Phishing campaign
A phishing campaign (phishing simulation) is an authorised, controlled security test in which an organisation deliberately sends its employees messages mimicking real phishing in order to measure susceptibility (click rate, submit rate), reinforce security awareness, meet regulatory requirements (NIS2 Art. 21, DORA Art. 13, GDPR Art. 32, ISO 27001:2022 A.6.3) and build a culture of reporting suspicious messages. It differs from a real attack on three counts: written board authorisation, no real financial consequences and immediate just-in-time microlearning after a click. A phishing campaign is not a one-off audit and not a substitute for an email security gateway — it is a continuous training programme whose mature form covers 12+ campaigns per year with escalating difficulty and industry benchmarking (Verizon DBIR, KnowBe4).
Phishing campaign (phishing simulation) — comprehensive guide (2026)
TL;DR — what is a phishing campaign and why run one?
A phishing campaign (phishing simulation) is an authorised, controlled security test in which an organisation deliberately sends employees messages mimicking real phishing — to measure susceptibility, reinforce awareness and meet NIS2, DORA, GDPR and ISO 27001:2022 A.6.3 requirements. Three things to know:
- What it is: a continuous training programme (12+ campaigns per year), not a one-off audit. It differs from real phishing in three ways: written board authorisation, no real financial consequences, and immediate just-in-time microlearning after a click.
- How it works: a 4-phase cycle — planning (goal + audience + KPI) → execution (scenario + payload + waves) → monitoring (real-time dashboard) → reporting and remediation (training assignments + lessons learned).
- Why it is needed: Verizon DBIR 2024 ranks phishing as the #1 initial access vector (36% of breaches). Mature programmes lower click rate from a ~14% baseline to <5% after 12 months (KnowBe4 benchmark). NIS2 Art. 21, DORA Art. 13, GDPR Art. 32 and ISO 27001 A.6.3 treat awareness training as a minimum requirement.
Phishing campaign vs real attack vs red team vs tabletop — comparison
In practice these four activities are often confused, even though they differ in intent, scope and legal framing. The table below clarifies the relationship:
| Trait | Real phishing attack | Phishing campaign (simulation) | Red Team engagement | Tabletop Exercise |
|---|---|---|---|---|
| Goal | Theft of data / money / access | Measure susceptibility + train | Test full defence (people + process + tech) | Review procedures and decisions, no action |
| Scope | Entire attack surface | Email + optionally SMS/voice | Multi-vector (phishing + network + physical) | Conference room, paper scenario |
| Intent | Hostile (criminal) | Educational + measurement | Adversarial (with mandate) | Educational + process |
| Legality | Illegal | Legal (board authorisation) | Legal (rules of engagement) | Legal (internal workshop) |
| Reporting flow | Attacker → victim, no feedback | Simulator → SOC → just-in-time training → quarterly board report | Red team lead → CISO → debrief | Facilitator → participants → action items |
| Tooling | Evilginx, Modlishka, EvilProxy, stolen GoPhish | KnowBe4, Cofense, SoSafe, Microsoft Attack Simulator, GoPhish | Cobalt Strike, Mythic, Sliver, custom C2 | No technical tooling |
| Employee consequence | Real (data theft) | None (educational landing + microlearning) | None (blue team exercise) | None (workshop) |
| Cadence | Continuous (attacker-driven) | 12+ campaigns per year | 1-4 times per year (expensive) | 2-4 times per year |
A phishing campaign does not replace a red team engagement — they are two different activities that complement each other in a mature security programme. A tabletop exercise tests incident response procedures, while a phishing campaign measures the behavioural exposure of employees.
What is a phishing campaign — operational definition
A phishing campaign is a planned, authorised cycle of sending employees messages that mimic real phishing, executed by the organisation’s IT/security team or an external service provider (such as nFlo). Messages are delivered through a real communication channel (email, SMS, phone, QR code), carry a realistic pretext (urgency hook, brand impersonation, sender spoofing), lead to a landing page controlled by the organisation (not the attacker) and are measured in real time (open, click, submit, report).
