Step 1: Get Permission and Set Goals
Never run a fake phishing test without telling upper management first. If people get confused, you need the bosses to know what is happening.
- Tell the leaders: Tell the CEO or HR team when the test will happen. (Do not tell the regular employees, or the test won't work!)
- Set a goal: The goal is NOT to trick people so you can punish them. The goal is to find out where your company is weak so you can give better training.
Step 2: Choose the Right Fake Email (The Lure)
You need to design an email that looks like a real attack, but is not too unfair.
Bad Ideas (Do not do this)
- Pretending to be HR offering a surprise cash bonus. (Too cruel)
- Pretending someone is fired. (Causes panic)
- Using the exact real email address of your CEO without telling them.
Good Ideas (Do this instead)
- A fake Microsoft 365 or Google Workspace "password expired" warning.
- A fake package delivery notification from FedEx or UPS.
- A fake LinkedIn connection request.
Include red flags: Make sure there are clues that the email is fake! For example, spell a word wrong on purpose, or make the sender address look slightly wrong (like `admin@rnlcrosoft.com` instead of `microsoft.com`).
Step 3: Run the Test Safely
You will need software to do this (like KnowBe4, GoPhish, or Microsoft Defender Attack Simulation).
- Whitelist the simulation tool: Tell your email spam filters to let these specific fake emails through, otherwise your own security tools will block your test!
- Start small: If your company has 500 people, test a group of 50 people first to make sure the software works correctly.
- Send it out: Send the emails out over a few days, not all at the exact same minute. If everyone gets it at the same time, they will talk to each other and ruin the test.
Step 4: The Immediate Feedback (The "Oops" Page)
What happens when an employee fails the test and clicks the link?
- Do not yell at them: The link should take them to a safe web page that says "Oops! You just clicked on a simulated phishing test."
- Show them what they missed: On that page, show them the exact email they just clicked, and circle the red flags (like the fake email address) so they learn immediately.
- Keep it short: The training on this page should take less than 3 minutes to read.
Step 5: Review the Results and Follow Up
After a week, look at the numbers.
- Look at the click rate: What percentage of people clicked? If it's your first time, 20% to 30% is normal. Do not panic.
- Look at the report rate: Did people use the "Report Phishing" button? This is actually more important than the click rate! A high reporting rate means your team is actively protecting the company.
- Train the clickers: People who clicked the link should be assigned a 10-minute training video on email security.
- Never punish: If you fire or publicly shame people for failing a phishing test, your employees will become scared of the IT department and will hide their mistakes in the future.