Phishing Simulations Done Right: Build Skills Without Breaking Trust
How to run phishing simulations that sharpen your team's instincts without damaging trust, and how to pair them with training that makes the lessons stick.
The Artillo Team12 min read

October is Cybersecurity Awareness Month, and in many organisations that means a phishing simulation. The security team sends a fake email that looks like a real attack, counts how many people click, and follows up with training. Done well, it's one of the most practical ways to build real instincts, because people practise on messages that look exactly like the ones attackers send.
Done badly, a simulation teaches people that the security team is trying to catch them out. Employees feel tricked and embarrassed, they complain to their managers, and some of them stop reporting anything at all in case they get it wrong. That outcome leaves the organisation less safe than before the simulation. This guide covers how to plan, run and follow up on simulations that build skills without breaking trust.
1. Decide what you want to change
The goal is a workforce that pauses before acting on an unexpected request and reports suspicious messages quickly. A low click rate on a single campaign follows from that. Write the goal down before you design anything, because it shapes what you measure and how you respond when someone clicks.
It helps to state the goal in terms of behavior. For example, you might want most employees to report a suspicious email within an hour of receiving it, or you might want the finance team to confirm every change of bank details by phone. Goals like these point to specific lessons and specific measurements. A goal such as reducing the click rate to a certain percentage tends to push teams towards easier or harder emails to hit the number, which says little about real resilience.
2. Agree the rules before the first campaign
Simulations touch on sensitive issues: monitoring, trust and how people are treated when they make mistakes. Agree the ground rules with HR, legal and, where relevant, employee representatives before the first email goes out. Decide what data will be collected, who can see individual results and how that information will be used.
The most important rule is usually that simulation results are used only for learning, with no disciplinary consequences. Write that down and share it. Employees who know that clicking on a simulated email leads to a short lesson, and nothing more, are far more willing to engage with the program and to report their real mistakes when they happen.
Tell employees that simulations will take place, even if you don't say when. Announcing the program in general terms doesn't spoil the exercise. Attackers don't announce themselves, but people who know the organisation runs simulations tend to look more carefully at every email, which is exactly the habit you want.
3. Train first, then test
A simulation that arrives before anyone has been taught what to look for mostly measures luck. Start with short training on the warning signs, then test whether the lesson stuck.
Five red flags to teach first
- Urgency or pressure, such as "act now" or "your account will be closed"
- A sender name that doesn't match the actual address
- An attachment or link you weren't expecting
- A request to change bank or payment details
- Any request for a password or sign-in code
Keep each lesson short and focused on one scenario, and use real examples of the lures your industry receives. Teach the reporting step as carefully as the spotting step, since a quick report protects everyone else in the organisation.
Show people how to check a link before clicking, how to look at the real sender address on a phone as well as on a laptop, and what a legitimate request from your own IT team looks like. Many employees have never been shown these basics. They're simple to teach, and they give people the confidence to question a message instead of guessing.
4. Keep simulations realistic and fair
Realistic lures look like the messages your people genuinely receive, such as a shared-document notification or a delivery update. Some teams use lures about bonuses or layoffs because they get clicks. They also damage trust, and many organisations now avoid them for that reason. Raise the difficulty gradually instead of starting with the hardest email you can write.
Realistic lures vs. cruel lures
Avoid: cruel lures
- Fake bonus or pay-rise announcements
- Layoff or restructuring scares
- Health or family emergencies
- Starting with the hardest possible email
Use: realistic lures
- Shared-document notifications
- Delivery or shipping updates
- Invoice and payment queries
- Difficulty that increases over time
Fairness also means matching the simulation to what people have been taught. If the training covered mismatched sender addresses and urgent payment requests, the first simulations should test those signs. Introducing a new kind of lure that nobody has seen before is reasonable later in the program, as long as it's followed by a lesson on that lure.
Be careful with impersonation. A simulated email that appears to come from a real, named colleague or senior leader can cause confusion and resentment, especially if that person didn't know. Use generic senders or roles, or agree the approach in advance with anyone whose name will appear.
People who feel tricked hide their mistakes. People who feel coached report them, and reporting is what makes you safer.