Three key differences vs real phishing:
- Written board authorisation — before launch there must be a rules of engagement document approved by CEO, CISO, IT, HR and the legal team. Without it you risk an HR incident as well as GDPR-style complaints.
- No real financial consequences — the landing page does not feed credentials into a harvester; it shows an educational message (“This was a simulation. Why was it phishing? — 1: sender mismatch, 2: time pressure, 3: unusual URL”).
- Just-in-time microlearning — a click triggers an immediate 60-120 second training (video, interactive module, short quiz). Without it the campaign measures exposure but does not reduce it.
A phishing campaign is a central element of a security awareness programme, codified in NIST SP 800-50 (Building an Information Technology Security Awareness Program) and ISO 27001:2022 A.6.3 (Information security awareness, education and training). It also maps to MITRE ATT&CK TA0001 (Initial Access) and technique T1566 (Phishing) — the simulation tests defences against exactly those techniques.
Why run phishing campaigns — five strategic reasons
(1) Baseline measurement. Without a campaign you do not know how many employees would click the first fake invoice they see. The first campaign establishes baseline click rate, submit rate and report rate, which becomes the reference point for every later metric. The industry baseline (KnowBe4 2024): click rate ~14%, submit rate ~4.7%, report rate 5-15%.
(2) Training reinforcement. A classic once-a-year security awareness training (compliance-check) has minimal effectiveness — knowledge decay sets in within 2-3 months. A monthly phishing campaign acts like spaced repetition: an employee tested regularly stays alert.
(3) NIS2 Art. 20 and Art. 21 awareness compliance. The NIS2 Directive obliges essential and important entities to implement cybersecurity risk management measures including basic cyber hygiene practices and training. The evidence of compliance (especially for an auditor) is documented phishing campaign results over time, showing progress in click rate and report rate.
(4) DORA Art. 13 ICT security awareness. The DORA Regulation (since 17 January 2025 for the financial sector) requires ICT security awareness programmes and regular testing. Phishing simulations are explicitly named as one of the testing mechanisms. For Threat-Led Penetration Testing (TLPT), social engineering elements including controlled phishing are mandatory.
(5) GDPR Art. 32, ISO 27001:2022 A.6.3, NIST CSF 2.0 PR.AT, SOC 2 CC1.4. GDPR requires “appropriate technical and organisational measures” — supervisory authorities regularly ask for evidence of training and simulations in complaint cases. ISO 27001:2022 control A.6.3 mandates awareness, education and training — without continuous campaigns it cannot be implemented in practice. NIST CSF 2.0 function PR.AT (Awareness and Training) and SOC 2 CC1.4 (workforce competence) both expect documented awareness activities. FTC, SEC and UK FCA guidance reinforce the same expectation for US and UK regulated entities.
4-phase phishing campaign methodology
Phase 1 — Planning
Pick the campaign goal (one of three): baseline measurement (first campaign in the organisation, no training before), training reinforcement (recurring campaign with escalating difficulty), regulatory evidence (documentation for a NIS2/DORA/ISO 27001 audit).
Define the target audience: entire organisation vs a specific department (finance, HR, board) vs specific roles (system administrators, executives, customer-facing staff). For a first campaign the recommendation is: entire organisation, generic template (bank/courier/Office 365).
Define KPIs: the first campaign measures the baseline, later ones measure progress against it. Mature target: click rate <5%, submit rate <1.5%, report rate >50%.
Scenario design: pick the pretext (urgency / curiosity / authority / fear / reward), sender domain (typo-squatting — nflo-pl.com instead of nflo.pl), payload (credential harvester landing / mock attachment / data submission form), localised copy.
Rules of engagement: written authorisation from CEO/CISO/IT/HR/legal, escalation procedure (what to do if a real attack hits in parallel), out-of-scope list (people on sick leave, maternity, carers leave), data retention policy consistent with GDPR.
