How to Choose a Phishing Simulation Tool: A Buyer's Guide for 2026

Most comparisons of phishing simulation tools are written by vendors, including this one - so let us be upfront: PhishGun is our product, and this guide names the situations where it is the wrong choice. What follows is the decision framework we would use if we were buying: how these tools are actually priced, the seven criteria that separate them in practice, whether the Microsoft 365 Attack Simulator you may already own is enough, and when a one-off agency test beats any subscription.

Start here: three questions that decide your shortlist

Tool selection goes wrong when it starts with a feature matrix. Answer these three first and most of the market eliminates itself.

  1. Is this a one-off measurement or an ongoing program? If you need one baseline number to show the board, you do not need a subscription. If you need a trend line and audit evidence, you do.
  2. Do your employees work in English? If a meaningful share of your staff reads Slovak, Czech, or another local language at work, a lure written in fluent local business language is the only honest test. Translated-from-English templates read as fake and depress click rates for the wrong reason.
  3. Who will run it? A dedicated security team can operate almost any tool, including a self-hosted one. An IT manager with four hours a month cannot, and the total cost of a cheap tool that needs constant attention is not cheap.

How phishing simulation tools are actually priced

The headline rate matters less than the model behind it. Four models dominate, and each one fails in a different way.

  • Per user, per month, billed annually. The industry default. Public estimates for the large platforms cluster in the low single-digit euros or dollars per user per month, with tiered feature sets - but almost all of them quote rather than publish, so treat any figure you read in a listicle as indicative only. The failure mode is the minimum seat count: a 60-person company is often quoted as if it were 200.
  • Bundled into a larger security licence. Some vendors include simulation with email security or an enterprise suite. The marginal cost looks like zero, which is exactly why nobody checks whether the tool is any good until the first campaign lands badly.
  • Flat annual fee for a size bracket. Predictable, easy to budget, and it stops the price rising every time HR onboards someone. This is what we do - EUR 1,000 a year up to 50 employees, then EUR 7.50 per additional employee up to 250, with lower per-employee rates above that. Our pricing page has the calculator.
  • Per engagement. Agencies charge per test rather than per seat. Excellent for a baseline, structurally unable to give you a trend.

Free phishing campaign

Test your employees with one free phishing campaign and see the results for yourself.

Run a focused pilot, measure clicks and reports, and review the training outcomes before rollout.

No credit card required.

The seven criteria that separate these tools in practice

Every vendor claims campaigns, templates and dashboards. These are the dimensions where real differences show up once you are three months into a program.

  1. Template localization. Not translation - localization. Does the library contain lures written by someone who knows what a Slovak payroll email or a Czech invoice reminder actually looks like? Ask to see three local-language templates before you buy.
  2. What happens after the click. A tool that only records the click produces a statistic. A tool that delivers short, contextual training at that moment produces a behaviour change. This is the single biggest functional difference in the category.
  3. Report-button workflow. Measuring who clicks is half the picture; measuring who reports is the half that predicts whether a real attack gets caught. Check whether the report button integrates with your mail platform and whether report rate is a first-class metric.
  4. Evidence export. Can you produce a clean PDF or export that an auditor will accept for NIS2, ISO 27001 or DORA without you rebuilding it in a spreadsheet? Our NIS2 compliance checklist lists exactly what that evidence needs to contain.
  5. Setup and identity integration. Microsoft 365 and Google Workspace import, plus allowlisting so simulations actually reach the inbox. Getting this wrong is the most common reason a first campaign returns meaningless data - the step-by-step playbook covers it.
  6. Attack realism. Does the library go beyond generic lures into the techniques attackers actually use now - adversary-in-the-middle, MFA fatigue, OAuth consent, QR codes, ClickFix? Our modern phishing techniques reference is a reasonable checklist to test a vendor against.
  7. Administrative weight. How many hours per month does the program cost you? Ask the vendor to describe a full campaign cycle end to end and count the manual steps.

