Security

Phishing Awareness Campaign: How to Build One That Works

A step-by-step phishing awareness campaign — baseline simulations, teachable-moment messaging, reporting culture, and metrics that actually shift behaviour.

Updated 29 July 2026
10 min read

A phishing awareness campaign that works does two things at once: it reduces the number of people who click, and it increases the number of people who report. This guide walks through the campaign structure that shifts both — simulation cadence, teachable moments, and the reporting culture that turns every employee into a sensor.

Why most phishing campaigns don't move the needle

  • They run one big awareness push, then go quiet for eleven months.
  • They punish clicks, which drives reports underground.
  • They train on generic examples instead of the phish your users are actually receiving.
  • They measure click rate only, ignoring the more important report rate.

The four building blocks

  1. Baseline simulation. Send one realistic phishing simulation to the whole organisation before the campaign starts. This is your reference point — never punished, never named, only measured.
  2. Teachable-moment landing page. When a user clicks, they land on a short page explaining exactly which signal in that email should have flagged it. Thirty seconds, one lesson.
  3. Reporting button, always visible. One-click "Report Phish" in the mail client. Public thank-you (aggregate, not individual) for every genuine report.
  4. Ongoing cadence. One simulation per month, escalating in difficulty. Rotate themes — HR, IT, finance, delivery — to cover real-world lures.

An eight-week rollout

Weeks 1–2 — Baseline and prime

Run a baseline simulation. Do not announce it. Follow with a company-wide message about the campaign, framed positively: we are getting better together.

Weeks 3–4 — Teach the signals

Publish short micro-lessons on the six most common signals: sender mismatch, urgency, unexpected attachments, credential prompts, look-alike domains, and generic greetings.

Weeks 5–6 — Report rate push

Focus every comm on reporting. Publish weekly leaderboards for the teams with the highest report rates. Recognise, don't reveal, individual reporters.

Weeks 7–8 — Advanced lures

Introduce more sophisticated simulations — spear-phish based on public information, SMS phish, MFA prompt bombing. Teach specific defences for each.

Metrics that matter

  • Click rate — trending downward, month over month.
  • Report rate — trending upward, month over month.
  • Time to first report — the earliest someone raised the alarm.
  • Repeat clickers — a small cohort that needs targeted coaching, not shaming.

Culture — the non-negotiable

The single biggest factor in phishing campaign success is whether people feel safe reporting. If IT is seen as an audit function, reports dry up. Publish visible thanks, close the loop on what was done with the report, and make sure the very first reporter each month is named (with permission) and celebrated. Culture beats content every time.

Related resources

Turn this topic into a complete campaign

Safety Campaign Hub generates posters, toolbox talks, safety alerts, and digital displays around any topic in minutes.