Phase 2 — Execution
Configure the platform (KnowBe4 / Cofense / Microsoft Attack Simulator / GoPhish): import target list, pick template, customise copy and brand assets, set up the educational landing page, integrate with the LMS for microlearning.
Whitelist in the email security gateway: without this the simulation will be blocked by Defender for Office 365 / Proofpoint / Mimecast. It requires coordination with IT.
Wave timing: peak hours (10:00-11:00 or 14:00-15:00), business days (Tue-Thu, avoid Monday and Friday), distribution across 1-4 weeks (avoid mass-send in a single window — easy for staff to identify as a simulation).
Variable scenarios within the same campaign: different sender domains (bank / courier / IT helpdesk / HR), different urgency levels (low / medium / high), different payloads (link / attachment / QR code).
Phase 3 — Monitoring
Real-time dashboard: emails sent / delivered / opened / clicked / submitted / reported. Spot in-campaign anomalies (for example, a wave not reaching one department — possible email gateway block).
Identify repeat clickers (employees who clicked in 2-3 previous campaigns) — flag for dedicated coaching, not disciplinary action.
Just-in-time microlearning: every click triggers an immediate educational landing page + a 60-120 second video / interactive module. The employee does not wait for a monthly training session — they learn at the moment of the mistake.
SIEM integration: export events (sent / clicked / submitted / reported) to Splunk / Microsoft Sentinel / Elastic for SOC correlation with real attacks in the same window.
Phase 4 — Reporting and remediation
Quarterly executive summary to the board: aggregated metrics, comparison vs industry benchmark (KnowBe4 PhishER, Verizon DBIR), trend over time.
Departmental breakdown: per department, never per person (GDPR + culture). Identify departments with the highest click rate as priorities for dedicated training.
Training assignments: repeat clickers get an extended training programme (for example, additional 4-hour sessions), manager involvement, follow-up at 30/60/90 days.
Lessons learned for the blue team: scenarios that bypassed the email gateway despite whitelisting (rare but possible) feed the tuning of email security policies.
Update the security awareness programme — the next campaign builds on weaknesses identified in the previous one.
Phishing campaign types
In practice nFlo and most mature platforms (KnowBe4, Cofense, SoSafe) distinguish eight main types:
- Mass phishing simulation — generic templates, broad target. Pretexts: bank PIN reset, courier delivery (FedEx, DHL, UPS, Royal Mail), Office 365 password reset, Microsoft Teams notification. Baseline click rate: 12-18%.
- Spear phishing simulation — targeted, personalised. Pretexts: CEO impersonation aimed at an action officer, HR salary update sent to the finance team, internal IT helpdesk to new hires. Click rate: 30-60% (vs generic 12-18%) — see spear phishing.
- BEC (Business Email Compromise) simulation — CFO/CEO impersonation, wire transfer fraud. The trick is a realistic email thread with prior correspondence + urgency + authority + secrecy. See BEC.
- Whaling simulation — executive-targeted, research-based, tailored. Pretexts: M&A confidential, lawsuit, board document. Small volume (5-15 people), high effort per template. See whaling phishing.
- SMS / Smishing simulation — delivery codes (FedEx, DHL), banking alerts, OTP requests. Mobile blind spot — employees are less vigilant on a phone. See smishing.
- Vishing simulation — callback request, IT support pretext, fake bank fraud alert. Increasingly combined with voice cloning (ElevenLabs and similar) — simulating real deepfake vishing. See vishing.
- QR phishing / Quishing simulation — QR code in email, parking ticket, restaurant menu. KnowBe4 reported a 51% YoY rise in 2024. Bypasses most email security gateways (QR code rendered as an image).
- Attachment-based simulation — Word/Excel macros, ISO/IMG containers, HTML smuggling, OneNote payloads. Requires sandbox detonation in the email gateway — without it the simulation will not show the real defence.
