Quick answer: A phishing simulation program works when it follows six principles: run monthly (not annually), use templates that mirror your real industry and seasonal threats, deliver teachable-moment micro-training the instant someone clicks, give repeat-clickers an escalated track, test high-risk roles with spear-phishing and vishing, and route the data to the security team, managers, and the board. Announced, generic, or punitive simulations produce cost without behaviour change.
Key Takeaways
- Simulated phishing is the highest-signal awareness tool, and the most frequently misapplied.
- Frequency is the biggest lever: monthly campaigns build the reflex a single annual test cannot.
- Templates must mirror your real industry, role, and seasonal threats, not generic pretexts everyone already knows.
- The teachable moment (the five seconds after a click) is where the learning happens.
- Never announce simulations, never use them punitively, and always route the data to security, managers, and the board.
Simulated phishing is the highest-signal tool available for measuring and improving human resilience against the most common initial attack vector in enterprise security. It is also the most frequently misapplied.
Organizations that run phishing simulations poorly, with infrequent campaigns, generic templates, no follow-through on repeat-clickers, and no integration with training, get data without insight and cost without benefit. Done well, simulated phishing changes behaviour, produces actionable risk intelligence, and generates audit evidence that regulators and insurers take seriously. It is the measurement engine behind a continuous awareness program.
The difference between a program that works and one that merely runs comes down to six design principles.
Principle 1: Frequency Determines Effectiveness

A single annual baseline phishing simulation produces a snapshot, not a trend. Employees who are tested once a year and never again have no opportunity to build the pattern recognition that enables them to identify real phishing when it arrives. Retention from a single event degrades within weeks, as research on spaced repetition and contextual memory consistently demonstrates.
Effective programs run monthly simulated campaigns at a minimum. The cadence ensures that employees encounter simulated phishing across different seasons, pretexts, and delivery styles, mirroring the distribution of real campaigns. It also provides a continuous baseline against which behavioural improvement can be tracked.
Monthly frequency is not about catching employees out. It is about ensuring that the cognitive reflex for identifying suspicious messages stays sharp across the full twelve months of the year.
Principle 2: Templates Must Reflect the Real Threat Landscape
Generic phishing simulation templates, such as password reset requests, shipping notifications, and LinkedIn connection requests, test awareness of well-known pretexts that employees have already been warned about. They have limited diagnostic value because the high performers and the low performers may both pass for the wrong reasons.
Effective simulation templates are customized to the organization’s industry, role distribution, and the actual threat actors targeting their sector, informed by cyber threat intelligence. A financial services firm should see business email compromise pretexts and wire transfer urgency scenarios. A healthcare organization should encounter patient data requests and insurance portal credential harvesting. A law firm should be tested on client impersonation and document delivery payloads.
Seasonal customization matters too. Tax season, open enrolment, payroll updates, and holiday gift card requests, real threat actors exploit these windows systematically. Simulations that mirror the seasonal threat calendar train employees on the exact pretexts they will face when threat actors are most active.
3.4x higher click rate on industry-customized phishing templates versus generic templates, a sign they test real judgment, not familiarity.
Monthly the minimum cadence required to drive and sustain below-5% click rates across an organization.
68% of spear-phishing attacks target executives, finance, and IT administrators specifically.
Principle 3: The Teachable Moment Is the Training
When an employee clicks a simulated phishing link, the most valuable learning moment is the five seconds immediately after the click, before they realize what happened and before defensive rationalization sets in. That window is where effective simulation programs deliver their highest-impact intervention.
A teachable moment redirect is a landing page that explains, in plain language, what just happened: this was a simulated phishing attempt, here is what made it suspicious, and here is a two-minute micro-training on how to recognize it next time.

Organizations that deliver teachable moment redirects consistently report faster improvement in click rates than those that simply track the click and move on. The immediacy of the feedback is critical. Training that arrives in an email two days after the click event has lost the emotional and cognitive context that makes the lesson stick.
Principle 4: Repeat-Clickers Require a Different Response
In most organizations, 5 to 15 percent of employees account for the majority of phishing click events across repeated simulations. This cohort is not the average employee having a bad day. It is a group with a persistent behavioural pattern that a single micro-training intervention will not correct.
Effective programs treat repeat-clickers differently. Escalated reinforcement tracks deliver more frequent simulation exposure, more targeted content, and manager notification when the pattern persists. In high-risk roles, such as finance, executive assistants, and HR, repeat-clickers may warrant one-on-one coaching or role reassignment from high-exposure tasks until the behavioural data improves.
Identifying this cohort requires data. Monthly simulations with per-user tracking produce the longitudinal view needed to distinguish a one-time failure from a persistent pattern, and turn that view into measurable ROI. Annual programs produce no such view, every employee resets to zero at year-end.
Principle 5: Spear-Phishing and Vishing Require Separate Treatment
Mass phishing simulations test the general workforce against opportunistic attacks. Spear-phishing and vishing exercises test high-risk roles against targeted attacks, and the design requirements are fundamentally different.
