Start with the decision you want to practise
Choose a situation employees actually encounter: an unexpected invoice, a shared document or a request to sign in. Define what a safe response looks like before choosing the scenario.
An exercise is a learning opportunity. Agree who approves it, who handles reports and how employees can ask for help. Avoid publishing individual failure rankings.
Check delivery and reporting before launch
Pilot the exercise with an authorised test group. Verify that the message arrives as intended, the reporting route works and the right team receives the report.
Use the current configuration instructions for your environment. Do not disable mail protection broadly or copy old allowlists from an unrelated setup.
- Record the audience, owner, dates and approved scenario.
- Check language, accessibility and how remote or absent employees will participate.
- Agree how to distinguish a simulation from a real incident during triage.
Teach the next action
Tell employees how to verify requests through a known channel and where to report something suspicious. CISA recommends recognising and reporting phishing; make the reporting process part of the exercise.
If someone interacted with a real suspicious message, they should contact the security team promptly and describe what happened. The response depends on whether they opened a link, entered information or downloaded a file.
Review results in context
Compare similar audiences and exercises. NIST’s Phish Scale explains why scenario difficulty matters when interpreting click and report rates. A harder scenario can change results without proving that the programme has deteriorated.
Choose one follow-up action, name its owner and set a review date. Record what changed so the next exercise has a useful baseline.
Your review checklist
Use this checklist during your review. Selections are not saved when you leave the page.