Bristol, Gloucestershire, Wiltshire, Somerset, Dorset, Devon, Cornwall and the South West
MULTI AWARD WINNING IT SUPPORT, SOLUTIONS AND SERVICES
Phishing. Simulation Testing
"I would have no hesitation in recommending Soltech.”
Janie Tucker, Managing Director, Waste-Disposer Warehouse
SME
Phishing Simulation Testing
Corporate
Phishing Simulation Testing
Charity
Phishing Simulation Testing
Public Sector
Phishing Simulation Testing
Test Your Employees Before a Real Cyber Criminal Does
Your employees are one of your organisation's most important lines of defence against cyber attacks.
They're also one of the most common targets.
A convincing email can trick even experienced employees into clicking a link, opening an attachment or entering their Microsoft 365 credentials.
That's why security awareness training alone isn't enough.
You need to know how your employees would actually respond to a realistic attack.
Soltech IT's Phishing Simulation Testing safely recreates real-world phishing attacks, allowing you to identify vulnerabilities, educate your employees and measure improvement over time.
What Is Phishing Simulation Testing?
Phishing simulation is a controlled cyber security exercise where employees receive simulated phishing emails designed to look and behave like genuine attacks.
The objective is not to catch employees out or punish them.
It's to answer important questions:
- Would employees recognise the attack?
- Would they click the link?
- Would they enter their credentials?
- Would they open an attachment?
- Would they report the email?
- Which departments are most vulnerable?
- Has previous security awareness training worked?
The results provide measurable insight into your organisation's human cyber risk.
Yet one successful phishing attack can still result in a compromised account.
Phishing simulation helps identify this risk before a real attacker does.
Modern Phishing Attacks Look Genuine
The old-fashioned phishing email full of spelling mistakes is becoming much less common.
Today's attacks can be highly convincing.
They may appear to come from:
- Microsoft
- Your bank
- A customer
- A supplier
- Your Managing Director
- HR
- A colleague
- A delivery company
- A solicitor
- Your IT provider
AI is also making it easier for criminals to produce convincing, personalised communications.
Employees therefore need to learn to recognise suspicious behaviour and requests, rather than simply looking for spelling mistakes.
How Phishing Simulation Works
1. We Plan the Campaign
We discuss your organisation, objectives and the types of attacks you want to simulate.
Campaigns can be tailored to your business and industry.
2. We Create the Simulation
Examples include:
Microsoft 365 Account Alert
A simulated security notification asking employees to verify their account.
Password Expiry
A message claiming that an employee's password is about to expire.
Supplier Invoice
A realistic invoice or payment-related email.
Delivery Notification
A simulated delivery message containing a link.
HR Request
A message appearing to come from HR requesting information or action.
Executive Impersonation
A simulated email appearing to come from a director or senior manager.
3. Employees Receive the Email
The campaign is conducted in a controlled manner and designed to replicate the type of attack an employee could realistically encounter.
4. We Measure the Results
Depending on the campaign, we can measure:
- Email interaction
- Link clicks
- Simulated credential submission
- Reporting behaviour
- Response times
- Department performance
5. Employees Learn From the Experience
If an employee interacts with the simulation, they can receive immediate guidance explaining what warning signs they missed.
This turns a potential mistake into a learning opportunity.
6. We Re-Test
Further simulations can be conducted to measure whether behaviour improves.
Test → Educate → Improve → Re-Test
What Does Phishing Testing Tell You?
A phishing simulation can reveal the difference between what your organisation thinks employees will do and what they actually do.
Click Rate
What percentage of employees clicked the simulated link?
Reporting Rate
How many employees reported the suspicious email?
Submission Rate
How many employees entered information into the simulated page?
Department Risk
Are particular departments more susceptible?
Improvement
Are employees becoming better at identifying phishing after training?
Human Risk Is Different Across Departments
We can tailor simulations for different roles.
Finance
Test invoice fraud and payment diversion scenarios.
HR
Test requests for confidential employee information.
Directors
Test executive impersonation and targeted attacks.
Sales
Test customer and supplier impersonation.