Spear-phishing simulations targeting executives, finance leaders, and IT administrators use personalized pretexts built from open-source intelligence: LinkedIn profiles, organizational charts, press releases, and vendor relationships, the same reconnaissance behind a targeted penetration test. The goal is to test whether high-value targets can identify an attack specifically engineered to exploit their role and relationships.
Vishing, or voice-based phishing, exercises test the human response to phone-based social engineering: urgent calls from IT support requesting credentials, impersonation of executives requesting wire transfers, and external callers probing for internal process details. In organizations where phone-based fraud is a material risk vector, vishing simulations should run alongside email campaigns.
Principle 6: The Data Has to Go Somewhere Actionable
Phishing simulation data that lives in a platform dashboard and never surfaces to decision-makers is wasted intelligence. The output of a well-run simulation program should feed three audiences: the security team, management, and the board.
Security teams need per-user and per-department click and report rates, repeat-clicker cohort data, and trend lines that allow targeted intervention, feeding the broader managed SOC picture. Department managers need visibility into their team’s risk posture. Boards need the organizational risk score, the trend direction, and quantified evidence that the program is reducing human risk over time, the kind of governance a vCISO is built to deliver.
Monthly programme reports and quarterly executive summaries, not just raw data exports, transform a phishing simulation program from a security tool into a boardroom risk management asset.
Across the 260+ organizations Armour runs simulations for in 52+ industries, a small repeat-clicker cohort consistently drives most of the risk, and it only becomes visible with monthly, per-user tracking, never with an annual test.
Avoiding the Common Failure Modes
A few design decisions consistently undermine otherwise well-intentioned simulation programs. Announcing simulations in advance destroys measurement value: employees who know a test is coming behave differently than employees encountering an unexpected message. Running all campaigns from the same sending infrastructure allows technically sophisticated employees to whitelist the simulation domain, reporting clean results that reflect domain recognition rather than security judgment.
Using simulations as a punitive tool consistently backfires. Employees who fear punishment for clicking a simulated phish will not report real phishing they suspect they may have already engaged with. The reporting culture that effective awareness programs depend on requires psychological safety, not a consequence culture, which is why simulation belongs inside a broader security awareness culture.
The Bottom Line
The goal of simulated phishing is not to catch employees failing. It is to build the reflex that catches real attackers before they succeed. Run it monthly, make it realistic, teach at the moment of the click, escalate repeat-clickers, test high-risk roles separately, and put the data in front of the people who act on it. Armour’s managed cyber awareness training runs monthly simulated phishing customized to your industry, threat landscape, and seasonal risk calendar. Book a discovery call to see the methodology in detail.
Phishing simulation rarely works alone. It is one pillar of Armour’s managed cybersecurity services, operating alongside a managed Security Operations Center for detection, cyber threat intelligence on live adversary behaviour, vulnerability management for the technical layer, vCISO leadership for governance, and the all-in-one Armour 360 managed program.
Frequently Asked Questions
How often should you run phishing simulations?
A: Monthly at a minimum. A single annual test produces a snapshot, not a trend, and retention from one event fades within weeks. Monthly campaigns expose employees to different seasons, pretexts, and delivery styles, build durable pattern recognition, and provide the continuous baseline needed to measure behavioural improvement over time.
Should you tell employees in advance that a phishing simulation is coming?
A: No. Announcing a simulation destroys its measurement value, because people who know a test is coming behave differently than people encountering an unexpected message. The point is to measure genuine security judgment under realistic conditions, which only works when the simulation is indistinguishable from a real campaign until after the click.
What is a teachable moment in phishing simulation?
A: It is the immediate feedback delivered the instant an employee clicks a simulated phishing link, usually a landing page explaining that it was a simulation, what made the message suspicious, and a short micro-training on recognizing it next time. Delivered in the five seconds after the click, when attention is highest, it produces faster improvement than training sent days later.
Should phishing simulations be used to punish employees who click?
A: No. Punitive programs backfire: employees who fear consequences for clicking a simulation will hide real phishing they may have engaged with, which destroys the reporting culture effective awareness depends on. Simulations should build psychological safety and a strong report rate, not fear. Repeat-clickers need targeted reinforcement, not punishment.
What makes a phishing simulation template effective?
A: Realism matched to your organization. Generic pretexts everyone has already been warned about have limited diagnostic value. Effective templates are customized to your industry, roles, and the actual threat actors targeting your sector, and they mirror the seasonal threat calendar (tax season, open enrolment, payroll updates) when real attackers are most active.
About the Author
David Chernitzky is the CEO and Co-Founder of Armour Cybersecurity, a Toronto-based firm that protects organizations across North America from advanced cyber threats. He brings more than 25 years of cybersecurity and military cyber intelligence experience, having served as an officer in an elite technology unit before co-founding Armour. Armour’s team of military-intelligence veterans and senior advisors serves 260+ clients across 52+ industries with a 97% client retention rate.



