Phishing Simulation is the LibraCyber product that measures — and helps reduce over time — how many employees in an organization fall for a phishing attack. It sends employees realistic but harmless phishing emails and observes how they react, turning every click into a training opportunity. You manage it from the Phishing Simulation menu, which brings together the results Dashboard, campaigns, the Template Catalog, and configuration (Setup).
How it works
Phishing Simulation sends employees emails that mimic a real attack, but with no risk: they are simulations that LibraCyber delivers on behalf of the company, and the landing pages teach rather than steal data. For each simulation, the platform records employee behavior: whether they ignore the email, open it, click the link, enter data, or report it as suspicious.
Those who click don't end up on a real attacker's page, but on a brief landing page that explains it was a test and how to recognize the threat next time. The administrator follows progress in the Dashboard, where the click rate should decline over time.
Simulations can be sent in three ways: automatically (the program always active), as a trial during startup, or through custom campaigns (Custom Campaign) fully controlled by the administrator.
Campaign types
- Automatic campaign — the always-on simulation program. Once Setup is complete and automatic delivery is enabled, LibraCyber templates are sent to employees continuously during business hours, without manual intervention. Example: a company leaves the program running all year.
- Trial campaign — the startup or proof-of-concept phase: a curated subset of templates, whose results still feed into the Dashboard, so the company sees impact right away. Example: a two-week trial before full rollout.
- Custom campaign — a simulation the administrator controls completely: chosen audience, template, volume, and time window. Example: a targeted test of the Finance department with three banking templates over two weeks.
Templates and landing pages
- Template — the phishing email used in a simulation. LibraCyber templates are the curated, ready-to-use library available to every company; custom templates are those the company creates or adapts for itself. You can also generate a template draft with the Create template with AI action.
- Payload / compromise type — the action the template tries to trigger: Credentials (enter username and password), Attachments (open an attachment), Downloads (download a file), Permissions (grant access), or none.
- Landing page — the page shown after clicking. Its purpose is to train: it explains that this was a simulation and what to watch for next time.
- Scenario (login page) — for a Credentials template, instead of the generic landing page, the click leads to a realistic fake login page (for example, a fake Microsoft 365 login). If the employee enters data, the simulation is marked as compromised.
- Micro-learning — the brief training an employee can take after clicking: it turns the mistake into a lesson. Completion is tracked as a separate signal.
- Company Scan — the company profile screen where the administrator enters details that make templates convincing: key people (CEO, CFO, HR…), company signature, and main clients. Despite its name, it is a configuration screen, not an external scan of the company.
How to read the results
The Dashboard collects program results and shows their trend over time. The main signals are:
- Click rate — the share of employees who clicked the simulation link; this is the indicator that should decline over time.
- Compromised — an employee not only clicked but performed the risky action the template was testing (entered data, opened the attachment, granted permission, or downloaded the file). This is the most important risk signal.
- Reported — an employee marked the simulation as suspicious: this is the desired behavior, and a high reporting rate indicates a healthy security culture.
Getting started
Before you begin: Phishing Simulation is active for your company; employees and their departments are synced on the platform; a sending domain is verified and email integration is configured; you have Phishing Simulation admin permission.
- Open Phishing Simulation › Setup and complete the Setup Checklist — verify user provisioning, email integration, and sending domain, and fill in your company profile (Company Scan: key people, signature, main clients) to personalize templates.
- Use Setup › Delivery Test to send yourself a test simulation and verify it arrives and displays correctly.
- Activate the program: in Setup › Preferences enable Automatic simulation delivery (the always-on campaign), or create a Custom Campaign from Phishing Simulation › Custom Campaign › Create new campaign.
- Follow results in Phishing Simulation › Dashboard: click rate over time, who clicked or reported, and which attack types are most effective against your organization.
Once the test is complete, the test simulation arrives in your inbox and displays correctly; once the program starts, the Simulations Sent boxes and Dashboard rates begin to populate as emails go out and employees interact.
Roles and permissions
| Function | Administrator | Employee |
|---|---|---|
| View the Dashboard (rates, users, compromises) and details for individual emails | ✅ | — |
| Create, schedule, and cancel Custom Campaigns | ✅ | — |
| Browse the Template Catalog, create or adapt templates (including with AI) | ✅ | — |
| Run Setup (Checklist, Delivery Test, Template Attribution, Preferences) | ✅ | — |
| Configure company profile (Company Scan) | ✅ | — |
| Receive simulations, view the landing page / micro-learning, report a simulation | ✅ (as employee) | ✅ |
Access is governed by granular permissions assigned in General Settings › Permissions: there are separate permissions for Dashboard, Custom Campaign, Template Catalog, Setup, Company Scan, and for reading the Risk Score, so you can assign an administrator only the areas they need. Employees need no permissions: they are the recipients of simulations.
AI, integrations, and data
AI. Phishing Simulation offers an optional action, Create template with AI: the administrator describes the desired phishing email and the platform drafts a template, which the administrator reviews and uses. The AI is only for drafting template content, which remains under administrator control; it makes no automatic decisions about employees. Classification of who clicked or reported does not use AI.
Integration. The product relies on the platform's identity and directory. Employees are provisioned from the company directory — Google Workspace, Microsoft 365, or any SCIM identity provider (for example Okta or Azure AD) — which provides users, departments, and groups for selecting recipients. Access to the admin console is via the platform's Single Sign-On. Beyond provisioning and the verified sending domain (configured in Setup), there is no separate connector to configure for Phishing Simulation.
Data collected. The product records each employee's interaction with a simulation — sent, opened, clicked, reported, whether they completed the micro-learning, and if they were compromised — along with identifying data needed to select recipients and produce reports (name, email, department, and optionally location). In a login page scenario it records only that the employee submitted data: it never stores the username or password entered.
What Phishing Simulation is NOT
- It is not a real attack or penetration test: the emails are simulations that LibraCyber sends on behalf of the customer and the landing pages teach rather than steal data.
- It is not the video-course product (Cyber Awareness / Video Training): although a click can lead to brief micro-learning, this product is the phishing test and its measurement.
- It is not Smart Banners, Threats, or Browser Defender.
- It is not something employees must install: it works server-side and requires nothing on the device.
Availability and support
Phishing Simulation is sold per company; access has levels Trial, Full, or No access.
For support, contact LibraCyber's standard support channel. Before opening a request, the administrator can perform some self-checks: Setup › Delivery Test (does a simulation arrive and display correctly?), the Setup Checklist (is provisioning, email, and domain in order?), and the Dashboard (are simulations being sent and tracked?).
Some operations only LibraCyber can perform and must be requested through support: create or modify the curated template library, manage the email sending infrastructure, and analyze any delivery or tracking issues.