Key phishing campaign metrics — 2026 benchmarks
| Metric | Definition | Baseline (new programme) | Target (after 12 mo.) | Benchmark source |
|---|---|---|---|---|
| Click Rate (CR) | % of recipients who clicked the link | ~14% | <5% | Verizon DBIR 2024, KnowBe4 |
| Submit Rate (SR) | % of recipients who entered data | ~4.7% | <1.5% | KnowBe4 industry baseline |
| Report Rate (RR) | % of recipients who reported via the Report button | 5-15% | >50% | Cofense Annual Report 2024 |
| Training Completion Rate | % of assigned trainings completed on time | ~60% | >90% | SoSafe Human Risk Review |
| Dwell Time | Time between delivery and click | <2 min | n/a (signal metric) | Microsoft Defender for Office 365 |
| Repeat Clicker Rate | % of employees with 3+ clicks per year | ~5-8% | <1% | KnowBe4 PhishER |
| Time To First Click (TTFC) | Seconds from delivery to first click | 30-90 s | n/a (signal metric) | KnowBe4 |
The most common interpretation mistake: an organisation looks only at CR. Report Rate is often more important — high RR with moderately elevated CR means a healthy security culture (employees sometimes click but immediately report). Low RR with low CR means insensitivity — employees do not click, but they also do not report, so a real attack will pass unnoticed.
Main tools / platforms in 2026
Full vendor landscape (alphabetical, with 2026 pricing model):
- Cofense PhishMe — focus on reporting culture, integrated with Cofense Triage (SOAR), ~$3-5 per user per month enterprise.
- GoPhish — open source, self-hosted, free. Requires in-house expertise. Ideal for small red team units and pentesters. No training content.
- Hoxhunt — Finnish startup, gamification, growing fast. Strongest personalisation in the market (ML-driven difficulty per user).
- Infosec IQ (Cengage) — solid mid-market option, broad content library.
- KnowBe4 — Gartner Magic Quadrant Leader 2024-2025, 65,000+ customers globally, the largest content library (1,000+ templates per locale), ~$2-4 per user per month enterprise.
- Lucy Security — Swiss, on-prem option for critical entities (public sector, critical infrastructure) where a cloud platform is a compliance blocker.
- Microsoft Attack Simulator — native to Microsoft 365 Defender, included in the E5 licence (no extra cost). Less content than KnowBe4, but enough for organisations already on Microsoft 365.
- Mimecast Awareness Training — post-Ataata acquisition, integrated with Mimecast email security.
- Proofpoint Security Awareness Training (PSAT) — enterprise-grade, integrated with Proofpoint email security gateway and Proofpoint Targeted Attack Protection.
- SANS Securing The Human — premium content, expensive (~$10-15 per user per month), executive-focused.
- SoSafe — German, GDPR-native, popular across the EU. Localised content on par with KnowBe4.
- Wizer Training — low-budget option, freemium model, for small companies without budget for KnowBe4.
Decision matrix: organisation on Microsoft 365 E5 → Microsoft Attack Simulator as a baseline + optionally KnowBe4 for content depth. Regulated B2B (NIS2/DORA) → KnowBe4 or SoSafe. Financial sector under DORA → Proofpoint PSAT (already running Proofpoint email security). In-house red team with zero budget → GoPhish.
Ethical and legal considerations
Board authorisation is non-negotiable. The mandate before launch must be written, approved by CEO, CISO, IT, HR and legal. Without it you risk: an HR incident (employees feeling deceived), supervisory complaints (GDPR Art. 6 lawful basis for processing), claims of breach of personal rights.
Naming and shaming is prohibited. Publishing the list of employees who clicked is doubly problematic: (1) it breaches GDPR (processing inconsistent with the original purpose), (2) it kills reporting culture for years — employees fear reporting because they see a “slip” is publicly punished. Report results aggregated per department, never per person.
