
Simulation email design. Simulated phishing emails cover the range of real-world phishing patterns: fake password-reset requests, fake invoice or delivery notifications, fake HR communications (payroll change, benefits update), fake IT communications (mailbox quota, security alert), fake vendor communications (Microsoft, Google, Adobe, DocuSign, Dropbox), fake executive impersonation (CEO fraud / business email compromise). Content library of a mature simulation platform (KnowBe4, Proofpoint) includes hundreds of templates across languages and industries with periodic updates reflecting real attack trends.
Click tracking. When a simulated email is sent, links in the email point to the simulation platform's tracker rather than to a real destination. Employees who click are recorded (with timestamp, template, click behaviour); no credentials are captured; no malware is delivered. Employees who report the email as suspicious (via the platform's 'report' button in the email client) are recorded positively. Employees who neither click nor report simply pass the simulation.
Just-in-time training. Employees who click are typically redirected to a short training landing page (1-2 minute video or interactive module) explaining what the specific phishing pattern was, how to recognise it in future, and what to do if they encounter it in the real world. The just-in-time delivery is materially more effective than mass-delivered training because the employee is at the moment of highest teachable engagement — they just made the mistake.
Reporting culture. Beyond individual training, a mature phishing simulation programme builds an organisation-wide reporting culture. Employees who report simulated (or real) phishing to IT/security get positive reinforcement. The 'Phish Alert Button' commonly integrated into Outlook and Gmail lets employees report with one click. Reported real phishing gets investigated and blocked at the email-security layer, protecting the entire organisation from a specific campaign.
Programme cadence. Enterprise programmes typically run monthly or biweekly simulations across the employee base with role-based targeting. Small business programmes can start with quarterly (four simulations per year) to establish baseline and demonstrate value, moving to monthly as the programme matures.
Difference from real phishing tests / penetration testing. Simulation is a training and behaviour-measurement tool. Penetration testing (or red-team engagement) is a security assessment where authorised testers attempt real intrusion including sophisticated phishing. Both have their place — simulation is continuous and behaviour-focused, penetration testing is periodic and security-posture-focused.
KnowBe4. The largest player globally, offering phishing simulation, security awareness training, PhishER (reported-phishing analysis), and adjacent tools. Content library extensively multilingual, template catalogue in the thousands, integration with major email systems (Google Workspace, Microsoft 365). Pricing tiered by seat count and feature bundle — small business tier (SBM) starts materially lower than enterprise but still typically £3-8 per user per month equivalent depending on volume. Acquired by Vista Equity Partners in 2023.
Proofpoint Security Awareness Training (PSAT). Formerly Wombat Security (acquired by Proofpoint 2018). Integrated with Proofpoint's broader email-security suite — attractive for businesses already using Proofpoint email protection. Content library extensive; reporting analytics sophisticated. Pricing enterprise-oriented with limited small business tier.
Hoxhunt. Finland-based; gamification-focused approach with individual and team leaderboards, achievement badges, personalised difficulty progression. Positioned as engagement-first alternative to compliance-focused competitors. Adopted by mid-market to enterprise organisations. Pricing subscription-based per seat.
SoSafe. Germany-based; GDPR-native design (data processing entirely in EU-designated data centres, GDPR-compliant data handling built in rather than bolted on). Attractive for European organisations with strict GDPR posture. Multilingual with strong European-language coverage.
Cofense (formerly PhishMe). US-based; incident-response oriented — includes PhishMe Reporter for employee reporting, Cofense Intelligence for threat context, Cofense Triage for security-team investigation. Attractive for organisations building integrated phishing-response capability.
Mimecast Awareness Training. Email-security-adjacent (Mimecast operates as an email security gateway with awareness training as a companion product). Attractive for Mimecast email-security customers.
Other players. Infosec Institute (IQ), Living Security, CybSafe, MetaCompliance, Terranova (acquired by Fortra), Trend Micro Phish Insight, Barracuda PhishLine, ArmorPoint. Regional players in specific geographies. The market is competitive with product differentiation on content quality, reporting depth, integration breadth, and pricing tier.
Selection criteria for small business. Employee count band that matches vendor tier availability; language coverage matching workforce; integration with your email platform (Google Workspace / Microsoft 365); GDPR / CCPA / DPDP data-processing posture matching your compliance framework; content library refresh cadence; support responsiveness; and honestly, price — a £600/month commercial contract for a 15-person business may exceed the security-programme budget available.
Trial before commit. Most vendors offer trials or evaluation licences — typically 30-60 days — to test integration and content quality before committing. A small business should evaluate 2-3 vendors in parallel over one quarter before selecting.
