24/7 Support Available
Skip to main content
Beginner
Ongoing programme

Phishing Simulation Programme

How to run phishing simulations that build a stronger team rather than a resentful one: set a baseline, send realistic but fair tests, and turn every click into a moment of learning.

Prerequisites

  • Sign off from senior leadership, and ideally their agreement to be tested alongside everyone else.
  • A simulation platform, or a provider who can run the campaigns for you.
  • An accurate, current list of the people you want to include.
  • Short training content ready to show the moment someone clicks a simulated link.

Step-by-Step Instructions

Set the tone before you start

A phishing programme is about learning, not catching people out, and saying so up front protects trust. Tell staff that simulations are coming and explain why, without giving away the timing or the templates. When people understand the goal is a safer organisation, they engage with it instead of resenting it.

Measure a baseline

Run one simulation before any training so you know where you stand. Record the click rate, how many people report the email, and how quickly they report it. Reporting speed matters as much as the click rate, because a fast report can stop a real attack while it is still unfolding.

Build realistic but fair templates

Base your emails on the lures attackers actually use, such as a delivery notice, a shared document, or a message that appears to come from a manager. Vary the difficulty across the programme. Avoid cruel themes like fake redundancy notices or bonus promises, which cause real distress and teach nothing useful.

Tip

Match the scenario to the season. Attackers lean on tax deadlines, holiday delivery notices and payroll changes, so your tests land better when they reflect what people are genuinely expecting.

Make reporting easy

Give everyone a one click way to report a suspicious email, such as a report button in Outlook, and make sure reports reach the people who can act on them. A workforce that reports quickly is worth far more than one that simply avoids clicking, because reports give your security team early warning.

Teach at the moment of the click

When someone clicks a simulated link, show a short, friendly page that explains the clues they missed and how to spot the next one. Learning lands hardest in that moment. Keep it supportive, never publish names, and never tie results to disciplinary action, or people will simply stop engaging.

Repeat, vary and report on the trend

Run simulations regularly, monthly or quarterly, and change the themes so people cannot pattern match. Track click and reporting rates over time and share the trend with leadership. The goal is steady improvement across the organisation, and a culture where reporting a mistake feels normal.

Every organisation is different, and a playbook can only take you so far. If you would like a second pair of eyes, or you would rather we handled the work, our security awareness training team is here to help. Talk to us about your requirements.