Scenario content must not be traumatising. Forbidden: fake family deaths, fake child abductions, fake disciplinary action, fake severe illness. Beyond the ethics, they generate complaints and HR incidents. Stick to neutral pretexts: bank, courier, IT helpdesk, HR salary update, Office 365 password reset.
Comms strategy — when to reveal it is a test. Best practice: post-click via the educational landing page. The employee clicks → immediately sees a message “This was a simulation. Why was it phishing? — 1: sender mismatch, 2: time pressure, 3: unusual URL” + 60-120 seconds of microlearning. Never leave the employee without an explanation.
Employee behavioural data and GDPR. Campaign logs contain personal data (who clicked, when, how many times). Lawful basis: legitimate interest (Art. 6.1.f GDPR) with appropriate information in the employee privacy notice; some jurisdictions prefer a separate consent. Data retention: typically 12-24 months. DPO consultation is mandatory.
Equal treatment — do not target an individual or team for disciplinary purposes. A campaign must not be a tool to “catch” a specific employee or team — that directly breaches ethical and legal principles (harassment, discrimination). The target audience must be representative.
Repeat clickers — coaching, not punishment. A repeat clicker signals that the training programme is not working for that person — not a reason for disciplinary action. Introduce dedicated coaching, manager involvement, a longer training cycle. Disciplinary action only in extreme cases (for example, an employee deliberately bypassing training).
Inclusion of third parties / partners — separate consent. If the campaign is to test suppliers / partners / contractors, it requires separate consent and a separate rules of engagement document.
What a phishing campaign is NOT
NOT a replacement for the email security gateway. Even the best employee training will not replace the technical defence layers — Proofpoint, Mimecast, Microsoft Defender for Office 365 must run in parallel. The simulation measures the “last line of defence” (the human), but every earlier layer remains mandatory.
NOT a one-off event. A single campaign once a year will not change habits — knowledge decay sets in within 2-3 months. A continuous programme requires 12+ campaigns per year minimum (monthly cadence preferable).
NOT a pretext for disciplinary action. See above — repeat clickers need coaching, not punishment.
NOT a substitute for a red team engagement. A phishing campaign tests only the human layer. A red team engagement tests the full defence (people + process + tech) multi-vector. They are two different activities that complement each other.
NOT a substitute for a tabletop exercise. A tabletop tests incident response procedures (decision-making, escalation, communication). A phishing simulation does not answer the question “what will we do when a real phishing attack gets through”.
Phishing campaign best practices 2026
- Continuous programme — 12+ campaigns per year minimum, monthly cadence preferable. Without it, knowledge decay kills the ROI.
- Variable scenarios — different hooks (urgency / curiosity / authority / fear / reward), different sender domains (bank / courier / IT / HR / external), different urgency levels.
- Difficulty escalation — start easy (generic bank template), ramp difficulty over time (spear phishing, BEC, deepfake vishing).
- Just-in-time training — immediate microlearning after a click (60-120 seconds video, interactive module, quiz). Without it = measurement without learning.
- Peer reporting culture — incentivise the Report button. Strongest practice: a monthly leaderboard of top reporters (per department, aggregated — never naming and shaming clickers).
- Repeat clicker special tracks — dedicated coaching, manager involvement, follow-up at 30/60/90 days.
- Localised content — native templates for local employees (local banks, courier brands, payroll, tax office), not machine-translated EN.
- SIEM integration — export events to Splunk / Microsoft Sentinel / Elastic for SOC correlation with real attacks.
- Benchmark vs industry — KnowBe4 PhishER benchmark, Verizon DBIR, Cofense Annual Report. Raw CR without industry context is meaningless.
- Quarterly executive dashboard — board reporting with trend over time, comparison vs benchmark, ROI calculation (cost of incident avoided).
- Combine with incident reporting drills — sister activities: tabletop exercises, IR runbooks, SOC SOAR playbooks.
2026 trends in phishing campaigns
AI-generated personalised phishing. Generative AI (ChatGPT, Claude, Gemini) creates grammatically perfect phishing in any language, eliminating the “broken English” signal. Mature platforms (KnowBe4, SoSafe, Hoxhunt) already offer AI-generated templates as a simulation option.
