Phishing Awareness Campaign: How to Build One That Works
A step-by-step phishing awareness campaign — baseline simulations, teachable-moment messaging, reporting culture, and metrics that actually shift behaviour.
A phishing awareness campaign that works does two things at once: it reduces the number of people who click, and it increases the number of people who report. This guide walks through the campaign structure that shifts both — simulation cadence, teachable moments, and the reporting culture that turns every employee into a sensor.
Why most phishing campaigns don't move the needle
- They run one big awareness push, then go quiet for eleven months.
- They punish clicks, which drives reports underground.
- They train on generic examples instead of the phish your users are actually receiving.
- They measure click rate only, ignoring the more important report rate.
The four building blocks
- Baseline simulation. Send one realistic phishing simulation to the whole organisation before the campaign starts. This is your reference point — never punished, never named, only measured.
- Teachable-moment landing page. When a user clicks, they land on a short page explaining exactly which signal in that email should have flagged it. Thirty seconds, one lesson.
- Reporting button, always visible. One-click "Report Phish" in the mail client. Public thank-you (aggregate, not individual) for every genuine report.
- Ongoing cadence. One simulation per month, escalating in difficulty. Rotate themes — HR, IT, finance, delivery — to cover real-world lures.
An eight-week rollout
Weeks 1–2 — Baseline and prime
Run a baseline simulation. Do not announce it. Follow with a company-wide message about the campaign, framed positively: we are getting better together.
Weeks 3–4 — Teach the signals
Publish short micro-lessons on the six most common signals: sender mismatch, urgency, unexpected attachments, credential prompts, look-alike domains, and generic greetings.
Weeks 5–6 — Report rate push
Focus every comm on reporting. Publish weekly leaderboards for the teams with the highest report rates. Recognise, don't reveal, individual reporters.
Weeks 7–8 — Advanced lures
Introduce more sophisticated simulations — spear-phish based on public information, SMS phish, MFA prompt bombing. Teach specific defences for each.
Metrics that matter
- Click rate — trending downward, month over month.
- Report rate — trending upward, month over month.
- Time to first report — the earliest someone raised the alarm.
- Repeat clickers — a small cohort that needs targeted coaching, not shaming.
Culture — the non-negotiable
The single biggest factor in phishing campaign success is whether people feel safe reporting. If IT is seen as an audit function, reports dry up. Publish visible thanks, close the loop on what was done with the report, and make sure the very first reporter each month is named (with permission) and celebrated. Culture beats content every time.
Related resources
Turn this topic into a complete campaign
Safety Campaign Hub generates posters, toolbox talks, safety alerts, and digital displays around any topic in minutes.
Related resources
How to Run a Security Awareness Campaign
Turn dry security policies into engaging, measurable campaigns. Covers phishing, password hygiene, physical security, and reporting culture.
SecurityPassword Security Awareness Campaign Guide
How to run a password security awareness campaign that actually changes habits — passphrases, MFA adoption, and password manager rollouts.
SecurityInsider Threat Awareness: Campaign Blueprint
Design an insider threat awareness campaign that raises signal without creating suspicion — warning signs, reporting channels, and a no-blame culture.