Home Roadmap Resources Join Now
Back to Resources

Phishing Simulation Campaign Guide

A phishing simulation is when your IT team sends fake, safe "hacker" emails to your own employees to test if they will click them. Here is how to do it without making everyone angry.

Step 1: Get Permission and Set Goals

Never run a fake phishing test without telling upper management first. If people get confused, you need the bosses to know what is happening.

  • Tell the leaders: Tell the CEO or HR team when the test will happen. (Do not tell the regular employees, or the test won't work!)
  • Set a goal: The goal is NOT to trick people so you can punish them. The goal is to find out where your company is weak so you can give better training.

Step 2: Choose the Right Fake Email (The Lure)

You need to design an email that looks like a real attack, but is not too unfair.

Bad Ideas (Do not do this)

  • Pretending to be HR offering a surprise cash bonus. (Too cruel)
  • Pretending someone is fired. (Causes panic)
  • Using the exact real email address of your CEO without telling them.

Good Ideas (Do this instead)

  • A fake Microsoft 365 or Google Workspace "password expired" warning.
  • A fake package delivery notification from FedEx or UPS.
  • A fake LinkedIn connection request.

Include red flags: Make sure there are clues that the email is fake! For example, spell a word wrong on purpose, or make the sender address look slightly wrong (like `admin@rnlcrosoft.com` instead of `microsoft.com`).

Step 3: Run the Test Safely

You will need software to do this (like KnowBe4, GoPhish, or Microsoft Defender Attack Simulation).

  • Whitelist the simulation tool: Tell your email spam filters to let these specific fake emails through, otherwise your own security tools will block your test!
  • Start small: If your company has 500 people, test a group of 50 people first to make sure the software works correctly.
  • Send it out: Send the emails out over a few days, not all at the exact same minute. If everyone gets it at the same time, they will talk to each other and ruin the test.

Step 4: The Immediate Feedback (The "Oops" Page)

What happens when an employee fails the test and clicks the link?

  • Do not yell at them: The link should take them to a safe web page that says "Oops! You just clicked on a simulated phishing test."
  • Show them what they missed: On that page, show them the exact email they just clicked, and circle the red flags (like the fake email address) so they learn immediately.
  • Keep it short: The training on this page should take less than 3 minutes to read.

Step 5: Review the Results and Follow Up

After a week, look at the numbers.

  • Look at the click rate: What percentage of people clicked? If it's your first time, 20% to 30% is normal. Do not panic.
  • Look at the report rate: Did people use the "Report Phishing" button? This is actually more important than the click rate! A high reporting rate means your team is actively protecting the company.
  • Train the clickers: People who clicked the link should be assigned a 10-minute training video on email security.
  • Never punish: If you fire or publicly shame people for failing a phishing test, your employees will become scared of the IT department and will hide their mistakes in the future.