Teach Yourself to Phish
Huntress, Friday, August 28th, 2026
Huntress explains the strategy behind phishing simulations and how they build organizational resilience.
Huntress pushes back on treating security awareness training as a passive purchase, where an organization buys a training product and considers the problem addressed.
This post covers the strategy behind phishing simulations: what they are meant to measure, how campaigns should be designed, and how results translate into real resilience rather than a compliance metric.
The argument is that simulations are an active program requiring thought about targeting, difficulty and follow-up, not a box to check annually.
It is aimed at the person responsible for running such a program rather than at end users.