Comparing the five realistic options

There are only five shapes of answer to this problem. Comparing categories is more useful than comparing brand names, because the brands move but the trade-offs do not.

OptionPricing modelSK/CZ localizationTraining after clickAudit evidenceSetup effort
Self-hosted open source (e.g. Gophish)Free software, your infrastructure and timeNone - you write every templateNot included; you build itRaw data only; you assemble the reportHigh and ongoing
Microsoft 365 Attack SimulatorIncluded, but requires E5 or Defender for Office 365 Plan 2 for every targeted userLimited local-language contentBuilt-in training library, Microsoft-authoredReporting inside the Microsoft stackLow if you already hold the licences
Global enterprise suitePer user per month, usually with a seat minimumVaries; often translated rather than localizedExtensive course librariesStrong, sometimes more than neededMedium to high; often needs an owner
Regional focused platform (incl. PhishGun)Flat annual fee by size bracketNative SK/CZ/EN contentImmediate micro-training at the clickExportable PDF aligned to NIS2/ISO/DORALow
Agency one-off testPer engagement, roughly EUR 199-1,000Native, written per engagementUsually a debrief, not per-user trainingA report for that single testNone - they run it

Is the Microsoft 365 Attack Simulator enough?

This is the first question any Microsoft-heavy organization should ask, and for a meaningful share of them the honest answer is yes. Attack simulation training is part of Microsoft Defender for Office 365, and if you already own the licences the marginal cost of running a campaign is nothing.

The prerequisite is the catch. According to Microsoft's own documentation, attack simulation training requires Microsoft 365 E5, Office 365 E5, or Microsoft Defender for Office 365 Plan 2 - and the licence is needed for every user you intend to include in a simulation, not just the administrator running it. If you are on Business Premium or E3 without the Plan 2 add-on, the tool is not free to you; it is a licence upgrade across your whole headcount, which is frequently more expensive than a dedicated platform.

Use Microsoft's tool if you already hold E5 or Plan 2 across the population you want to test, your workforce operates in English, and you are content to report from within the Microsoft stack. Look at a dedicated tool if you would have to buy licences purely to run simulations, if your staff need local-language lures, or if you need evidence exports shaped for a regulator rather than a security console.

Looking for a KnowBe4 or enterprise-suite alternative

The large awareness suites are large for good reasons: enormous course libraries, deep reporting, mature integrations, and years of benchmark data. If you are a multinational with a dedicated awareness manager, they are usually the right answer and this section does not apply to you.

Teams typically start looking for an alternative for three reasons, and it is worth being honest about which one is yours.

  • Seat minimums and pricing shape. A 60-person company quoted against a 200-seat minimum is paying for capacity it will never use. A flat bracket price solves this; so does any vendor willing to quote your actual headcount.
  • Content that does not fit the region. A course library of several thousand English-language modules is not obviously better than forty modules your employees will actually finish in their own language.
  • Administrative weight. Broad suites assume someone owns the program. If nobody in your organization has that job, the suite's best features go unused and you are paying for shelfware.

Where we would not recommend switching: if you need a full compliance LMS covering GDPR, health and safety, anti-bribery and a dozen other mandatory courses, a focused phishing platform - ours included - is the wrong tool. PhishGun does phishing simulation and the training attached to it. If your requirement is really "one system for all mandatory training", buy an LMS.

In-house, platform, or agency?

The build-versus-buy question has a clearer answer here than in most software categories, because the ongoing cost is dominated by content and operations rather than by the sending engine.

  • Build it in-house with open source when you have security engineers with spare capacity, you want full control of the data, and you are prepared to write and maintain local-language templates yourself. Gophish will send the mail competently and give you real-time results; everything after that - training content, report-button workflow, dashboards, identity integration, evidence formatting - is work you own forever.
  • Buy a platform when the program has to run repeatedly, be measured over time, and produce evidence, and when nobody on your team wants a second job maintaining it.
  • Hire an agency when you need a credible independent baseline, when you want an expert to interpret the result for management, or when you are below the size where a subscription pays for itself.

