A few years ago, a business owner we know sat down to renew their cyber insurance policy. The previous year, the application had been two pages. Check a few boxes, sign, done.
This time, the application was ten pages long.
New questions about endpoint detection. New questions about multifactor authentication. And a section that stopped them cold: "Provide documentation of your organization's phishing simulation program."
They didn't have any of that. They'd been checking "yes" on the security training question for years, assuming the annual compliance video counted. It didn't.
That conversation is happening in offices across California and Hawaii right now. And the businesses that can't answer those questions are facing a choice they didn't expect: scramble to build a real phishing simulation program, or accept a premium increase that makes their eyes water.
We want to walk you through what's changed about cyber security insurance requirements, why the bar moved, and what you need to do about it.
TL;DR: Most cyber insurance carriers now require a phishing simulation program as a condition of coverage. The application asks whether you have one. If you ever file a claim, the carrier's investigation asks for proof it was running the whole time you were paying premiums. Businesses that check "yes" and keep no records risk having a claim denied for material misrepresentation. Six major compliance frameworks (PCI DSS v4.0, NIST CSF 2.0, ISO 27001, SOC 2, HIPAA, CMMC) also require or strongly recommend phishing awareness activities.
Most cyber insurance carriers now require phishing simulation because the financial losses from phishing have made the old checkbox approach unsustainable.
Insurance carriers are in the business of math. And the math on phishing is unforgiving.
The FBI's Internet Crime Complaint Center logged 193,407 phishing complaints in 2024, with business email compromise alone responsible for $2.77 billion in losses. IBM and the Ponemon Institute put the average cost of a phishing-related breach at $4.88 million. The Anti-Phishing Working Group counted 3.8 million unique phishing sites active in 2025.
Carriers absorbed billions in ransomware payouts in 2024 and 2025. They responded the way any business would when the numbers stop working: they tightened the requirements.
The old standard was simple. "Do you provide security awareness training to employees?" Check yes, move on. The 2026 application goes further and asks for documentation that a phishing simulation program exists.
Here's the part most business owners miss. The application is the easy conversation. If you ever file a claim, the carrier's investigators come back and ask you to prove the program was running the entire time you were paying premiums. That is where monthly results, click-rate trends, and remedial training records earn their keep.
The shift makes sense when you understand that 74% of data breaches involve a human element. Carriers aren't asking about phishing simulation because it's trendy. They're asking because it's the single best predictor of whether an employee will click the link that starts a seven-figure claim.
We help businesses across California and Hawaii build exactly this kind of documentation. The ones who have it ready at renewal time have a fundamentally different experience than the ones who don't.
Key takeaway: Carriers tightened phishing simulation requirements because the math forced them to. The application asks whether you have a program. A claim investigation asks you to prove it was running.
Cyber insurance requirements for phishing have moved well past "we do annual training." Most 2026 applications ask you to confirm that a phishing simulation program is in place. Confirming it takes one checkbox. Defending that confirmation takes records.
Here's what belongs in those records, and why each piece matters if a claim ever gets investigated:
Monthly simulation cadence. Monthly is the cadence we recommend. Twelve documented sends a year, each with a date and campaign detail, gives an investigator a continuous record to work from.
Click-rate trends over time. Trend data across quarters shows the program is doing its job. A click rate moving downward is the strongest evidence you can hand someone that your employees are learning.
Remedial training completion. Records showing that employees who clicked went on to complete additional training. PCI DSS v4.0 requires this outright, and it demonstrates that your program closes the loop rather than stopping at a "you failed" notification.
Departmental reporting. Results broken down by team. Finance and HR handle sensitive data and get targeted more frequently, so breaking out their numbers shows you're paying attention to where your risk concentrates.
The evidence pack. Think of this as your cyber insurance checklist for phishing simulation documentation. A quarterly export showing campaigns sent, response rates, training completions, and trend lines. Your IT partner should be generating this for you. If they're not, that's a gap worth closing before your next renewal.
Key takeaway: The application asks for confirmation that a program exists. Monthly simulations, click-rate trends, remedial training proof, and departmental reporting are what let you defend that confirmation later. Package them into a quarterly evidence export.
Yes, your cyber insurance claim can be denied if you cannot produce phishing simulation records that match your application representations.
Your cyber insurance application is a legal document. When you check "yes" next to "Do you conduct regular phishing simulations?" you are making a binding representation. If you check yes and can't produce evidence to back it up, the carrier has grounds to deny your claim. This is called material misrepresentation: a false statement on an insurance application that, had the insurer known the truth, would have changed the terms or availability of coverage.