IT
Test technical support and administrator impersonation.
This helps identify where additional training may be required.
Discover the right certification for your business.
Explore Cyber Essentials and Cyber Essentials Plus.
Phishing Simulation & Security Awareness Training
The most effective approach isn't to run one phishing test every year.
Instead, create an ongoing programme:
1. Educate
Teach employees about cyber threats.
2. Test
Conduct realistic phishing simulations.
3. Measure
Identify where weaknesses remain.
4. Train
Provide targeted education.
5. Re-Test
Measure improvement.
This creates a measurable security awareness programme.
Phishing Simulation Shouldn't Be About Blame
An effective phishing programme should encourage employees to report suspicious emails—even if they aren't sure.
Employees should feel comfortable saying:
"I think I may have clicked something suspicious."
rather than hiding a mistake because they are worried about being punished.
A strong reporting culture can significantly improve your ability to respond to genuine attacks.
Phishing Simulation for Schools
Schools face a particularly challenging security environment.
They have large numbers of users, sensitive information and often limited internal cyber security resources.
We can provide phishing simulations for:
- Teachers
- Administrative staff
- Leadership teams
- Support staff
- Governors
- IT teams
Campaigns can be designed around realistic education-sector scenarios.
Phishing Simulation for Small Businesses
You don't need hundreds of employees to benefit from phishing testing.
A small business can be significantly affected by one compromised account.
An attacker who compromises a single Microsoft 365 account may potentially gain access to sensitive emails, documents and customer information.
Phishing simulation provides an affordable way to test one of your most important security controls: Your People
Phishing Simulation & Cyber Insurance
Cyber insurers increasingly ask businesses about employee security awareness and phishing protection.
Regular training and testing can help demonstrate that your organisation actively manages human cyber risk.
It can also provide evidence that employees are being educated and tested rather than simply given a policy document.
Speak to Soltech IT about your businesses Cyber Security needs
Contact Us
Why Choose Soltech IT?
Phishing simulation is most effective when it forms part of a wider cyber security strategy.
If testing identifies weaknesses, Soltech IT can help address them through:
- Security Awareness Training
- Email Security
- Microsoft 365 Security
- Cyber Essentials
- Cyber Essentials Plus
- Managed Security Risk
- Endpoint Detection & Response
- Managed Detection & Response
- Cyber Security Auditing
- Penetration Testing
- Dark Web Monitoring
- Incident Response
- Backup & Disaster Recovery
We don't just tell you that your employees clicked a phishing email.
We can help you reduce the risk of it happening again.
Frequently Asked Questions
Is phishing simulation safe?
Yes. A properly designed simulation is a controlled exercise intended to replicate phishing behaviour without deploying genuine malware or compromising your systems.
Will employees know it's a test?
The campaign can be conducted without giving employees advance notice of the exact timing or content. This provides a more realistic measurement of behavior.
Should employees be disciplined for clicking?
We recommend using simulations primarily as a training and improvement tool rather than a disciplinary exercise.
How often should we conduct phishing simulations?
Regular testing is generally more effective than a single annual campaign. Different scenarios can be introduced over time to maintain awareness and measure improvement.
Can you test senior management?
Yes. Directors and executives should not automatically be excluded. They can be attractive targets because of their access to sensitive information and authority to approve financial transactions.
Would Your Employees Spot a Real Attack?
You can invest thousands in cyber security technology.
But if an attacker can convince an employee to hand over their credentials, your security can still be compromised.
Phishing Simulation Testing from Soltech IT lets you safely test your employees, identify weaknesses and build a stronger security culture.
Don't wait for a cyber criminal to test your employees for you.
Contact Soltech IT Ltd today to arrange a Phishing Simulation Test.

Meet the team
Technical Director
Lee brings a wealth of certified qualifications to the business, along with also many years of experience dealing with prestigious SME's, and Educational organisations.
As our Technical Director Lee is responsible for managing the technical direction of the business and our clients. In his role, Lee is also very much 'hands on' with our client base and project installations..

