For small businesses with in-house technical capability (small IT team or a technical founder) and budget constraint, several free and open-source phishing simulation tools are viable alternatives to commercial platforms.
Gophish. Open-source phishing simulation framework available at getgophish.com. Runs on Linux/macOS/Windows; free to use. Provides campaign management, template library (starter set with community additions), landing page hosting, click tracking, and reporting dashboard. Setup requires: server or workstation with Gophish binary; SMTP configuration for sending simulated emails; DNS setup for landing page hosting; email-filter allowlist configuration to ensure simulated emails don't get blocked by the organisation's own email security. Trade-off: powerful and free, but content library is basic (organisation must create or source templates), reporting is functional but less polished than commercial competitors, ongoing programme management is manual.
King Phisher. Open-source phishing campaign framework (github.com/rsmusllp/king-phisher). Similar capabilities to Gophish with different UI and community. Actively developed with regular releases.
MSP-managed self-hosted. A small business can engage an MSP (Managed Service Provider) with security expertise to run a Gophish-based programme on the business's behalf — the MSP handles technical setup, template creation, campaign execution, and reporting. Cost typically less than commercial platform for small volumes; expertise dependency on the MSP.
Splunk Attack Range and Atomic Red Team. Advanced open-source security-testing frameworks that include phishing scenario capabilities. Overkill for basic phishing simulation but relevant for small businesses building broader security-testing capability.
When free tools fit. Small business with in-house Linux/networking skills, budget constraint that rules out commercial platforms, and willingness to invest ongoing time in programme management. Or MSP relationship where the security team runs simulation as part of managed services.
When commercial platforms fit better. Small business without in-house security expertise, where the platform-fee is small relative to the productivity cost of self-running; small business with regulated-industry compliance requirements (HIPAA, PCI DSS, SOC 2) where the vendor's documentation and audit-trail features matter; small business scaling past 20-30 employees where content library refresh and reporting sophistication matter.
Honest advice. Most small businesses that start with free tools end up either abandoning the programme (setup time exceeded expected budget) or migrating to commercial platforms (programme scaled past free-tool convenience). Starting with a lower-tier commercial platform for a small business often produces sustained value that self-hosted does not. The £3-8/user/month for KnowBe4 SBM or similar tier is materially lower than the productivity cost of self-running for a 10-30 person business without dedicated security time.
For a small business running phishing simulation for the first time, a structured four-week programme establishes baseline, delivers initial training value, and produces reportable outcomes.
Week 1 — Preparation and communication. Select the simulation platform (commercial tier or free with capacity). Configure integration with the organisation's email platform (Google Workspace or Microsoft 365 — this includes email-filter allowlist for simulation traffic, DNS setup for landing pages, Phish Alert Button installation if the platform provides one). Prepare an internal communication announcing the phishing simulation programme — critical context: the programme is training, not gotcha; results are aggregated, not individually punitive; employees who click get supportive training, not disciplinary action. Publish a written phishing simulation policy addressing HR, IT, and legal alignment.
Week 2 — Baseline simulation. Send the first simulation to the full employee base. Use a moderate-difficulty template — not the most obvious (which under-tests) and not the most sophisticated (which over-shocks). Track click rate, report rate, and time-to-first-click. Provide just-in-time training to those who click. Do not identify individuals in leadership communications about results — aggregate reporting only.
Week 3 — Analyse and communicate baseline. Review the baseline click rate against industry benchmarks (KnowBe4 publishes baseline click-rate benchmarks in annual reports; ProofPoint State of the Phish provides comparable data). A first-time small business baseline click rate is commonly in the 15-35% range depending on template difficulty, industry, and workforce composition. Report aggregate results to leadership with context: baseline is the starting point, not the achievement; the value comes from trend over the next 12-24 months.
Week 4 — Follow-up simulation. Send a second simulation with a different template. Compare click rate and report rate. Some employees who clicked the first will not click the second (immediate training effect); others will click again (needing ongoing training). Establish the pattern of monthly (or quarterly for very small businesses) simulations going forward.
Beyond week 4 — sustained programme. Monthly simulations with rotating templates (avoid staleness). Track click rate trend line (should decline over 6-12 months as awareness matures). Track report rate trend line (should climb — signals engagement). Track time-to-report (should shorten as employees develop confidence in reporting). Provide role-based targeting once the general programme is mature (higher-difficulty simulations for finance and executive functions given the specific attack patterns they face — BEC, wire fraud, invoice fraud).
Reporting cadence for leadership. Monthly one-page summary: click rate this month, click rate trend, report rate, notable incidents (real phishing detected via reporter), remediation actions taken. Quarterly review with programme adjustments.
