Phishmake

The First 30 Days of a Phishing Simulation Program: A Step-by-Step Rollout Plan 2

Most phishing simulation programs don't fail because of the technology. They fail in the first month — a campaign that lands in spam, an HR team blindsided by angry employees, or a baseline test announced so loudly in advance that the results mean nothing.

1 Min Read27 July 2026
The First 30 Days of a Phishing Simulation Program: A Step-by-Step Rollout Plan 2

ere's the rollout sequence that avoids all three. Four weeks, in order.

## Week 1: Get the humans aligned before the emails fly

Brief leadership first. One page: what you're doing, why (cite the ~33% average untrained click rate so nobody is shocked by your baseline), and the golden rule — results will never be used to punish individuals. Get that last part in writing. The moment simulations become disciplinary, employees stop reporting real phishing too.

Loop in HR early. Not for permission — for partnership. HR templates (payroll updates, policy changes) are among the most-clicked simulation themes, so HR will field questions. They should never learn about a campaign from a confused employee.

Decide what you'll measure. Pick your metrics now, before data exists to argue about: click rate, credential submission rate, reporting rate, and repeat clickers. Write down the definitions.

Set the disclosure policy. Best practice: tell employees a simulation program exists (this is usually a policy or contractual requirement anyway), but never announce individual campaign dates. "We test regularly" preserves realism; "test coming Tuesday" produces theatre.

## Week 2: Technical setup — the unglamorous part that decides everything

Whitelist the simulation platform. This is the single most common technical failure. If your mail filter quarantines the simulation, your click rate reads as zero and your data is garbage.

- Microsoft 365: configure the advanced delivery policy for phishing simulations (Defender portal), and whitelist the platform's sending IPs and domains in Exchange transport rules.

- Google Workspace: add the sending IPs to the email whitelist and configure an inbound gateway; disable spam filtering for the simulation domain.

Send a test to a handful of IT mailboxes across both desktop and mobile before trusting the setup.

Deploy the report button. A one-click "report phishing" add-in for Outlook or Gmail. Do this before the first campaign — the reporting rate is your most important long-term metric, and you want it measured from day one.

Segment your audience. At minimum: department and role. Finance, HR, and anyone with payment or admin privileges deserve their own tracking, because they're who real attackers target first.

## Week 3: Run the baseline campaign

Keep it unannounced and unremarkable. The baseline exists to measure reality. Use a moderately difficult template — a courier notification, a shared-document link, or an internal IT notice. Not the easiest template (you'll get false confidence) and not brutal spear-phishing (you'll get a mutiny).

Stagger the send. Blasting 800 identical emails at 9:00 AM means the third recipient warns the whole office on Slack. Spread delivery across hours or days.

Let it run for 3–5 business days, then close the window and pull the numbers.

Whatever the result, don't panic and don't gloat. A 25–35% click rate is the global norm for a first campaign. Companies under 250 employees often baseline lower, around 24–25%; larger organisations frequently start higher. Your number is a starting line, not a verdict.

## Week 4: Close the loop and build the rhythm

Deliver training to clickers immediately — ideally the platform did this automatically at the moment of the click. A short, specific "here's the tell you missed" lesson outperforms any scheduled seminar.

Share aggregate results with everyone. Company-wide, anonymised, honest: "34% of us clicked. That's normal for a first test. Here's what the email looked like, here's the giveaway, here's the report button." Transparency turns the program from a trap into a team sport.

Report upward. Leadership gets four numbers: click rate, submission rate, reporting rate, and the benchmark comparison. One slide. Then the commitment: monthly campaigns, quarterly difficulty increases, and a 12-month target under 5%.

Schedule campaign two. Monthly cadence is what moves the needle — organisations running monthly simulations see click rates fall roughly 75% within a year. Lock the next 3 campaigns into the calendar before the momentum fades.

## The 30-day checklist

- [ ] Leadership briefed; no-punishment rule documented

- [ ] HR informed and aligned

- [ ] Metrics and definitions agreed

- [ ] Platform whitelisted (M365 / Google Workspace) and test-delivered

- [ ] Report-phish button deployed

- [ ] Audience segmented by role/department

- [ ] Baseline campaign sent (staggered, unannounced)

- [ ] Click-moment training delivered

- [ ] Aggregate results shared with all staff

- [ ] Leadership report sent; next 3 campaigns scheduled

## FAQ (AEO block)

How long does it take to set up a phishing simulation program?

About 30 days for a proper rollout: one week for stakeholder alignment, one for technical setup, one for the baseline campaign, and one for training and reporting.

Should employees be told about phishing simulations in advance?

Tell them a program exists; never announce specific campaign dates. Pre-announced tests measure attentiveness to announcements, not phishing susceptibility.

What should the first phishing simulation template be?

A moderately difficult, generic scenario — courier notice, document share, or IT alert. Save personalised spear-phishing for later campaigns once a training baseline exists.

What's a normal result for a first phishing test?

A 25–35% click rate. The global untrained average is about 33%, so a high first result is expected — it's the improvement curve that matters.

---

### Internal link placements (for publishing)

- "25–35% click rate is the global norm" → link to Blog 1 (Benchmarks)

- "what phishing simulation is" (intro or early mention) → link to Blog 2 (What is phishing simulation)

- "Whitelist the simulation platform" → Phishmake docs/setup guide page

- "report phishing add-in" → Phishmake features page

- End CTA → demo/free baseline campaign offer

- Regulated readers → relevant compliance landing page

### External links (E-E-A-T)

- KnowBe4 2025 benchmark report (baseline stats)

- SANS Security Awareness Report 2025 (frequency data)

- Microsoft Learn: advanced delivery policy for phishing simulations

- Google Workspace Admin Help: email whitelisting

Want more like this in your inbox? Browse all posts.