Cybersecurity

Anti-Phishing Testing for London Firms: Does It Work?

Anti-phishing testing cuts phishing risk for London businesses — but only the NCSC way, without a blame culture. What works, how often to test, and what it costs.

N

Nerdster Team

15 July 2026

Anti-phishing testing — sending staff safe, simulated phishing emails to measure and improve how they respond — does reduce risk, but only when it is run the way the National Cyber Security Centre (NCSC) recommends: as one part of a layered defence, and without punishing people who click. Done as a blame exercise, it can backfire and even create legal risk. This guide explains what phishing simulation testing is, whether it works, and how a London business should actually run it.

The reason to bother is simple. In the government’s Cyber Security Breaches Survey 2025/2026 (fieldwork August–December 2025), 38% of all UK businesses experienced a phishing attack, and phishing was rated the single most disruptive type of breach or attack by 69% of the businesses and charities that were hit. It is the most common threat your staff will face, and it is the one most likely to cause real damage.

What Is Anti-Phishing Testing?

Anti-phishing testing, also called phishing simulation, is a controlled exercise in which your IT or security provider sends realistic but harmless fake phishing emails to your employees. Nobody’s data is at risk. The point is to measure how many people click a link, enter credentials, or open an attachment — and, just as importantly, how many report the email.

A good programme is not a one-off “gotcha”. It combines three things:

  • Simulated phishing emails that mirror the tactics real attackers use against your sector.
  • Short, targeted training delivered at the moment someone interacts with a simulation, and repeated over time.
  • A simple reporting mechanism — usually a “Report Phishing” button in Outlook or Microsoft 365 — so staff can flag suspicious mail in one click.

The output is a baseline you can improve on: your click rate, your report rate, and which teams or roles need extra support.

Does Phishing Simulation Testing Actually Work?

Yes, with an important caveat. The NCSC is candid that “no training package, including phishing simulations, can teach users to spot every phishing attempt.” Attacks are increasingly convincing — including AI voice-cloning and vishing calls that go well beyond the classic dodgy email. So the goal of testing is not a zero per cent click rate, which is unrealistic and counter-productive to chase.

What testing does achieve is threefold: it builds a habit of pausing before acting, it dramatically increases the number of genuine phishing emails your staff report (which is what actually protects you), and it gives you evidence of where your human risk concentrates. The NCSC’s clearest instruction is to “widen your defences to include technical measures, with user education being just one aspect.” Testing tells you how well the human layer is holding; it does not replace the technical layers underneath it.

The One Thing Most Firms Get Wrong: Blame

The fastest way to make anti-phishing testing worthless is to name, shame, or discipline the people who click. The NCSC is emphatic: “Don’t reprimand users who are struggling to recognise phishing emails. Users who fear reprisals will not report mistakes promptly, if at all.” It goes further, warning that punishing people for clicking can even create legal risk, because no one can reliably detect every phishing email.

The practical rule for London firms: reassure first. Tell staff plainly that they will never get in trouble for reporting something — including reporting after they have already clicked. A report five minutes after a click still lets your provider contain the incident. A silence because someone was scared of a telling-off is how a single click becomes a breach.

How to Run an Effective Programme

Here is a straightforward approach that follows NCSC guidance:

  1. Set a baseline. Run an initial simulation across the whole organisation to measure current click and report rates. Do not announce the exact date — but do tell staff in advance that simulations happen, so it never feels like a trap.
  2. Deploy a one-click report button. Make reporting “clear, simple and quick to use”, in the NCSC’s words. In Microsoft 365 this is the built-in Report Phishing add-in.
  3. Train at the teachable moment. When someone clicks a simulation, show a short, friendly explainer of the tell-tale signs — not a warning notice. Keep annual e-learning short; long modules do not change behaviour.
  4. Target higher-risk roles. Staff who handle payments, sensitive data or IT administration should get extra, tailored support. Finance and executive-assistant roles are the ones criminals research and impersonate.
  5. Measure the report rate, not just the click rate. Rising reporting is the real sign of a maturing security culture.
  6. Layer the technical defences. Enforce multi-factor authentication everywhere (a requirement under Cyber Essentials v3.3), filter mail at the gateway, and separate privileged accounts. These are also the controls that cyber insurers reward with lower premiums.

How Often Should You Test?

For most SMEs, a monthly or six-weekly cadence of short simulations keeps awareness fresh without fatiguing staff, paired with brief refresher training each quarter. Testing once a year is largely pointless — the lesson has faded long before the next email arrives. Higher-risk sectors such as financial services and professional firms often test more frequently and with more sophisticated scenarios.

What Does It Cost?

Anti-phishing testing is usually priced per user per month, and for London SMEs it typically sits in the low single-digit pounds per user, per month — often bundled into a managed security or awareness-training package rather than bought standalone. That is a modest number set against the disruption phishing causes: it remains the most common attack UK businesses face, part of the picture behind roughly 612,000 UK businesses identifying a breach or attack in the last year. The bigger cost is almost always not testing.

Frequently Asked Questions

What is anti-phishing testing?

Anti-phishing testing, or phishing simulation, is a controlled exercise where your IT provider sends staff realistic but harmless fake phishing emails to measure how they respond, then delivers short training to improve awareness and reporting. No real data is ever at risk.

Does phishing simulation actually reduce risk?

Yes, when run correctly. The NCSC notes that no simulation can teach users to spot every phishing attempt, so it should sit alongside technical defences such as multi-factor authentication and mail filtering. Its real value is building a reporting habit and showing where your human risk sits — not chasing a zero per cent click rate.

Should you punish employees who fail a phishing test?

No. The NCSC advises against reprimanding users who click, warning that a blame culture stops people reporting mistakes and can even create legal risk. Reassure staff they will never be in trouble for reporting — even after a click.

How often should a business run phishing simulations?

For most London SMEs, monthly or six-weekly short simulations with quarterly refresher training works well. Annual-only testing is largely ineffective because the lesson fades. Higher-risk firms in finance and professional services usually test more often.

Is phishing really the biggest threat to UK businesses?

It is the most common. The Cyber Security Breaches Survey 2025/2026 found 38% of businesses experienced phishing, and 69% of those breached rated it the most disruptive type of attack they faced.

How Nerdster Helps

We run anti-phishing programmes for London businesses the way the NCSC recommends: realistic simulations, one-click reporting built into Microsoft 365, short just-in-time training, and — crucially — a no-blame culture that gets people reporting. Alongside it we put the technical layers in place, from enforced MFA to gateway mail filtering, so the human layer is never your only line of defence.

If you want to know your firm’s real phishing risk, book a free assessment through our anti-phishing testing service. We will baseline your click and report rates and give you a clear, practical plan to improve them.


Sources: UK Government Cyber Security Breaches Survey 2025/2026 (DSIT, fieldwork by Ipsos August–December 2025), gov.uk; NCSC guidance, “Phishing attacks: defending your organisation”, ncsc.gov.uk. Figures verified 15 July 2026.

phishingphishing simulationsecurity awarenessLondoncybersecurity

Related insights

Replies the same business day

Ready to fix your IT?

Book a free 30-minute IT assessment. We'll review your setup, identify risks, and show you exactly what better IT looks like.

  • 30-day rolling contracts
  • No callout fees
  • Free assessment