Phishing uses convincing messages to obtain access, information or money. Alongside technical protection, people need to recognise suspicious requests and report them quickly. A regular, measurable simulation programme can help turn training into practical behaviour.
Why is phishing dangerous?
An attacker may impersonate a real organisation or person, requesting a login, opening an infected attachment, making an urgent payment or sending data. Correct spelling does not establish authenticity. Check the request, sender, destination and expected action together.
Why is one annual session insufficient?
A single training session can provide a foundation, but attendance does not show how people respond to real messages. NIST’s learning guidance emphasises role-specific learning, evaluation and continual programme improvement. Frequency and methods should reflect organisational risks.
Security awareness develops through repeated practice. Like any skill, it needs reinforcement to remain reliable under pressure.
This also supports regulatory expectations. NIS2 names cyber hygiene and staff training among risk management measures, while ISO/IEC 27001 requires awareness, education and training. A measurable recurring programme provides useful compliance evidence.
What does a recurring simulation programme provide?
Simulations add measurement, targeted follow-up and practical habits. Controlled, harmless emails model real attacks so the organisation can learn from responses.
Agree organisational authorisation, privacy arrangements and restricted access to results in advance. Do not collect real passwords; a training interface can record an attempted action without capturing credentials.
Measurement and visibility
Measure how many people click, attempt to submit data and report suspicious messages. Together, these measures give management a clearer view of human risk exposure.
Timely, contextual learning
A simulated link can lead to a short learning module explaining the warning signs in that message. Immediate feedback connects the lesson to a specific decision. Follow-up measurements should test whether learning has translated into improvement.
Reporting habits and culture
The programme can make reporting a natural response. Recognising and reporting a suspicious email, instead of silently deleting it, helps security teams detect and respond to genuine campaigns earlier.
What makes a good programme?
Effective programmes use a continuing series of role-specific campaigns, progressively adjusted difficulty, immediate learning and clear measures:
- Baseline: establish initial click and reporting rates.
- Regular scheduling: run monthly or quarterly campaigns at unpredictable times.
- Increasing difficulty: progress from simple lures to plausible internal messages, executive requests or supplier invoices.
- Immediate learning: offer brief, practical feedback after a click.
- Role-specific scenarios: finance may receive an invoice scenario, HR a CV attachment scenario and executives a business email compromise scenario.
- Review and iteration: adjust later campaigns based on results.
Annual training and continuous practice
| Factor | Annual training | Recurring simulation programme |
|---|---|---|
| Retention | Harder to apply without practice | Reinforced through repetition |
| Measurement | Attendance and knowledge tests | Adds behavioural measures |
| Changing threats | Content needs regular updates | New scenarios can be introduced |
| Targeting | General or role-specific | Role- and risk-based |
| Outcome | A knowledge foundation | Measured behavioural improvement |
What should we measure?
Click rates, reporting rates and repeat clicks should be assessed together as trends. No single figure gives the whole picture, and scenario difficulty affects comparisons.
| Metric | What it shows | Desired direction |
|---|---|---|
| Click rate | People who follow a simulated link | Downward |
| Reporting rate | People who report the suspicious message | Upward |
| Repeat clicks | Recurring difficulty recognising scenarios | Downward, with targeted support |
| Time to report | Time until the first report | Shorter |
| Data submission attempts | Actions beyond clicking | Downward |
Reporting is especially valuable. High reporting rates can show that employees help the organisation detect threats early. The aim is a sustained reduction in exposure and dependable reporting, rather than an unrealistic promise of zero clicks.
How do we avoid a punitive culture?
Position the programme as a learning tool. Public embarrassment and punishment can discourage precisely the behaviour needed most: reporting. Someone afraid of admitting a click may conceal a real incident, costing the organisation an early warning.
Practical principles include:
- Recognise reporting: acknowledge people who raise concerns.
- Include leadership: senior managers take part too.
- Keep feedback private and constructive: individual learning should be discreet.
- Communicate trends: reports focus on organisational progress.
- Support repeat difficulties: offer patient, targeted follow-up.
A healthy culture makes both acknowledging a mistake and reporting a suspicion safe, useful actions.
How zemITis helps
We design and operate awareness programmes from baseline assessment and recurring targeted simulations to management reporting. Our CISA, CISM and ISO 27001 / 42001 Lead Auditor expertise helps align the programme with regulatory and certification requirements.
Explore our security officer service and NIS2 preparation, then contact us to discuss how to strengthen your organisation’s security awareness.