These are not mutually exclusive, and the most common sensible pattern is an agency test first to establish the baseline and get management attention, then a platform to run the program that the baseline justified. The phishing test guide covers what a good one-off test should deliver.

Running the evaluation: what to ask and what to test

Shortlist two or three, then run the same evaluation against each. Demos are designed to impress; a trial with your own employees is not.

  1. Ask to see three templates in your employees' working language, written for your industry. Judge them as an employee would, not as a buyer.
  2. Ask what a targeted user sees in the sixty seconds after they click. Have them show it, not describe it.
  3. Ask for a sample evidence export and check it against what your auditor actually requires.
  4. Ask for the total price at your exact headcount, for both annual and quarterly billing, including any seat minimum and any renewal uplift.
  5. Ask how long onboarding takes and who does the Microsoft 365 or Google Workspace allowlisting.
  6. Run one real campaign against a pilot group before committing. Any vendor confident in the product will let you.

That last point is the one we would insist on as a buyer, so we offer it: PhishGun's first campaign is free, needs no card, and runs against a real group of your employees so the comparison is against your reality rather than a sandbox. If a vendor will not let you test with your own people before signing an annual contract, that is information too.

Frequently asked questions

How much does a phishing simulation tool cost?

Three models dominate. Per-user subscriptions from the large platforms are commonly quoted in the low single-digit euros per user per month on annual contracts, though most vendors quote rather than publish. Flat annual pricing by size bracket is the alternative - PhishGun charges EUR 1,000 a year up to 50 employees, then EUR 7.50 per additional employee up to 250. A one-off agency test runs roughly EUR 199 promotional to EUR 1,000 standard. Always confirm seat minimums and the quarterly-versus-annual difference before signing.

Is the Microsoft 365 Attack Simulator good enough?

For English-speaking organizations that already hold Microsoft 365 E5, Office 365 E5, or Defender for Office 365 Plan 2 across the users they want to test, it often is. The catch is that the licence is required for every targeted user, not just the administrator - so if you are on Business Premium or E3, running simulations means a licence upgrade across your headcount, which is frequently more expensive than a dedicated platform.

What is the best free phishing simulation tool?

Gophish is the established open-source option: free, self-hosted, and genuinely capable at creating templates and delivering real-time results. What it does not include is training content, a report-button workflow, identity integration or audit-ready evidence formatting - all of which you build and maintain yourself. It is a good fit for teams with engineering capacity and a strong data-residency requirement, and a poor fit for a lean IT team.

What should I look for in a phishing simulation platform?

Seven things: genuinely localized templates rather than translated ones, immediate training delivered at the moment of the click, a report-button workflow with report rate as a first-class metric, evidence exports an auditor will accept, straightforward Microsoft 365 or Google Workspace integration including allowlisting, template coverage of current attacker techniques such as adversary-in-the-middle and QR-code phishing, and a low enough administrative burden that the program survives a busy quarter.

When is a phishing simulation tool not worth buying?

Below roughly 30 employees, where a one-off agency test is usually cheaper than any annual licence. When you need a single baseline number rather than a trend. And when your actual requirement is a full compliance LMS covering many mandatory training topics - a focused phishing platform will not replace that.

Do I need a separate tool if I already have security awareness training?

It depends on whether your current training measures behaviour or only completion. A course library tells you who finished a module; a simulation tells you who would have clicked. Regulators and auditors increasingly ask for the second, because NIS2 and ISO 27001 both expect verification that awareness education actually works rather than evidence that it was delivered.

Next step

Ready to measure your phishing and training program?

Book a demo and see how PhishGun can support your simulation and training program, reporting needs, and compliance evidence.