Running simulations without wrecking trust
The fastest way to kill a report rate is to make people afraid of being wrong. Framing, manager comms, and the lures never to send.
By SafeLoop
Simulated phishing is a test you run on colleagues without warning them of the specific occasion. That is defensible, and it stops being defensible quickly if the results are used as material for humiliation.
Lures never to send
- Redundancy, restructuring or termination notices.
- Bonus, pay-rise or payroll-error messages.
- Medical results, benefits changes or anything touching a family member.
- Charitable appeals tied to a live disaster.
These produce excellent click rates and lasting damage. A programme that needs distress to generate a result has a content problem, not a measurement opportunity.
Framing that holds up
- Announce the programme, its channels and its purpose before it starts.
- Report at team level publicly and at individual level privately.
- Make the reporting path trivially easy and thank every report, including the false positives.
- Never send a leaderboard of failures. Send a leaderboard of reporters if you send one at all.
We stopped naming people in the monthly update and our report rate doubled in six weeks. Nothing else changed.
Awareness lead, 4,200-person financial services firm
What managers need
Managers ask two questions: is my team a problem, and what do I do about it. Give them a department grade, the size of their repeat cohort, and the specific modules assigned. Do not give them a list of names to raise in a one-to-one unless your culture has genuinely earned it.
The goal is a workforce that tells you when something looks wrong. Every design decision that makes people feel watched rather than supported works directly against that.
Keep reading
Related articles
Why quarterly phishing tests fail, and what monthly-per-person fixes
Sending one campaign to everybody every three months optimises for administrative convenience. Here is what changes when you pace per person instead.
Read article →Stop reporting completion: measuring human risk instead of attendance
Training completion measures whether people showed up. Here is a factor model that measures whether they are getting harder to attack.
Read article →The 2026 human risk benchmark: what 4.6 million simulations show
Phish-prone rates fall from 33.2% to 4.2% over twelve months — but two-thirds of that lands in the first ninety days.
Read article →