QR phishing (Quishing) rise. KnowBe4 reported a 51% YoY rise in 2024. A Quishing simulation requires extra infrastructure (QR code as an image embedded in the email — bypasses most email gateways).
MFA fatigue attack simulation. Push notification spam to a mobile authenticator app until approval. The simulation requires integration with Microsoft Entra ID (formerly Azure AD) / Okta / Duo Security.
Adversary-in-the-Middle (AiTM) simulation. Evilginx2-style — the attacker proxies the session token rather than credentials. Phishing-resistant MFA (FIDO2, passkeys) is the only effective defence. The simulation educates employees about this category of attack.
Cloud-native phishing. Microsoft 365 OAuth consent phishing — the attacker asks for application consents (not credentials). The simulation must reproduce the consent flow end-to-end.
Cross-channel campaigns. Email + SMS + voice combo — higher pressure, more realistic scenario. Requires platforms with multi-channel support (KnowBe4, SoSafe, Cofense).
Behavioural risk scoring. Per-user risk profile, dynamic difficulty per employee. Hoxhunt leads this category.
Privacy-preserving simulation. Federated learning, no central user data — a requirement for critical entities (public sector, defence). Lucy Security is currently the only vendor with a mature offering.
Phishing-as-a-Service (PhaaS) parity testing. Mature programmes increasingly run simulations that mirror real PhaaS kits sold on dark forums (EvilProxy, Tycoon 2FA, NakedPages) so the training surface tracks the actual threat landscape.
How nFlo runs phishing campaigns
At nFlo (200+ clients, 500+ projects, 98% retention, <15 min SOC reaction time) phishing campaigns are delivered under the phishing simulations service as part of a wider cybersecurity portfolio. A typical engagement includes:
- Initial consultation — analysis of the client’s awareness programme maturity, identification of goals (baseline / training reinforcement / regulatory evidence), selection of scope (entire organisation / pilot for a specific department).
- Platform selection — depending on the client’s existing stack (Microsoft 365 E5 → Attack Simulator + optionally KnowBe4 for content depth; regulated B2B → KnowBe4 or SoSafe; financial sector → Proofpoint PSAT).
- Content localisation — native templates for native employees (local banks, courier brands, payroll, tax office) rather than machine-translated EN.
- Campaign execution — the 4-phase cycle (planning → execution → monitoring → reporting), with difficulty escalation over time.
- SOC integration — export events to the client’s SIEM (Splunk, Microsoft Sentinel, Elastic) or to our SOC 24/7.
- Quarterly executive report — a board-level dashboard with trend over time, comparison vs benchmark, ROI calculation.
For organisations in scope of NIS2 and DORA we also provide full audit documentation support — the phishing campaign as evidence of compliance with Art. 21 (NIS2), Art. 13 (DORA), A.6.3 (ISO 27001:2022). Where Threat-Led Penetration Testing (TLPT) under DORA is required, the phishing campaign is one of the mandatory social engineering elements within a full red team engagement.
FAQ — frequently asked questions about phishing campaigns
What is a phishing campaign in simple terms? An authorised security test in which an organisation deliberately sends employees messages mimicking real phishing — to measure susceptibility and teach them to recognise similar attacks. It differs from real phishing in board authorisation, no real financial consequences and immediate just-in-time microlearning after a click.
What are the key metrics? Click Rate (target <5% after 12 months), Submit Rate (target <1.5%), Report Rate (target >50%), Training Completion Rate (target >90%). Signal metrics: Dwell Time, Repeat Clicker Rate, Time To First Click.
Which tools to use in 2026? Enterprise: KnowBe4, Proofpoint PSAT, Cofense PhishMe, Mimecast. EU-native: SoSafe, Hoxhunt. Microsoft 365 native: Attack Simulator (included in E5). Open source: GoPhish. The choice depends on stack, regulations and content localisation.
