Phishing simulation is explicitly required under CTDISR-2025 Section 18, distinguishing it from the general security awareness training requirement. A simulation exercises the human layer of your security programme: rather than teaching staff to recognise phishing in a classroom, it tests whether they actually do when a convincing phishing email arrives in their inbox.
The simulation is not a trap or a performance evaluation. It is a measurement tool that identifies where additional training is needed and provides a baseline against which future simulations can show improvement.
Platform Selection
Three approaches are available at different cost points.
Commercial simulation platforms (KnowBe4, Proofpoint Security Awareness Training, Cofense) provide the most complete solution: a library of realistic phishing templates including localised scenarios, automated campaign management, per-user tracking, follow-up training delivery for users who clicked, and reporting designed for compliance documentation. The cost is per-user per-year and ranges from USD 10-30 per user for basic tiers. For an ISP with 30-50 staff, this is a manageable budget item.
GoPhish is an open-source phishing simulation platform that can be self-hosted. It provides the core campaign management and tracking functionality without the template library or automated follow-up training. For operators comfortable with the setup and willing to write their own phishing templates, GoPhish delivers the compliance requirement at zero licensing cost. The operational effort is higher than a commercial platform.
Manual simulation, where the CISO or security team sends test phishing emails directly without dedicated tooling, is possible for small organisations but difficult to scale, track consistently, or document in a way that satisfies audit evidence requirements. It is the least recommended approach for any organisation with more than 10 staff.
Scenario Design
The most effective simulation scenarios are those that are plausible given your organisation's context and current threat landscape. Generic simulations (a Nigerian prince email) are easily recognised and produce artificially low click rates that overstate actual resilience. Targeted, realistic scenarios produce more useful data.
Scenarios relevant to ISP staff include: an email appearing to be from PTA about a regulatory document requiring urgent download or response (specifically relevant because PTA communication is a legitimate and frequent event for ISP staff), a billing or payment notification from a known vendor the ISP works with, an internal IT notification about a password expiry or security alert requiring immediate action, and a delivery notification for a physical package addressed to a named staff member.
Rotating scenarios across simulations prevents staff from recognising a specific format and reporting it while still falling for different phishing approaches.
Running the Campaign
Configure the simulation to track three metrics: who received the email, who opened it, who clicked the link, and who submitted credentials if a fake login page is presented. Per-user tracking is essential for the follow-up training component.
Launch campaigns at realistic times: mid-week during normal working hours, not on a Friday afternoon or during a known busy period that would produce artificially low engagement with any email.
Inform senior leadership before the campaign launches but not general staff: this is standard practice and prevents leadership escalations when staff forward suspicious emails internally. Some organisations also inform the IT team to prevent simulation emails from being caught by email security controls, which would produce artificially low delivery rates.
After the campaign, users who clicked the link receive an immediate notification that they have participated in a phishing simulation, followed by a brief training module on how to recognise the specific technique the simulation used. This immediate, specific follow-up is more effective than adding the clicker to the next scheduled training session.
Results Documentation and CTDISR Evidence
The simulation results report is the CTDISR Section 18 evidence item. The report should contain: the simulation date, the scenario used, the total number of staff in scope, the number who received the simulation, the number who clicked or submitted credentials, the percentage click rate, and the follow-up training actions taken for users who clicked.
Retain this report as part of your compliance evidence package. For operators using ComplianceIQ, phishing simulation results are stored alongside the annual security training records under Section 18.
The click rate trend across multiple simulations is the metric that demonstrates programme effectiveness: a declining trend indicates that simulations combined with training are improving resilience. A static or rising trend is a signal that training content needs to change.
For operators who want phishing simulation managed as part of the CISO function alongside the broader security awareness programme, CISO-as-a-Service covers Section 18 as a governance deliverable. For the CTDISR evidence package that includes training records and simulation results, CTDISR Audit Readiness includes Section 18 review as part of audit preparation.