How to run a phishing simulation: a step-by-step programme
Running a phishing simulation well is less about the fake email and more about the loop around it. Here’s how to plan, run and follow up in a way that actually builds awareness.
Start with goals and buy-in
Before any email goes out, agree what "success" means — usually a lower click-rate and a higher, faster report-rate over time — and get leadership and HR on board. Frame it as training, not testing, and commit to a blame-free approach up front.
The programme loop
- Plan — choose a realistic, fair scenario relevant to your people (a supplier invoice, an HR notice, an MFA prompt), and define who receives it.
- Send — deliver the simulated campaign, ideally spread over a window so results aren’t skewed by one person warning everyone.
- Measure — record who clicked, who submitted data, and crucially who reported, and how quickly.
- Teach — the moment someone clicks, show a short, friendly explainer of the red flags they missed. This "teachable moment" is where learning happens.
- Repeat — run again with a different scenario. Behaviour changes through spaced repetition, not a single test.
Design fair scenarios
Effective lures mirror the phishing your staff actually face. Vary difficulty over time, and avoid cruel themes (fake bonuses, layoffs, bereavements) that damage trust. The goal is recognition of real patterns, not maximising the click count.
Follow up and report
- Share aggregate results with leadership — trends, not individuals.
- Celebrate reporting: highlight that fast reporting is the win.
- Give extra, supportive training to groups that need it — never punishment.
- Track the trend across campaigns so you can prove improvement.
FAQ
Related questions
How long should a phishing simulation programme run?
Indefinitely — it’s ongoing, not a project with an end date. Behaviour drifts back without reinforcement, so most organisations run simulations monthly or quarterly on a continuous basis.
Who should be included?
Everyone, including leadership and IT. Attackers target executives (whaling) and technical staff too, and excluding them creates blind spots and a sense that the rules don’t apply to everyone.
What makes a simulation realistic?
Scenarios that match real-world lures your people encounter — supplier and invoice themes, internal notices, delivery and MFA prompts — at a difficulty that rises gradually as awareness improves.
Keep reading
More guides
-
Ethical phishing simulations: how to test without breaking trust
A phishing simulation can build a security culture — or destroy it. The difference is ethics: blame-free, fair lures, and coaching over shaming.
Read guide -
Measuring phishing simulations: the metrics that matter
Click-rate is only half the story. Report-rate and reporting speed tell you whether your people are becoming a real defence.
Read guide