How to Answer Phishing Simulation Questions

Your customer asked: “Do you conduct phishing simulations?”

The short answer

A phishing simulation is a controlled exercise that sends simulated phishing messages to evaluate or reinforce employee behavior. General awareness training and real phishing attempts do not automatically count as simulations.

Educational guidance only. This page does not determine what is true about your company and does not create a security, compliance, testing, or certification claim.

What the customer is really asking

Understand the question before you answer it.

The customer is asking whether your company actively tests or exercises phishing awareness, often beyond merely assigning training content. They may care about frequency, participation, follow-up training, and whether results are tracked.

How to answer accurately

Start with the version that matches reality.

1

If simulations are conducted

State the population and cadence only if verified. You can describe follow-up training or measurement at a high level without exposing individual employee results.

2

If you provide training but no simulations

Answer “no” or “not currently” to the simulation question and describe the separate awareness training if context is useful.

3

If your provider sends test emails

Confirm that the feature is actually enabled and used for your workforce before claiming a program exists.

A useful answer structure

Status → scope → current practice → supporting information. Start with the direct answer, narrow it to what you can verify, explain how the practice works, and reference evidence only when that evidence actually exists.

Evidence that may help

These are examples, not requirements and not proof that your company has the practice. Use only evidence that really exists and is appropriate to share.

  • Simulation campaign record
  • Aggregate completion or reporting metrics
  • Training platform configuration
  • Follow-up education record

What not to say

  • That annual security training automatically includes phishing simulations.
  • That a platform feature proves simulations have been run.
  • That simulation results prove an independently tested security control.

How Oredra handles this

Answer it once. Keep the truth behind the answer.

Oredra prevents “training” from automatically becoming “phishing testing” when a questionnaire asks a more specific question.

Inside Oredra, a written policy, stated company practice, implemented control, available evidence, tested control, and independent certification remain distinct. Oredra uses approved information to draft future answers and flags questions that the approved profile cannot support.

Authoritative references

Oredra uses primary guidance where a technical or assurance concept benefits from verification. These references do not determine your company's answer.

Related questionnaire questions