Skip to content

Why quarterly phishing tests fail, and what monthly-per-person fixes

Sending one campaign to everybody every three months optimises for administrative convenience. Here is what changes when you pace per person instead.

By SafeLoop

The most common phishing-simulation schedule in enterprise security is one campaign per quarter, sent to everybody on the same morning. It is also close to the worst schedule available, and the reasons have nothing to do with content quality.

Everybody-at-once destroys the measurement

The first person to click tells the second person a test is running. In a large organisation, a simultaneous send means the later cohorts are measuring how fast news travels rather than how susceptible people are. Staggered, per-person delivery removes the effect entirely.

A quarter is longer than the memory

The teaching value of a failed simulation decays in hours, not weeks. If the consequence — a lesson, a conversation, anything — arrives at the next cycle, the person has forgotten the specific decision they made. Auto-enrolment inside a few minutes is the single highest-leverage change most programmes can make.

Delivered: 12,000 people (100%)Delivered100%Opened: 5,280 people (44%)Opened44%Clicked: 1,140 people (9.5%)Clicked9.5%Credentials submitted: 312 people (2.6%)Credentials submitted2.6%Reported to security: 4,690 people (39%) — the outcome we optimise forReported it39%
One campaign, 12,000 recipients. Every stage is a drill-down to the people in it — the bottom row is the number SafeLoop optimises for.

One campaign, resolved into the stages you can act on.

Uniform difficulty teaches the wrong half of the org

One template for everybody is either trivial for your engineers or unfair to your warehouse. Neither group learns anything. Difficulty tiered per person means the same campaign can be a genuine test for both.

What monthly-per-person looks like in practice

  • Each person receives roughly one simulation a month, scheduled independently.
  • A cool-down window prevents anybody being tested twice inside a week.
  • Difficulty steps up after a pass and down after a failure.
  • Channel is chosen by reachability, not by convenience.

The administrative argument for quarterly campaigns disappears once scheduling and enrolment are automated. What remains is a cadence that produces cleaner measurement and faster behaviour change for the same amount of human effort.

See these numbers on your own people

A twenty-minute demo runs a live campaign against a test group and produces your own provisional grade.

See your human risk in 20 minutes

Book a demo and we’ll run a sample campaign against a test group.