How to Set Up a Phishing Simulation: A Step-by-Step Guide for 2026
Updated
A phishing simulation is a controlled, fake phishing email that a company sends to its own employees to measure how many people click, enter credentials, or report it — without any real risk to data or systems. It's the single most effective way to find out whether your security awareness training is actually working before a real attacker finds out for you.
Nearly a third of untrained employees (33.1%) fail a baseline phishing test the first time they're tested, according to KnowBe4's 2025 Phishing by Industry Benchmarking Report, which analyzed 67.7 million simulated phishing tests. With consistent simulation and training, that number drops to roughly 5% within a year. The gap between those two numbers is the entire business case for running phishing simulations.
This guide walks through exactly how to set one up: preparing your environment, choosing a campaign type, launching it, and reading the results — plus the mistakes that quietly sabotage most programs.
What Is a Phishing Simulation?
A phishing simulation (also called a simulated phishing attack or phishing test) is a safe, internal exercise where an organization sends realistic-looking phishing emails to its own employees. The goal isn't to catch people out — it's to measure susceptibility, identify who needs more training, and build the habit of pausing before clicking.
Unlike a real phishing attack, a simulation:
- Comes from your security awareness platform, not an attacker
- Never harvests real credentials or deploys malware
- Redirects clickers to an instant training moment instead of a compromised account
- Feeds into reporting you can track over time
Before You Begin: Set Up Your Environment
Skipping setup is the number one reason phishing simulations produce misleading results — usually because the test email lands in spam, or IT accidentally "catches" it and alerts the whole company before it even reaches inboxes.
Before launching your first campaign, confirm three things:
- Whitelist your simulation platform. Add your phishing simulation tool's sending domains and IPs to the allow list in Microsoft 365, Google Workspace, or your email security gateway (e.g., Proofpoint, Mimecast). If you skip this step, spam filters can quietly block the test, and you'll get a false "0% click rate" that just means nobody saw the email at all.
- Confirm your user list is current. Most platforms only send simulations to registered users by default. If you want to test employees who haven't logged into the training platform yet, look for a "silent phishing" or unregistered-user sending option.
- Decide what you're testing for. A one-time baseline test and an ongoing training program require different setups. Get clear on the goal before you pick a campaign type — it changes everything downstream, from template selection to reporting cadence.
Step 1: Choose Your Campaign Type
Most phishing simulation platforms offer two core campaign types. Picking the right one up front saves you from re-running everything a month later.
One-Time Phishing Campaign
A single round of phishing emails sent to some or all of your organization. This is the right choice when you want to:
- Run a quick baseline test to see who clicks
- Measure awareness at a single point in time (e.g., before/after a training rollout)
- Quickly flag specific users who need follow-up coaching
One-time campaigns are ideal for onboarding a new security awareness program, satisfying an annual compliance requirement, or benchmarking a department before a bigger rollout.
Smart (Automated) Phishing Campaign
An ongoing, recurring simulation program that sends new templates on a schedule — weekly, biweekly, or monthly — without manual relaunching. This is the right choice when you want to:
- Continuously train employees with fresh, varied phishing scenarios
- Automatically enroll new hires as they join
- Track long-term trends in click rate and reporting rate
Security awareness practitioners generally recommend simulations every 2–4 weeks at minimum to build lasting habits without triggering fatigue or desensitization — a cadence that's only realistic with an automated, "smart" campaign rather than manual one-off sends.
Step 2: Design Realistic (But Ethical) Templates
Template choice determines whether your simulation measures anything useful. Two principles matter most:
Match current attack patterns. Generic "you won a prize" emails no longer reflect what employees actually face. Prioritize templates that mirror real 2026 threats: business email compromise (invoice or wire-transfer requests), credential-harvesting login pages, QR-code phishing ("quishing"), MFA-fatigue prompts, and SMS or voice-based lures. AI-generated phishing emails now account for the large majority of attacks detected in the wild, and they read far more convincingly than the typos-and-urgency templates of a few years ago — your simulations should keep pace.
Stay proportionate and transparent. Avoid lures that impersonate sensitive topics like layoffs, bonuses, health benefits, or a colleague's personal crisis — these erode trust even when technically effective. Tell employees, at a program level, that phishing simulations will happen periodically (without revealing exact timing or templates). Programs that are transparent about their existence — while keeping specifics a surprise — see meaningfully higher reporting rates than programs run in total secrecy.
