Baseline phishing simulation: fake invoice
Sample Company (80 employees) · Launched 1 September 2026
This is a sample report built on a fictional company. The structure is exactly what your company receives after its first risk baseline.
Clicked the link
24%
Medium risk
Entered credentials
7
of 80 delivered emails
Reported it
15%
12 employees reported
Follow-up training
63%
12 / 19 completed
What happened after the email arrived
- Delivered80 · 100%
- Opened57 · 71%
- Clicked the link19 · 24%
- Entered credentials7 · 9%
- Reported as phishing12 · 15%
Risk by department
| Department | Emails | Clicked | Reported | Risk score | Training |
|---|---|---|---|---|---|
| Finance | 12 | 42% | 8% | 64 | 58% |
| Sales | 22 | 32% | 9% | 71 | 66% |
| HR | 9 | 22% | 11% | 78 | 81% |
| Operations | 25 | 16% | 12% | 80 | 74% |
| IT | 12 | 8% | 42% | 91 | 92% |
Knowledge assessment
Average score 68% · 64 respondents
- Phishing & email72%
- Passwords & authentication58%
- Device & network security74%
- Incident response61%
Recommended 30-day plan
- 1
Reset passwords for 7 employees
They entered credentials on a fake page. In a real attack those accounts would already be lost: reset the passwords and confirm two-factor authentication is on.
- 2
Start with Finance (42% clicked)
This department carries the highest risk. Assign a short phishing course and tailor the next simulation to how they actually work.
- 3
Teach reporting (currently 15%)
Few employees report phishing. Set one simple channel for suspicious email and walk everyone through it: a reported attack is the earliest warning you get.
- 4
3 employees are past their training deadline
Reminders already go out automatically. The remaining cases need a manager to follow up in person.
- 5
Weakest topic: Passwords & authentication (58%)
This topic scored lowest in the knowledge assessment. Start the next course pack there.
- 6
Re-test in 30 days
Run a different scenario on the same team. Comparing the two results shows whether risk is actually going down.
How we count: every percentage is of delivered emails. Each employee is counted once, at the furthest step they reached. Risk levels are ShieldWise's own thresholds (low: up to 10%, medium: up to 25%), not an industry average.