5. Choose tools that fit your environment
Simulations are usually run with a dedicated tool, either a standalone product or a feature of your email security platform. Whatever you choose, test it carefully before the first campaign. Simulated emails need to reach inboxes without being blocked by your own filters, and links need to be tracked without triggering security alerts. The IT team will usually need to add the tool's sending servers to an allow list.
Check that the tool records reports as well as clicks, ideally through the same reporting button employees use for real phishing. If reporting a simulated email and reporting a real one feel different, people learn two habits instead of one. Make sure the landing page shown after a click can be customised, so you can write the explanation in your own words and in the languages your employees speak.
Finally, confirm where the tool stores its data and who can see it. Simulation results are sensitive, and the settings should match the privacy rules you agreed at the start. If the tool is run by an outside provider, ask how long they keep individual results and how those results are deleted when your contract ends.
6. Prepare the helpdesk and the security team
A simulation creates work for the people who answer questions. Employees will forward the email to the helpdesk, call to ask whether it's genuine or report that they clicked and are worried. If the helpdesk doesn't know a simulation is running, it may escalate a harmless test as a real incident, or give people conflicting advice.
Brief the helpdesk and the security operations team before each campaign, and give them a short script. Anyone who calls should be thanked for checking, told that reporting was the right thing to do and pointed to the reporting button for next time. Keep the helpdesk informed about when campaigns start and end, so they can tell the difference between a test and a real attack that happens to arrive at the same time.
7. Plan the timing and the audience
Sending the same email to everyone at the same moment rarely works well. Word spreads within minutes, people warn each other and the results reflect how quickly the news travelled more than how well anyone spots a phishing email. Spread each campaign over several days and vary the send times, so the experience is closer to a real attack.
Target the content to groups where it makes sense. Finance teams can receive invoice lures, while engineers might see a fake code-repository notification. Everyone can receive common lures such as a shared document or a parcel delivery. Avoid sending simulations during periods of known stress, such as the week of a restructuring announcement or the end of a financial year, when a failed test can feel particularly unfair.
8. Treat a click as a chance to teach
The half minute after someone clicks matters most. Show a short explanation of what they missed, without judgment, and offer a two-minute microlearning on that exact lure. Never name and shame anyone. People who click repeatedly need more support, and public exposure only teaches them to hide.
The 30 seconds after a click
- 1
Explain without blame
Show a short note on what gave the email away.
- 2
Teach the exact lure
Offer a two-minute microlearning on that specific trick.
- 3
Practise reporting
Show the one-click way to report the next suspicious email.
Write the landing page with care. A friendly tone, a clear explanation and an annotated copy of the email that highlights each warning sign turn an embarrassing moment into a useful one. Avoid words like failed or caught. Many people feel foolish when they realise they clicked, and a supportive message makes them far more likely to remember the lesson and to report the next suspicious email.
For people who click on several simulations in a row, offer extra support privately. That might be a slightly longer course on phishing, a conversation with someone from the security team or simply a check on whether their job exposes them to more suspicious email than most. Some people receive large volumes of external messages as part of their role, and they may need different tools or processes as well as more training.
9. Reward reporting
Reporting is the most valuable behavior you can build. A reported phish, real or simulated, gives the security team time to act before anyone else is caught. Make reporting a one-click action and thank people when they do it. Track the reporting rate alongside the click rate.
A quick, personal acknowledgement goes a long way. When someone reports a simulated email, tell them straight away that they spotted a test and did the right thing. When someone reports a real phishing email, let them know what happened as a result, if you can. People who see that their reports make a difference keep reporting, and they encourage their colleagues to do the same.
Some organisations also recognise teams with strong reporting rates in internal newsletters or meetings. Keep this positive and focused on reporting. Celebrating low click rates can backfire, because it encourages people to hide the fact that they clicked.
10. Look at trends across several campaigns
A single campaign is only a snapshot. Track click and reporting rates over several months, broken down by team and role, along with how long reports take to arrive. If finance keeps falling for invoice-change lures, that's where the next round of training should go.
Remember that results depend heavily on the difficulty of the lure. A campaign with a very convincing email will produce more clicks than one with obvious mistakes, even if the workforce hasn't changed at all. Compare campaigns of similar difficulty, or note the difficulty alongside each result, so that nobody reads a harder test as a decline in skills.
The time to first report deserves particular attention. In a real attack, the security team can often limit the damage if someone reports the email quickly, because they can block the sender and remove the message from other inboxes. A falling time to first report is one of the clearest signs that the program is making the organisation safer.
