Dev.to
7/5/2026

Your Phishing Simulation Score Is 99%. Here's Why That Worries Me.
Short summary
Phishing simulations show 1.5% click rates after years of training—unchanged by training. The problem: simulations are known tests, and attackers study the same compliance frameworks (NIST, ISO 27001) that organizations follow. Real breaches succeed through attacks that look nothing like simulations—voice phishing (+442%), social engineering, configuration errors—exploiting gaps between tools that each assume another layer checked the boundary.
- •Verizon DBIR: phishing simulation training shows zero correlation with reduced click rates
- •Attackers study public compliance frameworks (NIST, CIS, ISO 27001) and exploit assumed trust patterns
- •Real breaches (EtherRAT, Coinbase, Blue Shield) use attacks simulations don't train for—social engineering, voice phishing (+442% surge), configuration drift
Generated with AI, which can make mistakes.
Is this a good recommendation for you?



