You don't need to do vishing and smishing "simulations" with your employees.

Since we can all agree you're going to get victims (and they ARE being emotionally victimized, make no mistake about it), redirect that energy to hardening your defenses against the inevitable failures.

@malwarejake Reminds me of this guidance published by the NCSC:

https://www.ncsc.gov.uk/guidance/phishing#section_4

Phishing attacks: defending your organisation

How to defend your organisation from email phishing attacks.

National Cyber Security Centre - NCSC.GOV.UK