Are they legally required? Yes — directly or indirectly: NIS2 Art. 20/21, DORA Art. 13, GDPR Art. 32, ISO 27001:2022 A.6.3, SOC 2 CC1.4, PCI DSS 4.0 12.10. Phishing simulations are the de facto evidentiary standard for auditors.
What mistakes should you avoid? No board authorisation, naming and shaming, traumatising scenarios, treating repeat clickers as a disciplinary problem, machine translation from EN, a once-a-year event, no SOC integration.
Related terms
- Phishing — the broader category of attacks the campaign simulates
- Social engineering — the superordinate category of manipulation
- Spear phishing — targeted variant, simulated in the second phase of a programme
- BEC (Business Email Compromise) — the most dangerous form, requiring a dedicated simulation
- Smishing — SMS phishing, a separate mobile-channel campaign
- Vishing — voice phishing, increasingly with voice cloning
- Whaling phishing — executive-targeted, the highest difficulty tier
- Red team — complementary multi-vector defence test
- Tabletop — complementary workshop on response procedures
- Social engineering testing — the parent service category
Explore our services
Want to deploy a mature phishing campaign programme in your organisation?
- Phishing simulations — phishing, smishing, vishing and quishing simulations delivered by nFlo
- SOC 24/7 — monitoring and response to phishing incidents, integrated with campaigns
- Audits — NIS2, DORA, ISO 27001 compliance audits — phishing campaign as evidence of compliance
- Security awareness training — employee education on recognising attacks
- Outsourcing DPO — GDPR consultation when designing the campaign (lawful basis, data retention)
A phishing campaign in 2026 is not an optional add-on to a security awareness programme — it is its operational core and the evidence of compliance with NIS2, DORA, GDPR and ISO 27001. A mature organisation runs 12+ campaigns per year with escalating difficulty, just-in-time microlearning, SOC integration and quarterly board reporting. nFlo supports 200+ clients in designing, delivering and maintaining such programmes.
Frequently asked questions
+ What is a phishing campaign in simple terms?
A phishing campaign (synonyms: phishing simulation, controlled phishing test, phishing as a service) is an authorised security test in which the IT/security team or an external provider sends employees email (or SMS, or phone) messages that imitate a real phishing attack. The goal is twofold: measure how many employees click a link or submit credentials, and teach them to recognise similar attacks in the future. The key differences vs real phishing: (1) there is written board authorisation, (2) there are no real financial consequences — the landing page is educational rather than a credential harvester, (3) after a click the employee immediately receives short microlearning (a 60-120 second video). In 2026 phishing campaigns are the de facto standard in regulated sectors — NIS2 Art. 21 indirectly requires them as part of an awareness programme, DORA Art. 13 names them explicitly for financial entities, and KnowBe4 reports that mature programmes lower click rate from a ~14% baseline to <5% after 12 months.
+ What are the key metrics of a phishing campaign?
Four primary metrics and three advanced. **Click Rate (CR)** — share of recipients who clicked the link. Verizon DBIR 2024 baseline: ~14%, target after 12 months of programme: <5%. **Submit Rate (SR)** — share of recipients who entered data (credentials, card data). KnowBe4 industry baseline: ~4.7%, target after training: <1.5%. **Report Rate (RR)** — share of recipients who reported the suspicious message via a Report Phishing button. Baseline for new employees: 5-15%, target for mature programmes: >50%. RR is often more important than CR because it measures active defensive posture. **Training Completion Rate** — share of assigned trainings completed on time. Advanced metrics: **Dwell Time** (time between delivery and click — typically <2 minutes, a hour-of-day risk signal), **Repeat Clicker Rate** (share of "serial clickers" with 3+ clicks in a year — they need dedicated coaching), **Time To First Click (TTFC)** — typically 30-90 seconds from delivery. In quarterly board reports use industry benchmarks from KnowBe4 PhishER or Cofense Reporter — raw CR without industry context is meaningless.
