Cybersecurity

Anti-Phishing Testing for London Firms: Does It Work?

Anti-phishing testing cuts risk for London businesses, but only the NCSC way, without a blame culture. What works, how often, and what it costs.

Nerdster Team

Anti-phishing testing — sending staff safe, simulated phishing emails to measure and improve how they respond — does reduce risk, but only when it is run the way the National Cyber Security Centre (NCSC) recommends: as one part of a layered defence, and without punishing people who click. Done as a blame exercise, it can backfire and even create legal risk. This guide explains what phishing simulation testing is, whether it works, and how a London business should actually run it.

The reason to bother is simple. In the government’s Cyber Security Breaches Survey 2025/2026 (fieldwork August–December 2025), 38% of all UK businesses experienced a phishing attack, and phishing was rated the single most disruptive type of breach or attack by 69% of the businesses and charities that were hit. It is the most common threat your staff will face, and it is the one most likely to cause real damage.

What anti-phishing testing actually involves

Anti-phishing testing, also called phishing simulation, is a controlled exercise in which your IT or security provider sends realistic but harmless fake phishing emails to your employees. Nobody’s data is at risk. The point is to measure how many people click a link, enter credentials, or open an attachment — and, just as importantly, how many report the email.

A good programme is not a one-off “gotcha”. It combines three things:

  • Simulated phishing emails that mirror the tactics real attackers use against your sector.
  • Short, targeted training delivered at the moment someone interacts with a simulation, and repeated over time.
  • A simple reporting mechanism — usually a “Report Phishing” button in Outlook or Microsoft 365 — so staff can flag suspicious mail in one click.

The output is a baseline you can improve on: your click rate, your report rate, and which teams or roles need extra support.

What phishing simulation testing can and cannot do

Yes, with an important caveat. The NCSC is candid that “no training package, including phishing simulations, can teach users to spot every phishing attempt.” Attacks are increasingly convincing — including AI voice-cloning and vishing calls that go well beyond the classic dodgy email. So the goal of testing is not a zero per cent click rate, which is unrealistic and counter-productive to chase.

Testing achieves three things instead. It builds the habit of pausing before acting. It sharply increases how many genuine phishing emails your staff report, and reporting is what actually protects you. And it shows you where your human risk concentrates. The NCSC’s clearest instruction is to “widen your defences to include technical measures, with user education being just one aspect.” Testing tells you how well the human layer is holding; it does not replace the technical layers underneath it.

Why a blame culture makes the testing worthless

The fastest way to make anti-phishing testing worthless is to name, shame, or discipline the people who click. The NCSC is emphatic that users who are struggling to recognise phishing emails must not be reprimanded: “Users who fear reprisals will not report mistakes promptly, if at all.” It goes further, warning that punishing people for clicking can even create legal risk, because no one can reliably detect every phishing email.

The practical rule for London firms: reassure first. Tell staff plainly that they will never get in trouble for reporting something — including reporting after they have already clicked. A report five minutes after a click still lets your provider contain the incident. A silence because someone was scared of a telling-off is how a single click becomes a breach.

Running the programme the way the NCSC recommends

Here is a straightforward approach that follows NCSC guidance.

  1. Set a baseline. Run an initial simulation across the whole organisation to measure current click and report rates. Do not announce the exact date — but do tell staff in advance that simulations happen, so it never feels like a trap.
  2. Deploy a one-click report button. Make reporting “clear, simple and quick to use”, in the NCSC’s words. In Microsoft 365 this is the built-in Report Phishing add-in.
  3. Train at the teachable moment. When someone clicks a simulation, show a short, plain-English explainer of the tell-tale signs — not a warning notice. Keep annual e-learning short; long modules do not change behaviour.
  4. Target higher-risk roles. Staff who handle payments, sensitive data or IT administration should get extra, tailored support. Finance and executive-assistant roles are the ones criminals research and impersonate.
  5. Measure the report rate, not just the click rate. Rising reporting is the real sign of a maturing security culture.
  6. Layer the technical defences. Enforce multi-factor authentication everywhere (a requirement under Cyber Essentials v3.3), filter mail at the gateway, and separate privileged accounts. These are also the controls that cyber insurers reward with lower premiums.

Monthly or six-weekly testing, never once a year

For most SMEs, short simulations every month or six weeks keep awareness fresh without wearing people down. Add a brief refresher each quarter. Testing once a year achieves very little, because the lesson fades long before the next email lands. Higher-risk sectors such as financial services and professional firms usually test more often, with harder scenarios.

Cost: a few pounds per user per month

Anti-phishing testing is priced per user per month. For London SMEs it usually sits in the low single-digit pounds, and it is more often bundled into a managed security or awareness package than bought on its own.

Set that against what phishing costs when it lands. It is still the most common attack UK businesses face, and part of the picture behind roughly 612,000 UK businesses identifying a breach or attack in the last year. Not testing is almost always the more expensive option.

Answers to the questions we get asked most

What is anti-phishing testing?

Anti-phishing testing, or phishing simulation, is a controlled exercise where your IT provider sends staff realistic but harmless fake phishing emails to measure how they respond, then delivers short training to improve awareness and reporting. No real data is ever at risk.

Does phishing simulation actually reduce risk?

Yes, when run correctly. The NCSC notes that no simulation can teach users to spot every phishing attempt, so it should sit alongside technical defences such as multi-factor authentication and mail filtering. Its real value is building a reporting habit and showing where your human risk sits — not chasing a zero per cent click rate.

Should you punish employees who fail a phishing test?

No. The NCSC advises against reprimanding users who click, warning that a blame culture stops people reporting mistakes and can even create legal risk. Reassure staff they will never be in trouble for reporting — even after a click.

How often should a business run phishing simulations?

For most London SMEs, monthly or six-weekly short simulations with quarterly refresher training works well. Annual-only testing is largely ineffective because the lesson fades. Higher-risk firms in finance and professional services usually test more often.

Is phishing really the biggest threat to UK businesses?

It is the most common. The Cyber Security Breaches Survey 2025/2026 found 38% of businesses experienced phishing, and 69% of those breached rated it the most disruptive type of attack they faced.

Would your team click?

We run anti-phishing programmes for London businesses the way the NCSC recommends: realistic simulations, one-click reporting built into Microsoft 365, short training delivered at the moment it lands, and, above all, a no-blame culture that keeps people reporting. We put the technical layers in alongside it, from enforced MFA to gateway mail filtering, so the human layer is never your only defence.

If you want to know your firm’s real phishing risk, book an assessment through our phishing simulation service. We will baseline your click and report rates and give you a clear, practical plan to improve them.


Sources: UK Government Cyber Security Breaches Survey 2025/2026 (DSIT, fieldwork by Ipsos August–December 2025), gov.uk; NCSC guidance, “Phishing attacks: defending your organisation”, ncsc.gov.uk. Figures verified 15 July 2026.

phishingphishing simulationsecurity awarenessLondoncybersecurity

Related insights

Talk to our team about your IT

Tell us what you need. Our London team replies within 2 hours during business hours.

We respond within 2 hours during business days. Your data is handled per our privacy policy.

Contact details

0330 043 7414

Mon-Fri 8am-6pm

[email protected]

We reply within 2 hours

71-75 Shelton Street

Covent Garden, London WC2H 9JQ

IT assessment

A review of your IT, your security posture and your compliance readiness, free of charge.

  • 30-minute consultation call
  • Infrastructure & security review
  • Compliance gap analysis
  • Custom recommendations report