Phishing Simulations for Accounting Firms: Worth It, With Conditions

Phishing simulations get sold as a compliance box and run as a gotcha. Done that way they achieve very little and cost you goodwill. Done properly they are one of the better things a small firm can do.

What they actually achieve

Not perfect click rates. Nobody gets to zero and chasing it is a waste of effort.

What they achieve is a workforce that has seen a realistic attempt before the real one arrives, and a habit of reporting. That second one is the whole point, and it is the thing most programmes fail to measure.

The metric that matters

Everyone measures click rate. The more useful number is report rate, meaning how many people flagged it. A firm where 40 percent click but 60 percent report is in far better shape than a firm where 10 percent click and nobody says anything, because the second firm has no early warning at all.

Measure both. Reward the reporting.

How to run it without damaging trust

Tell people it is going to happen. Not when, but that it will. A programme run secretly reads as entrapment and people remember it.

Never publish who clicked. Aggregate numbers to the firm, private conversations with individuals. Anyone who has been publicly embarrassed will never report anything again.

Make the training that follows short. Two minutes at the moment of clicking beats a forty minute module next quarter.

Do not use cruel lures. Fake bonus announcements and fake redundancy notices work extremely well and poison the relationship. The point is preparation, not proving you can catch people.

What to simulate in an accounting firm

The scenarios that actually get used against you. A client asking to change bank details mid season. A message that looks like it comes from your tax software vendor. An IRS themed lure in January. A shared document notification that mimics your portal.

Generic templates about parcel deliveries teach very little because nobody in your firm is going to fall for them at work.

The honest limitation

Simulations reduce risk, they do not remove it. Under pressure, in March, a good person will click something. That is why the technical controls underneath, particularly multi factor authentication and a verification rule for payment changes, matter more than the training does.

Scroll to Top