Step 3: Segment and Schedule Your Send
- Spread delivery across different days and times so employees don't compare notes in real time — a Tuesday-morning email that everyone in Slack is discussing by 10am stops being a useful test.
- Add role-based targeting for high-risk groups like finance, HR, and executive assistants, who are disproportionately targeted by BEC and wire-fraud attempts in real attacks.
- Include new hires automatically if you're running a recurring program — day-one employees are consistently among the highest-risk group, since they haven't yet absorbed company norms for verifying requests.
Step 4: Launch and Monitor Results
Once the campaign is live, track results in real time: emails sent, opened, clicked, and "phished" (credentials or data submitted). But click rate alone is a shallow metric — it tells you who failed, not whether the program is working.
Track these instead:
- Report rate — the percentage of employees who correctly flagged the email as phishing. This is a stronger leading indicator than click rate, and it's the number that most directly predicts whether employees will catch a real attack.
- Time-to-report — how quickly employees flag suspicious emails, since a 5-day delay on a real attack is functionally the same as never reporting it.
- Repeat-clicker rate — a small percentage of employees who click on nearly every simulation, regardless of topic. This group needs targeted coaching, not another generic module.
Step 5: Close the Loop With Training, Not Punishment
The single biggest driver of program failure isn't a bad template — it's what happens after someone clicks. Best practice is to deliver an immediate, short (2–3 minute) training moment explaining exactly what indicator they missed, rather than a generic "you failed" notice.
Avoid public leaderboards of "worst performers," disciplinary action tied to simulation results, or manager-cc'd shame emails. Research on security awareness programs consistently finds that punitive approaches backfire: they suppress future reporting, damage trust in leadership, and make employees less likely to report a real attack out of fear of consequences. Organizations that frame simulations as skill-building — not entrapment — see both higher engagement and better long-term click-rate reduction.
How Often Should You Run Phishing Simulations?
At minimum, every employee should receive one simulation per quarter to establish a trend line. For meaningful behavior change, monthly simulations are the widely recommended baseline, with many mature programs running every 2–4 weeks. Organizations that maintain a consistent monthly cadence with immediate feedback typically see a 40%+ drop in phishing-prone employees within 90 days, and long-term click rates that stabilize in the low single digits after about a year — down from an industry-wide baseline of roughly 33% on an untrained population.
Common Phishing Simulation Mistakes to Avoid
- Skipping the whitelist step and mistaking spam-filtered emails for a low click rate.
- Testing too rarely (once a year) to build any real habit change.
- Testing too often with no variety, training employees to recognize your simulation platform rather than phishing in general.
- Using shame-based reporting (public leaderboards, manager call-outs) that suppresses future reporting of real attacks.
- Ignoring report rate and optimizing only for a lower click rate, which can be gamed without actually improving detection skills.
- Never testing new hires or unregistered users, leaving your newest and most vulnerable employees untested.
Ready to run your first phishing simulation?
Wizer's phishing simulation platform supports both one-time and Smart Phishing campaigns, built-in whitelisting guidance, and instant micro-training for anyone who clicks. See the full setup walkthrough in the Wizer Knowledge Base.
FAQ:
A one-time campaign sends a single round of phishing emails and is best for a baseline test or quick check. A smart (automated) campaign runs continuously on a schedule, rotating templates and automatically enrolling new employees, and is better suited to an ongoing security awareness program.
At minimum quarterly, to track a usable trend line. Most security awareness practitioners recommend monthly simulations, with high-maturity programs running every 2–4 weeks.
Untrained populations average around 33% click rates on a baseline test. After roughly a year of consistent simulation and training, well-run programs typically bring that down to the low single digits (1.5%–5%, depending on industry).
Yes, at a program level. Best practice is to disclose that simulated phishing tests are part of the security program without revealing specific timing or templates. This keeps the test valid while avoiding the trust and morale damage of a fully secret program.
They should receive immediate, short, educational feedback explaining what they missed — not punishment. Public shaming or disciplinary action tends to suppress future reporting of real phishing attempts.