+ Which phishing campaign tools/platforms are used in 2026?
The landscape splits into three segments. **Enterprise leaders** (Gartner Magic Quadrant 2024-2025): KnowBe4 (65,000+ customers, ~$2-4 per user per month), Proofpoint Security Awareness Training (PSAT, integrated with Proofpoint email security), Cofense PhishMe (focus on reporting culture), Mimecast Awareness Training (post-Ataata acquisition). **Mid-market and EU-native**: SoSafe (German, GDPR-native, popular across the EU), Hoxhunt (Finnish, gamification, growing fast), Infosec IQ (Cengage), Lucy Security (Swiss, on-prem option for critical entities). **Cloud-native and open source**: Microsoft Attack Simulator (part of Microsoft 365 Defender, included in E5 at no extra cost for organisations already on Microsoft 365), GoPhish (open source, self-hosted, free, ideal for small red team units and pentesters), Wizer Training (low-budget option, freemium). **Niche**: SANS Securing The Human (premium content, expensive ~$10-15 per user per month, executive-focused). The choice depends on three factors: (1) integration with the existing Microsoft 365 / Google Workspace stack, (2) content localisation (native templates for native employees — not machine-translated EN), (3) SIEM integration (export to Splunk / Microsoft Sentinel for SOC correlation).
+ Are phishing campaigns legally required?
Yes — in many sectors phishing campaigns are required directly or indirectly. **NIS2 (Directive 2022/2555)** — Art. 20 places on the management of essential and important entities the duty of supervising cybersecurity risk management measures, including awareness; Art. 21 lists training, cyber hygiene and basic practices as minimum requirements. Phishing simulations are the de facto evidentiary standard that an awareness programme actually works. **DORA (Regulation 2022/2554)** — from 17 January 2025 for the financial sector (banks, insurers, asset managers, fintech, ICT providers) Art. 13 requires ICT security awareness programmes and testing, including threat-led penetration testing (TLPT) with social engineering elements. **GDPR Art. 32** — appropriate technical and organisational measures; in complaint cases supervisory authorities regularly ask for evidence of employee training and simulations. **ISO 27001:2022 A.6.3** (Information security awareness, education and training) — a requirement for all certified organisations. **NIST SP 800-50** (Building an IT Security Awareness Program) and **NIST SP 800-181** (NICE Framework) are the US reference documents, frequently cited in European policies as well. **SOC 2 CC1.4** (workforce competence) and **PCI DSS 4.0 Requirement 12.10** also expect documented awareness activities.
+ What mistakes should you avoid when running a phishing campaign?
Seven common mistakes. **(1) No written board authorisation** — without a C-level mandate (CEO, CISO, IT, HR, legal) you risk an HR incident or GDPR-style complaints. **(2) Naming and shaming** — publishing a list of employees who clicked breaches the GDPR principle of purpose limitation and kills reporting culture for years. Report results aggregated per department, never per person. **(3) Traumatising scenarios** — never use fake family deaths, fake child abductions, fake disciplinary action, fake serious illness. Beyond the ethics, they generate complaints and HR incidents. **(4) Repeat clickers treated as a disciplinary problem** — this is an anti-pattern. A repeat clicker signals that the training programme does not work for that person, not a reason for disciplinary action. Introduce dedicated coaching, manager involvement, a longer training cycle. **(5) Content machine-translated from EN word-for-word** — local employees easily recognise unnatural phrasing, artificially lowering click rate. Use native templates (local banks, postal/courier brands, tax office, payroll). **(6) One-off event** — a single campaign per year will not change habits. Minimum: 12 campaigns per year (monthly cadence), with escalating difficulty over time. **(7) No SIEM integration** — a campaign without event export to SIEM (Splunk, Microsoft Sentinel) loses detection value. Reported messages should feed the Email Security Gateway (Proofpoint, Mimecast, Defender for Office 365) as threat intelligence.