Concepts
Run a fair security awareness program
How to plan simulations and training people trust, from the first announcement to the quarterly review.
A security awareness program only works if people report things. People report things when they believe reporting is safe and that a mistake will be met with help rather than blame. Everything below is about keeping that belief intact while you measure and train. Where it is our opinion rather than how the product behaves, it says so.
Before anything is sent
- Tell people it is happening. Say that practice phishing will arrive, roughly how often, and what to do with it. You don't need to say when. In our experience the announcement does more for completion and reporting than any setting.
- Brief the people who will get the calls. Your service desk, HR and the security team should know a campaign is live, so a worried employee gets a calm answer.
- Agree what you will and won't use as a lure. We'd steer away from lures about pay cuts, layoffs, bonuses, health or bereavement. They work, and they cost you trust you need for the real thing.
- Involve HR, and a works council or union if you have one, before the first campaign, not after the first complaint. Explain what is recorded and who sees it.
Measure before you train
Run one simulation before the first training assignment. Without it, the first campaign after training looks like an improvement when it is just a starting point. The launch checklist puts this step in order with the rest of setup.
Count reports, not just clicks
A click rate on its own rewards people for ignoring email. The number that tells you whether people would catch a real attack is the reporting rate. In HRS, reporting a simulation counts in a person's favor in their ShieldScore, and someone who reports every lure scores better than someone who simply never clicks.
When you review a campaign, read the whole funnel: delivered, opened, clicked, submitted, reported. A campaign where clicks fell and reports rose is a better result than one where both fell.
Make the mistake the lesson
When someone clicks a practice lure in HRS, they land on a teachable moment: a short page that shows the message they just saw, marks what gave it away, and gives one thing to do differently. It does not scold, and it does not describe something that didn't happen. If they clicked but entered nothing, it does not talk about stolen passwords.
Keep your own follow-up in the same spirit. A note from a manager that starts with "I failed one of these last month" does more than a list of names.
Spend effort where the risk is
A single click is a bad moment. A second click on another campaign is a pattern. HRS shows repeat clickers separately for that reason, and targeted training for that group usually moves the organization's risk more than another all-staff module.
Keep it going
Pick a steady rhythm you can sustain. A simulation every month or so, spread over hours rather than sent at once, with a short module tied to what the last campaign showed, keeps the practice fresh without becoming background noise. Review the trend every quarter with the people who own the risk, using the executive overview rather than a single campaign.