Two separate moments matter here, and the gap between them is where businesses get hurt. Checking the box takes a second at renewal. The request for proof arrives months or years later, at the worst possible time, from someone whose job is to examine your answer closely.
Think about what that means. You pay premiums for years. Your company gets breached. You file a claim. The carrier's forensic team reviews your application, asks for your phishing simulation logs, and you can't produce them. Your cyber insurance claim gets denied because of a phishing-related misrepresentation. The premiums you paid are gone. The breach costs are yours to cover.
This isn't theoretical. Coalition's 2024 Cyber Claims Report found that 56% of cyber insurance claims now originate from business email compromise or funds transfer fraud, both of which start with phishing. As claim volume rises, carriers are scrutinizing applications more aggressively during the claims process. Misrepresentations on insurance applications, even unintentional ones, can void your policy entirely.
The most expensive phishing simulation program is the one you told your insurer you had and never ran.
Key takeaway: Your insurance application is a legal document. Checking "yes" on phishing simulation without proof to back it up can void your policy when you need it most.
Cyber insurance isn't the only reason to run phishing simulations. Phishing simulation for compliance is increasingly a baseline expectation. Multiple frameworks now require or strongly recommend it. Here's a reference table:
| Framework | Requirement | What It Says |
|---|---|---|
| PCI DSS v4.0 | Requirement 12.6.3.1 | Organizations must provide additional training to personnel who fail phishing simulations |
| NIST CSF 2.0 | PR.AT (Awareness and Training) | Personnel must be trained to recognize and respond to social engineering attacks |
| ISO 27001 | Annex A.7.2.2 | Information security awareness, education, and training must be provided to all employees |
| SOC 2 | CC1.4 (COSO Principle 4) | Organizations must demonstrate commitment to attracting, developing, and retaining competent individuals, including security awareness |
| HIPAA | 45 CFR 164.308(a)(5) | Covered entities must implement a security awareness and training program for all workforce members |
| CMMC | AT.2.056 | Organizations must ensure that personnel are trained to carry out their assigned information security responsibilities |
PCI DSS v4.0 is worth paying special attention to. It's the first major framework to explicitly call out phishing simulation failure as a trigger for additional training requirements. If your business processes credit card payments, this one applies directly.
For businesses pursuing SOC 2 compliance or maintaining HIPAA requirements, documented phishing simulation results serve as concrete evidence during audits. The same logs that satisfy your insurance carrier also satisfy your compliance auditor.
Key takeaway: Six major frameworks require or recommend phishing simulation. The same evidence pack that satisfies your insurer also satisfies your compliance auditor.
We believe in being candid, even when the truth is complicated. So here it is.
The largest study ever conducted on phishing training effectiveness found that it barely works. Researchers at UC San Diego ran 10 phishing campaigns against 19,500 employees over eight months. The result: embedded training reduced click rates by just 2%. Seventy-five percent of users spent less than one minute on the training materials. A third closed them immediately.
Grant Ho and Ariana Mirian, the study's lead researchers, concluded that "anti-phishing training programs, in their current and commonly deployed forms, are unlikely to offer significant practical value in reducing phishing risks."
Bruce Schneier, one of the most respected voices in cybersecurity and a fellow at Harvard's Kennedy School, has been even more direct: "There is no evidence that the tests result in fewer incidences of successful phishing campaigns."
We're telling you to do them anyway, and here's why.
First, your insurance carrier requires a program regardless of the academic debate. What the carrier wants to know is whether you have one, whether you run it consistently, and whether you can show improvement over time.
Second, how you run phishing simulations matters more than whether you run them.
In December 2020, GoDaddy sent employees a phishing simulation promising a $650 holiday bonus during a year when actual bonuses had been canceled due to COVID. Five hundred employees clicked. They were told they'd "failed" and had to retake security training. The backlash became international news.
That's the wrong way to do it. Shame-based, gotcha-style simulations damage trust between employees and the IT team. They create anxiety. They turn security into something people resent instead of something people participate in.
The research on behavioral science is clear: positive reinforcement builds stronger security habits than punishment. Recognizing employees who report suspicious emails, celebrating team improvement trends, making cybersecurity awareness training feel collaborative instead of adversarial. That's what moves the needle.
The simulations that work aren't designed to catch people failing. They're designed to give people practice succeeding.
Key takeaway: The research says traditional phishing simulation barely moves the needle. Your carrier requires it anyway. The difference is in how you run it: positive reinforcement, not gotcha-style shame.
There's a second reason the old approach to phishing simulation is breaking down, and it has nothing to do with employee psychology.
The phishing emails your team trained to spot two years ago no longer look like the phishing emails arriving in their inbox today.
