All resources
Practical guide

Phishing simulation programme checklist

Plan a phishing exercise, give employees a clear reporting route and turn the results into useful follow-up.

Go to checklist

Start with the decision you want to practise

Choose a situation employees actually encounter: an unexpected invoice, a shared document or a request to sign in. Define what a safe response looks like before choosing the scenario.

An exercise is a learning opportunity. Agree who approves it, who handles reports and how employees can ask for help. Avoid publishing individual failure rankings.

Check delivery and reporting before launch

Pilot the exercise with an authorised test group. Verify that the message arrives as intended, the reporting route works and the right team receives the report.

Use the current configuration instructions for your environment. Do not disable mail protection broadly or copy old allowlists from an unrelated setup.

  • Record the audience, owner, dates and approved scenario.
  • Check language, accessibility and how remote or absent employees will participate.
  • Agree how to distinguish a simulation from a real incident during triage.

Teach the next action

Tell employees how to verify requests through a known channel and where to report something suspicious. CISA recommends recognising and reporting phishing; make the reporting process part of the exercise.

If someone interacted with a real suspicious message, they should contact the security team promptly and describe what happened. The response depends on whether they opened a link, entered information or downloaded a file.

Review results in context

Compare similar audiences and exercises. NIST’s Phish Scale explains why scenario difficulty matters when interpreting click and report rates. A harder scenario can change results without proving that the programme has deteriorated.

Choose one follow-up action, name its owner and set a review date. Record what changed so the next exercise has a useful baseline.

0 / 5 completed

Your review checklist

Use this checklist during your review. Selections are not saved when you leave the page.

Your review checklist

Sources and further reading

Continue your programme

Get started

See how your team can reduce human risk

Explore how Moxso helps your team identify employee risk, target training and assess progress. Tell us where you want to reduce exposure.

  • Explore how training, simulations and follow-ups address gaps.
  • See how human risk varies across your organization, departments and employees.
  • Review how your goals automatically steer risk reduction.

By submitting this form, you agree to our Privacy Policy.

ISO 27001-certified ISMSReview the certificate and its scope.
EU sovereign by architectureData sovereignty compliance built in.