Common early-programme mistakes. Punishing individuals who click (destroys reporting culture immediately; nobody wants to admit clicking after they've seen a colleague disciplined). Using templates too obvious for baseline (produces artificially-low click rates that don't build training value). Using templates too sophisticated for baseline (produces shock reactions and pushback against the programme). Publishing individual results (breaches implicit trust and violates data-protection principle of proportionality in most jurisdictions). Stopping the programme after 2-3 months when the initial novelty fades (sustained programme is where trend improvement happens).
Simulation programmes produce two headline metrics: click rate (percentage of recipients who clicked the simulated link) and report rate (percentage who reported the simulated email as suspicious). Both need contextual interpretation to be useful.
Click rate interpretation. The single-simulation click rate depends heavily on template difficulty, template relevance to the recipient (a 'password reset for Microsoft 365' template hits differently for a workforce using Google Workspace), industry-specific context (finance employees see more BEC templates in the wild than software engineers), workforce composition (large percentage of newer employees typically clicks more; deeply-tenured employees who've been through multiple programmes typically click less). Comparing single-simulation click rates across organisations without matching context is misleading.
Click rate trend line. More useful than any single click rate is the trend over 6-12-18-24 months. A mature simulation programme typically shows click rates declining from the 20-30% baseline range to 5-10% range as the programme matures, with occasional spikes when a particularly clever template is used. If click rates are not trending down over 12+ months, the programme has an operational issue (templates too repetitive, training not resonating, employees not engaged with the reporting culture) that needs diagnosis.
Report rate as the leading indicator. Report rate (employees who report the simulated email as suspicious) is a stronger leading indicator of security culture than click rate. A workforce with high report rate is a workforce that will report real phishing when it arrives — protecting the organisation via the email-security team's ability to block campaigns. A workforce with high click rate but zero report rate is disengaged; the click-rate might improve tactically but the underlying security culture is weak. The right target is dropping click rate AND rising report rate simultaneously.
Repeat clickers. A subset of employees click on multiple simulations across the programme. This isn't punishment territory — it's targeted-training territory. Repeat clickers benefit from role-based additional training, one-on-one coaching from the IT/security team member, and potentially adjusted email-security controls (additional filtering for their inbox specifically). Some organisations treat consistent repeat clickers with additional review of role-appropriate access — a finance team member who repeatedly clicks phishing may need additional approval controls on wire-transfer initiation.
What the numbers do not tell you. Simulation click rates do not directly measure real-attack susceptibility — a well-crafted real phishing attack may bypass a workforce that scores well on simulations, and vice versa. Simulation report rates do not directly measure incident-response effectiveness — a workforce that reports well may still lack the technical incident-response processes to act on reports. Simulation programme is one control among several; complementary controls (email security gateway, multi-factor authentication, endpoint detection and response, patch management, backup regime) matter equally.
Reporting to leadership. Frame click rate as directional (declining is the goal) rather than absolute (specific-number targets tempt gaming the programme). Frame report rate as engagement signal. Frame the programme as one layer of defence-in-depth, not the entire security posture. Don't over-claim the programme's value — a simulation programme reduces phishing susceptibility but doesn't eliminate it; other controls remain necessary.
Phishing simulation involves processing personal data of employees (name, work email, click behaviour, sometimes department and role). This is data processing under most data-protection frameworks and requires specific compliance handling.
Lawful basis for processing. Under GDPR Article 6, phishing simulation typically operates under legitimate interest (Article 6(1)(f)) — the organisation's legitimate interest in cybersecurity outweighs individual employee-privacy interest in not being tested, subject to appropriate safeguards. Some organisations rely on legal obligation (specific compliance framework requiring security awareness training) or contract (employment contract implying reasonable security measures). Employee consent is generally not the right basis under GDPR because the employment power imbalance makes 'consent' problematic in this context.
Legitimate Interest Assessment (LIA). For GDPR-scope organisations relying on legitimate interest, a documented Legitimate Interest Assessment covers: purpose of processing (cybersecurity via phishing awareness); necessity (why simulation is needed rather than lighter alternatives); proportionality (aggregate reporting rather than punitive individual reporting; minimum data collection). The LIA is not filed with regulators but is retained for potential DPA inspection.
Data minimisation. Simulation data collection should be minimum necessary for the purpose. Collecting click behaviour is necessary; collecting keystroke behaviour or browsing history is not. Retention should be limited — 12-18 months for aggregate trending, shorter for individual-level data.
Employee notification. GDPR Article 13 requires informing data subjects at collection about the processing. For phishing simulation, this means an initial notice to employees about the programme's existence, purpose, data collected, retention, and rights. This does not compromise the programme — the employee knows the programme exists and simulations will occur, but does not know when specific simulations will happen. This transparency-compatible-with-effectiveness is the standard approach and is broadly considered proportionate.
