Why quarterly phishing tests fail, and what monthly-per-person fixes
Sending one campaign to everybody every three months optimises for administrative convenience. Here is what changes when you pace per person instead.
By SafeLoop
The most common phishing-simulation schedule in enterprise security is one campaign per quarter, sent to everybody on the same morning. It is also close to the worst schedule available, and the reasons have nothing to do with content quality.
Everybody-at-once destroys the measurement
The first person to click tells the second person a test is running. In a large organisation, a simultaneous send means the later cohorts are measuring how fast news travels rather than how susceptible people are. Staggered, per-person delivery removes the effect entirely.
A quarter is longer than the memory
The teaching value of a failed simulation decays in hours, not weeks. If the consequence — a lesson, a conversation, anything — arrives at the next cycle, the person has forgotten the specific decision they made. Auto-enrolment inside a few minutes is the single highest-leverage change most programmes can make.
One campaign, resolved into the stages you can act on.
Uniform difficulty teaches the wrong half of the org
One template for everybody is either trivial for your engineers or unfair to your warehouse. Neither group learns anything. Difficulty tiered per person means the same campaign can be a genuine test for both.
What monthly-per-person looks like in practice
- Each person receives roughly one simulation a month, scheduled independently.
- A cool-down window prevents anybody being tested twice inside a week.
- Difficulty steps up after a pass and down after a failure.
- Channel is chosen by reachability, not by convenience.
The administrative argument for quarterly campaigns disappears once scheduling and enrolment are automated. What remains is a cadence that produces cleaner measurement and faster behaviour change for the same amount of human effort.
Keep reading
Related articles
Stop reporting completion: measuring human risk instead of attendance
Training completion measures whether people showed up. Here is a factor model that measures whether they are getting harder to attack.
Read article →Running simulations without wrecking trust
The fastest way to kill a report rate is to make people afraid of being wrong. Framing, manager comms, and the lures never to send.
Read article →The 2026 human risk benchmark: what 4.6 million simulations show
Phish-prone rates fall from 33.2% to 4.2% over twelve months — but two-thirds of that lands in the first ninety days.
Read article →