20+ years with Microsoft 1,100+ organisations under management 131 countries invoiced locally 5 of 6 Solutions Partner designations 4-hour first response
IT Partner.Microsoft Solutions Partner +44 20 8142 5752 Talk to us Get a quote

HomeBlog › Attack simulation

Security · 23 September 2026 · 9 min read

The phishing test you run on your own staff, before someone else does

Every organisation has a click rate. Most only learn theirs from an incident. Attack simulation in Microsoft Defender sends your own people a phishing message you approved in advance, tells you who clicked, who typed a password and who reported it, and gives you the one document that reliably moves a security budget: a number with your company’s name on it.

Attack simulation, in one table

WhatAnswer
What it isA controlled phishing campaign against your own staff, sent from inside Microsoft Defender, with a report per person and per message
Who it is forAn IT director who needs to show the board how exposed the company is; an IT team that wants to know how staff handle mail
LicenceMicrosoft Defender for Office 365 Plan 2 — included in Microsoft 365 E5 and E5 Security; an add-on at €4.30 per user a month on our September list; the ninety-day trial is enough for a first campaign
Group sizeThirty, a hundred, five hundred — the tool does not care; the debrief does
TimeThree weeks end to end when we run it: agree the message, send, wait, report, debrief
ResultClick rate, credential rate, report rate and repeat offenders — and the list of tenant settings that would have stopped the real one

The mail filter is good. Defender for Office 365 stops the bulk phishing, the malware attachments, the obvious impersonations. What reaches the inbox is the well-crafted minority: the supplier who “changed bank details”, the shared document from a colleague’s real name, the voicemail notification, the HR policy that needs a signature by Friday. Those are stopped by a person, or not. Attack simulation is the tool that measures which.

It lives in Microsoft Defender, under the same roof as the filter. You pick a technique and a message, choose the people, send, and wait. The messages look real because they are built from real ones; the links go to Microsoft’s own landing pages, so nothing is exposed and nothing leaves the tenant. When someone clicks, Defender records it. When someone types a password into the fake sign-in page, Defender records that too, without keeping the password. When someone uses the Report button, that is recorded as the good outcome it is. Two weeks later you have a table.

Why it matters, and for whom

For the IT director, it is a budget document. Boards do not fund security because it is important; they fund it because of a number they can picture. “Eighteen of our sixty people entered their password into a page that was not ours, including two in finance” is such a number. It is more persuasive than any industry statistic because it is about the people the board knows by name, and it comes with a plan: training for the eighteen, Conditional Access and multi-factor policies that make a stolen password useless, a second campaign in three months to show the improvement. That sequence — measure, fix, measure again — is how a security budget gets approved and how it gets renewed.

For the IT team, it is a diagnostic. The team already suspects who forwards everything and who never reads the sender address. The simulation replaces suspicion with data, and it finds the surprises: the senior person who never clicks but also never reports, the department where the click rate is triple the average because a supplier really does send them invoices with new bank details. It also tests the team’s own side — whether the reported messages reach anyone, and how fast.

For an auditor or an insurer, it is evidence. Cyber-insurance questionnaires ask whether staff receive phishing awareness training and whether it is tested. ISO 27001 and NIS2 expect awareness to be demonstrable. A simulation with a report is the demonstration; a slide saying “we did training” is not.

What can be simulated

Defender offers the techniques attackers actually use, each with a library of ready messages that can be sent as they are or rewritten in your company’s tone:

Every message is agreed with the IT director before it goes anywhere: the pretext, the sender, the landing page, the group. Nothing is sent that the company has not signed off, and nothing pretends to be a real supplier without permission.

How a campaign runs, against thirty people or five hundred

  1. Agree the scope. Which technique, which pretext, which group. A first campaign is usually one technique against everyone, or two techniques against two halves so that the results compare. A named executive is included only if they have agreed; a department is never singled out to embarrass it.
  2. Prepare the message. From the library or written for you: your language, your tools, a pretext that fits the week — the payroll cycle, the audit, the new expense system.
  3. Send, and say nothing. The messages go out over a day or two, at working hours, in the group’s time zones. The helpdesk is briefed so that reports are handled normally and not answered with “it’s a test”.
  4. Wait two weeks. Long enough for the late clickers and the people who were on leave.
  5. Read the report. Per message and per person: delivered, opened, clicked, credentials entered, attachment opened, reported, and how long each took. Defender also assigns training to the people who failed, automatically if you want it to.
  6. Debrief. The numbers, the pattern, the settings that would have made the real attack fail, and the date of the next campaign. That debrief is the document that goes to the board.

What the report shows, and what it does not

The headline is the compromise rate: the share of recipients who did the thing the attacker wanted — entered credentials, opened the attachment. Beside it, the click rate, which is higher and less important, and the report rate, which is the number you actually want to grow. Defender adds a predicted compromise rate for the message, so you can see whether your people did better or worse than Microsoft’s data would expect, and a list of repeat offenders across campaigns.

What it does not show is a person’s password, and it does not need to. And it does not say who is careless: a first campaign in almost every organisation produces a double-digit click rate, and the point is not the number but what happens to it in the second campaign. The organisations that treat the first report as a ranking learn less than the ones that treat it as a baseline.

From the report to the budget

The report by itself changes nothing. What changes things is the page after it, and it is short:

Priced, that page is usually a fraction of what the board imagined a security programme would cost, because most of it is configuration of licences the company already pays for. That is the second reason the simulation moves budgets: it makes the ask specific and small.

Doing it yourself, or with us

You can run all of this from the Defender portal without us. The licence is Defender for Office 365 Plan 2 — already there in Microsoft 365 E5 and E5 Security, an add-on to E3 and Business Premium at €4.30 per user a month on our September list, and the ninety-day trial covers a first campaign in full. The portal is clear and the library is large. What people underestimate is not the tool but the judgement around it: which pretext is fair, which group is representative, what to tell the helpdesk, how to present a result that embarrasses nobody and still moves money.

When we run it, the engagement is three weeks end to end and priced from €1,200: the campaign agreed with you message by message, the report, a debrief written for the board, and the list of tenant changes with the settings already tested in your tenant. If you want the second campaign, the same engineers run it and the report compares the two. Either way, the first step is the same — a thirty-minute call to agree who is in the group and what they will receive.

Questions we are asked before the first campaign

Is it legal to phish our own staff?

Yes, when the company runs it against its own accounts with management approval. In countries with works councils, and in Germany in particular, the council is consulted first; we prepare that paper with you.

Will people be named?

Defender records results per person because training has to be assigned per person. What goes to the board is our decision together: rates by department are usually enough, and no report of ours ranks individuals.

Do we need E5?

No. Defender for Office 365 Plan 2 is the licence, and it is an add-on to Microsoft 365 E3 and Business Premium; the ninety-day trial is enough for a first campaign.

How often should we run it?

Quarterly is the common cadence: often enough that the report rate keeps rising, rare enough that people do not start ignoring real mail.

Can we simulate a real supplier?

Only with that supplier's written permission. Otherwise the pretext is generic — a document share, a sign-in prompt, an HR notice — which is how most real attacks look anyway.

Worth reading next