CCPA / CPRA (California). Employee data is covered under CPRA amendments effective 1 January 2023 (previously partially exempted). Employers must provide notice at collection and respect employee subject-rights requests. Phishing simulation programmes must include employee notification and appropriate handling of subject requests.
DPDP Act 2023 (India). Employee data processing under DPDP requires consent-based framework subject to the specific implementation rules being finalised through MeitY. Employer-employee power dynamic makes pure consent basis problematic; the framework's employment-context provisions will clarify.
Sector-specific frameworks. Healthcare (HIPAA in US, similar in other jurisdictions) — phishing simulation programmes involving PHI handlers need alignment with HIPAA training and workforce-safeguard requirements. Financial services (FCA / SEC / RBI / equivalent) — phishing awareness is typically a regulatory expectation for supervised firms. Legal services — bar association rules may require attention to client-confidentiality preservation during simulation programme design.
Cross-border data flows. Commercial simulation platforms typically process data in specific jurisdictions (KnowBe4 US-based, SoSafe EU-based, Hoxhunt EU-based). Cross-border transfer of employee personal data (EU employees to US-based platform) requires GDPR-compliant transfer mechanism (Standard Contractual Clauses, EU-US Data Privacy Framework certification for participating US organisations). Vendor Data Processing Agreements should cover cross-border transfer safeguards.
Phishing simulation is one control in a layered security stack. Small businesses running only phishing simulation without adjacent controls are exposed; small businesses running technical controls without simulation are exposed to human-layer attacks. The right posture is layered defence.
Foundation controls that every small business needs. Multi-factor authentication (MFA) on all business accounts — Google Workspace, Microsoft 365, business banking, payment gateways, SaaS tools, cloud infrastructure. Endpoint protection on every business device (Windows Defender for Business, Microsoft Defender for Endpoint, CrowdStrike Falcon Go, Bitdefender GravityZone, Sophos Central). Email security gateway (Microsoft 365 Defender for Office 365 for Microsoft-based businesses, Google Workspace Advanced Protection for Google-based, or third-party like Mimecast/Proofpoint/Barracuda for higher assurance). Regular backup with restore testing (Backblaze, iDrive, Wasabi for cloud backup; Veeam or Acronis for local + cloud hybrid). Patch management discipline (Windows Update managed via WSUS or InTune; browser and application updates enforced).
Where phishing simulation fits. After the foundation technical controls are in place, phishing simulation adds the human-layer defence. Simulation without foundation controls is putting a smoke alarm in a house without a fire door — training employees to spot attacks that the technical controls should have blocked. Simulation on top of foundation controls addresses the attacks that technical controls miss (novel phishing, targeted BEC, credential-harvesting URLs not yet in threat intelligence feeds).
Adjacent controls that materially improve outcomes. Password manager deployment (1Password Business, Bitwarden Teams, Dashlane Business) — reduces phishing susceptibility by removing the need for employees to type credentials into forms (autofill doesn't work on lookalike domains). DNS filtering (Cloudflare Gateway, Cisco Umbrella, Quad9) — blocks known malicious domains at the network level regardless of email delivery. Web application firewall for customer-facing apps. Security incident response plan documented and practiced.
Small business security budget. For a 10-30 person small business, a reasonable annual cybersecurity budget is 2-5% of revenue with adjustments up or down for industry risk profile. Phishing simulation platform typically consumes a small portion of this budget; foundation controls (MFA licences, endpoint protection, email security add-on, backup) consume the bulk.
MSP vs in-house vs hybrid. Very small businesses (under 20 employees) typically outsource cybersecurity to an MSP with security specialisation. Mid-sized small businesses (20-100 employees) commonly run a hybrid — MSP for infrastructure and incident-response, in-house designated security lead for awareness programmes and vendor management. Deciding factor is whether internal capability exists to select vendors, evaluate reports, and respond to incidents.
Reference frameworks for small business. UK NCSC 10 Steps and Cyber Essentials. US CISA Cyber Essentials Toolkit. NIST Cybersecurity Framework 2.0 (with the Quick Start Guide for small business). Australian Essential Eight. Following one framework consistently rather than mixing frameworks produces better outcomes than partial-adoption of multiple frameworks.
Data + numbers referenced in this article are sourced from these public documents:
Product page with honest feature list, "not for you if" filter, and live demo for this vertical.
See /for/coaching →BossBot secures WhatsApp Business customer conversations with data-protection discipline built-in.
Explore BossBotNot ready to sign up yet? Try the free demo →