11. Remember phishing doesn't only arrive by email
Most simulation programs focus on email, because that's where most phishing starts. Attackers also use text messages, messaging apps, phone calls and even fake QR codes on posters and letters. A message that claims to come from a delivery company and asks the recipient to pay a small fee by following a link is as common by text as it is by email.

Include these channels in your training even if you don't simulate them. Show examples of suspicious text messages and explain how to check a caller's identity by hanging up and calling back on a known number. Remind people that the same warning signs apply everywhere: unexpected contact, urgency and a request for money, passwords or codes. Phone-based attacks deserve special attention for teams that handle payments or account changes, since a convincing call can bypass every email filter.
12. Protect the privacy of individual results
Simulation results are personal data, and they can be sensitive. A record showing that someone clicked on several fake emails could be embarrassing if it were shared widely, and it could be misused in decisions about promotion or discipline. Limit access to individual results to the small group who need them to run the program and provide support.
Decide in advance how long individual results will be kept, and delete or anonymise them after that period. Share aggregated figures by team and role for planning, and make sure teams are large enough that an individual can't be identified from the numbers. Being open about these rules with employees builds trust, and trust is what makes people willing to report.
13. A sample first year
For an organisation starting from scratch, a first year might look like this. The first month introduces the program with a message from leadership and a short baseline lesson on the warning signs, followed a few weeks later by a first, fairly easy simulation. Over the next few months, short lessons on specific lures alternate with simulations every six to eight weeks, each slightly harder than the last and targeted by role where it makes sense.
Halfway through the year, review the results with the security team and adjust the plan. Around Cybersecurity Awareness Month in October, run a more varied campaign alongside refreshed training for everyone. By the end of the year, you should be able to show a clear trend in reporting rates and time to first report, and you'll have a much better picture of where the organisation is most exposed.
A sample first year
Month 1
A leadership message, a baseline lesson and a first, fairly easy simulation.
Months 2 to 5
Short lessons on specific lures, with a simulation every six to eight weeks.
Month 6
Review the results with the security team and adjust the plan.
Months 7 to 11
Harder, role-targeted simulations and refreshed training for everyone.
Month 12
Compare reporting rates and time to first report with the start.
14. Connect simulations to the wider program
Simulations work best as one part of a broader security awareness program. They test whether lessons have stuck, and they show where more training is needed, but they can't teach everything. Pair them with a steady rhythm of short lessons on other risks, such as password hygiene, handling sensitive data and securing devices while working away from the office.
Use the results to decide what to teach next. If a campaign shows that people struggle with messages that arrive on their phones, the next lesson can cover checking links on a small screen. If a particular team rarely reports, their manager can raise the topic in a team meeting. The simulation becomes a regular source of information for the whole program.
15. Share results with leadership carefully
Leadership will want to know how the organisation is doing. Share trends and leave individual names out. A short summary covering reporting rates, time to first report and the areas where more training is planned gives leaders what they need without turning individual mistakes into a management issue.
Explain what the numbers can and can't tell them. A low click rate on one campaign doesn't mean the organisation is safe, and a high one doesn't mean the program is failing. What matters is the direction over time, and whether people are reporting suspicious emails faster than they were a year ago.
Common mistakes
The first common mistake is running simulations without training. It turns the program into a test nobody prepared for, and it produces results that mostly reflect luck. The second is using lures designed to shock or upset, which buy a few extra clicks at a heavy cost in trust.
Another mistake is focusing entirely on the click rate. A program that reduces clicks but doesn't increase reporting leaves the organisation exposed, because the few people who still click will do so quietly. The last is running one large campaign a year and treating it as the whole program. Security habits come from regular practice, and a single annual test can't build them.
How Artillo helps
Artillo covers the training side of a phishing program. Short security microlearnings and full courses are assigned by role with due dates, and automatic reminders and manager digests help get them finished. Use Artillo alongside your simulation tool to teach before you test and to follow up after a click with a short lesson on the exact lure.
Every completion is kept in an audit-ready record, with certificates and reports broken down by team. Training works on web and mobile, in Uzbek and Russian as well as English. Book a demo to plan your Cybersecurity Awareness Month campaign.
The Artillo Team12 min read


