Skip to content
Updated: 6 min read

Running simulated phishing campaigns in your organisation: A Rollout Plan for Team Managers

Simulated phishing campaigns teach employees to spot real threats without the risk of actual data loss — how to plan your first simulation, avoid a "blame the clicker" culture, and measure the team's progress over time.

Adrian Kwiatkowski Author: Adrian Kwiatkowski

A simulated phishing campaign sends employees a fake but harmless email imitating a real attack, to measure and raise vigilance without any risk of actual data loss. Effectiveness depends less on how hard the simulation is, and more on whether the organisation treats the result as a starting point for education rather than a tool for punishing whoever clicks.

Quick Overview

What you’ll learn from this article:

  • How to plan your first simulated phishing campaign without triggering team resistance
  • The most common rollout mistakes and how to avoid them — from an overly hard simulation to no follow-up
  • A step-by-step rollout plan for a manager responsible for team security
  • How to measure awareness progress over time, not just the result of a single campaign

Who this article is for: team managers responsible for rolling out a security awareness programme, security specialists planning their first simulation campaign, HR Business Partners working with the security team on programme communication.

Reading time: 7 minutes

Running simulated phishing campaigns in your organisation: a rollout plan for team managers

The first simulation campaign should be relatively easy to spot — the goal isn’t to catch as many people as possible, it’s to establish a baseline and build the habit of scrutinising suspicious messages. An overly hard first simulation (e.g. one that precisely impersonates a company’s real vendor) generates a high click rate that demotivates the team instead of educating it. NIST’s Phish Scale method rates simulation difficulty based on cues of suspicion (domain errors, context mismatches, time pressure) and how well the scenario fits the recipient’s everyday work — the more cues present, and the less the scenario matches the recipient’s reality, the easier the simulation is to spot.

The biggest rollout mistake is framing the programme as a tool for catching and punishing employees who click a link. That kind of messaging builds a culture of fear in which employees hide real incidents (e.g. actually clicking a genuine phishing link) out of fear of consequences — exactly the opposite of the intended effect. The programme should be communicated as training, similar to fire drills: the goal isn’t to find someone to blame, it’s to build a reflex for reacting in a real situation.

Common rollout mistakes and how to avoid them

MistakeEffectHow to avoid it
Overly hard first simulationHigh click rate demotivates the teamStart with a simulation carrying visible warning cues
Punishing employees who clickCulture of fear, hidden real incidentsCommunicate the programme as training, not an employee evaluation
No follow-up after a clickEmployee doesn’t know what they did wrong or how to spot it next timeAutomatic micro-training triggered immediately after clicking a simulation
A one-off campaign with no repeatsNo data on real behaviour change over timeRegular, progressively harder campaigns run quarterly

How to roll out a phishing simulation programme step by step

  1. Get leadership buy-in and clearly communicate the programme’s purpose to the team — a lack of transparency breeds distrust and reduces the educational effect.
  2. Establish a baseline with a first, relatively easy campaign — treat the result as a reference point, not a team evaluation.
  3. Design an automatic follow-up for anyone who clicks — a short micro-training explaining which cues indicated phishing in that specific message.
  4. Gradually increase the difficulty of subsequent campaigns, using the Phish Scale method to calibrate difficulty against the educational goal.
  5. Measure the trend over time, not a single result — a falling click rate across successive campaigns is a better measure of programme effectiveness than the result of any one simulation.

Campaign frequency matters — simulations that run too rarely (e.g. once a year) don’t build a lasting habit of vigilance, while ones that run too often (weekly) can cause fatigue and cynicism toward the programme. A quarterly rhythm, with scenario difficulty scaled up based on the team’s earlier results, usually strikes the best balance between building a habit and keeping people engaged.

It’s also worth involving internal communications before launching the programme, rather than treating it as an initiative that belongs solely to the security team. A short announcement telling the team that simulated phishing attempts will appear as part of a regular education programme (without revealing exact dates) lowers the sense of being surveilled and builds trust in the programme’s intent. Team managers should also receive aggregated, anonymised results for their team rather than a named list of who clicked — this lets them respond at the team level (e.g. with additional group training) without putting pressure on specific individuals, which again reinforces trust in the programme rather than avoidance of it.

Read Also

Develop Your Skills

Want to build a security awareness programme based on real simulations? Check out our training led by experienced EITT instructors.

➡️ Social engineering in cyber security — EITT training ➡️ Cyber security awareness training — EITT training

Frequently Asked Questions (FAQ)

How often should phishing simulations run?

A quarterly rhythm usually strikes the best balance — often enough to keep the team vigilant, but not so often that it causes fatigue with the programme. Frequency is worth tuning based on the results of previous campaigns and the size of the organisation.

No. Punishment builds a culture of fear in which employees hide real incidents out of fear of consequences. A more effective approach is an immediate, short micro-training explaining what indicated an attack, framed as education, not punishment.

What is the NIST Phish Scale method?

It’s a method for rating phishing simulation difficulty based on the number of suspicion cues (domain errors, time pressure, context mismatches) and how well the scenario matches the recipient’s everyday work. It helps calibrate the difficulty of successive campaigns against the educational goal.

How do you measure whether a simulation programme is actually working?

Track the trend in click rate across successive campaigns over time, not the result of a single simulation. A falling trend alongside gradually increasing scenario difficulty is the best available signal that the team is genuinely building the habit of spotting threats.

Adrian Kwiatkowski
Adrian Kwiatkowski Opiekun szkolenia

Request a quote

Develop Your Competencies

Check out our training and workshop offerings.

Request Training
Call us +48 22 487 84 90