IBM's X-Force team demonstrated that AI can produce a phishing campaign in five prompts and five minutes that's as effective as one that took human experts sixteen hours to build. Harvard research found that 60% of recipients fall for AI-generated phishing emails, a success rate comparable to those crafted by experienced attackers. SentinelOne reported a 1,265% surge in phishing attacks linked to generative AI.
The old tells are gone. Bad grammar, generic greetings, suspicious formatting. AI-generated phishing reads like it was written by a colleague. In one case, attackers used a deepfake video of a company's CFO to authorize a $25 million wire transfer.
FBI Special Agent Robert Tripp from the San Francisco field office warned that criminals are using AI to build "highly targeted phishing campaigns" that produce messages "tailored to individual recipients with perfect grammar and style."
If your phishing simulation program still trains people to look for typos and misspelled URLs, you're preparing them for a threat that no longer exists. Modern simulations need to reflect modern attacks: well-crafted, personalized, and increasingly difficult to distinguish from legitimate communication.
Key takeaway: AI eliminated the old red flags. If your simulations still train people to spot typos and bad grammar, you're training for yesterday's threat.
Here's what the whole program looks like in practice for a small to mid-size business:
Monthly simulations, minimum. Consistent cadence is what carriers want to see. Monthly gives you twelve data points per year for trend analysis.
Varied attack templates. Mix email phishing with SMS (smishing) and voice (vishing) simulations. Rotate the scenarios: fake invoices, password resets, shipping notifications, calendar invitations. The goal is to reflect what real attackers send.
Immediate, educational follow-up. When someone clicks, they're redirected to a brief training module that explains what they missed and what to look for next time. Short, respectful, focused on learning.
A metrics dashboard. Track click rates, report rates (employees who flagged the email as suspicious), and training completion rates. These three numbers tell the full story.
Quarterly evidence exports. Package your results into a format your insurance carrier or compliance auditor can review. Campaign dates, participation rates, click-rate trends, remedial training completion. This is your evidence pack.
Recognition over punishment. Celebrate the employees and departments that improve. Recognize the ones who report phishing attempts correctly. Build a culture where reporting a suspicious email feels like the right thing to do, not an interruption.
We run this kind of program for businesses across California and Hawaii. The goal isn't to trick your employees. The goal is to give them practice, build muscle memory, and produce the records your insurance carrier expects to see.
If your current program doesn't look like this, or if you don't have one yet, your next insurance renewal is the right time to get it in place. Most of our clients tell us the hardest part was not knowing where to start. We're happy to walk you through what's involved. Schedule a conversation and we'll show you what the program looks like and what the carrier documentation should include.
Key takeaway: An insurance-ready program runs monthly, varies the templates, follows up with education instead of shame, and produces quarterly evidence exports your carrier can review.
Does cyber insurance require phishing simulation?
Most cyber insurance carriers in 2026 require a phishing simulation program as a condition of coverage. The application asks you to confirm the program exists. If you later file a claim, the carrier's investigation asks for records proving it was running, so checking "yes" without documentation to back it up can jeopardize the claim.
What happens if I fail a phishing simulation?
In a well-designed program, failing a phishing simulation triggers a brief educational module that explains what the phishing email looked like and how to recognize similar attempts. Under PCI DSS v4.0 Requirement 12.6.3.1, organizations must provide additional training to employees who fail simulations.
How often should you run phishing simulations?
Monthly is the cadence we recommend. It provides enough data points to demonstrate a trend if a carrier ever asks for proof, and it gives employees regular practice. Some compliance frameworks accept quarterly, though monthly is the safer benchmark.
Can my cyber insurance claim be denied for lack of phishing training?
Yes. Your insurance application is a legal document. If you represented that you conduct phishing simulations but can't produce records during a claim review, the carrier can deny coverage on the basis of material misrepresentation.
What is the best phishing simulation frequency for compliance?
Monthly simulations satisfy the requirements of most compliance frameworks. PCI DSS v4.0, NIST CSF 2.0, and SOC 2 all require ongoing security awareness programs, and monthly simulation results provide the strongest evidence during an audit or a claim review.
What should be on my cyber insurance checklist for phishing simulation?
Your checklist should include monthly simulation campaigns with documented send dates, click-rate trend data across at least two quarters, remedial training completion records for employees who clicked, departmental breakdowns, and a quarterly evidence export your carrier can review during renewal, an audit, or a claim investigation.
About this article: This analysis is based on Endsight's direct experience managing IT and cybersecurity for hundreds of California and Hawaiian businesses, current cyber insurance application requirements from major carriers, and the latest versions of each compliance framework cited. Last updated September 2026.