You can configure every security control correctly and still lose a mailbox because one person clicked a convincing link on a busy Tuesday. Technical defenses stop most attacks; training is what handles the ones that get through, by turning your team from the target into the alarm system.
This guide covers how to run phishing awareness training that actually changes behavior: how to baseline, what to teach, how to run simulations without wrecking trust, and which numbers to track. There's a red-flags checklist you can copy at the end.
Measure where you stand with a baseline simulation. Write a one-page policy with a single, obvious way to report. Run a short, example-driven session rather than a slide deck. Follow it with regular, realistic simulations. Track reporting rate at least as closely as click rate, and never punish people who click.
Before You Start
Know who's highest risk. Finance, HR, executives, and anyone who can change bank details or approve payments. They receive the most convincing lures and the costliest ones.
Get a baseline. Run a simulation before you train anything, so you can show improvement later.
Secure leadership buy-in, including leadership's own participation. A program the executives skip is a program nobody takes seriously.
Decide your reporting route before training, because the first thing people will ask is "what do I actually do?"
Budget realistically: an initial session of under an hour, then short monthly touchpoints.
Check your technical baseline. Training complements controls; it doesn't replace them. Make sure 2FA is rolled out and your domain is authenticated first. See our 2FA rollout guide and business email security best practices.
Step 1: Baseline Your Risk
Send one simulated phishing email before any training, using a platform like GoPhish (open source, needs technical setup) or a commercial simulation tool. Track three things: who clicked, who entered credentials, and who reported.
Segment by department. Finance and HR often click more, not because they're careless, but because invoices and résumés from strangers are their actual job.
Then look backwards: have you had real incidents? What was the entry point? Real attempts against your own company make the best training material, far better than generic examples.
Two practical notes before you send anything. Simulation tools send mail that deliberately imitates attacks, so you'll usually need to allowlist the sending infrastructure, and you should confirm with your provider that this won't affect your domain's reputation. And tell your leadership what's going out, so the first report doesn't trigger an incident response.
Pro tip: Never publish individual click results. Share aggregate numbers only. The moment people fear being named, they stop reporting, and reporting is the behavior you're buying.
Step 2: Write the Policy and Make Reporting Effortless
One page, in plain language, covering what phishing is, the red flags, and exactly what to do. The reporting instruction should be a single sentence:
"If an email looks suspicious, don't click anything. Use the Report Phishing button in your mail app, or forward it to phishing@yourcompany.com. Then delete it."
Make that address exist before you publish the policy. A group or shared address works well here, so several people see reports and nothing depends on one person being at their desk. See aliases, mailboxes, and groups and our shared team inbox guide.
Add one more line that matters more than any other: reporting a click is never punished. The expensive scenario isn't someone clicking; it's someone clicking and saying nothing for three days.
Pro tip: Give the team a rule for the pressure cases: any request to change bank details, send a payment, or buy gift cards gets verified by phone on a known number, no matter who it appears to come from. That single habit stops most business email compromise.
Step 3: Run a Session People Remember
Keep it under 45 minutes:
10 minutes: how modern phishing actually looks. Not misspelled princes. Credential-harvesting pages that mirror your real login screen, invoice fraud that references a real project, and messages written fluently with AI, which is why "bad grammar" is no longer a reliable tell.
20 minutes: hands-on. Show real (anonymized) examples from your own baseline test and inbox. Demonstrate hovering over a link to reveal the real destination, how display names are spoofed, and what a lookalike domain looks like when you read it carefully.
10 minutes: Q&A, which is usually where the most valuable material comes out, because someone always says "I got one like that last week."
Cover the newer tactics too: QR codes in emails or attachments that lead to fake login pages, repeated MFA prompts designed to make you tap Approve out of frustration, requests to authorize a third-party app, and emails asking you to call a phone number where the real attack happens on the call.
Pro tip: Run it live, not as a recorded module. Questions are the point.
Step 4: Run Simulations That Are Fair and Realistic
Start easy, like a generic password reset, and increase difficulty as the team improves. Vary timing and content so people aren't just primed on the first Monday of every month.
Three rules keep simulations useful rather than corrosive:
Don't use cruel lures. Fake bonuses, fake layoffs, or fake payroll errors generate great click statistics and real resentment. Companies have made national news for this, and the damage to trust outlasts the lesson.
Debrief every time. Send a short note explaining what the test was, which clues gave it away, and the aggregate result.
Teach at the moment of the click. Anyone who clicks should land on a short page explaining the specific red flags they missed, not a generic error.
For people who click, a brief refresher is enough. Repeated clicks are a signal to check whether that person's role puts them under unusual pressure, not a disciplinary matter.
Step 5: Measure the Right Things
Track:
Click rate: the headline number, and the one everyone focuses on.
Reporting rate: arguably more important, because reports are what let you pull a real attack from everyone else's inbox.
Time to first report: your early-warning speed. Minutes, not hours, is the target.
Credential entry rate: the one that actually causes incidents.
A falling click rate with a flat reporting rate means people are getting cautious but staying quiet. Push on reporting.
Reinforce between sessions with a short "phish of the month" in team chat, quick refreshers after real incidents, and updates when tactics change. And review the whole program at least annually alongside your other security practices.
The Free Checklist: Phishing Red Flags
Copy this into a one-pager, or pin it in your team chat.
Check the sender
Does the actual address match the display name?
Is the domain subtly wrong (extra letter, hyphen, different ending)?
Is the reply-to address different from the sender?
Were you expecting to hear from this person at all?
Check the message
Is it creating urgency, secrecy, or fear?
Does it ask you to change payment details, buy gift cards, or send money?
Does it ask you to verify credentials or re-enter your password?
Does it come with an unexpected attachment, especially one asking you to enable content?
Check the links
Hover first: does the real destination match the text?
Is it a QR code sent by email? Treat it as an untrusted link.
Does the login page URL exactly match the service you expect?
Check the ask
Does this bypass a normal process?
Would this person normally ask this way?
Did an MFA prompt appear that you didn't trigger? Deny it and report it.
When in doubt
Don't click. Don't reply. Don't forward it to colleagues.
Verify by phone on a number you already have, never one in the email.
Report it, then delete it.
Choosing Tools
Under ~25 people: manual simulations with a free tool plus a live session work well. The constraint is your time, not your budget.
25–250 people: a dedicated simulation platform earns its cost by automating sending, tracking, and follow-up training.
Larger or regulated organizations: add compliance reporting, single sign-on, and role-specific content.
Whatever you use, favor realistic customization over volume of content. A simulation that mimics your actual vendors and workflows teaches more than fifty generic templates.
Common Mistakes
Making it annual. Tactics change; one session a year fades to nothing.
Shaming clickers. It suppresses reporting, which is the metric that protects you.
Using cruel lures. The outrage outlives the lesson.
Generic examples. Customize to your vendors, tools, and workflows.
Tracking only click rate. Reporting rate and time-to-report matter more.
Treating training as a substitute for controls. Train and enforce 2FA, authenticate your domain, and watch for suspicious account activity.
Leaving leadership out. Executives are the most impersonated people in your company and need the training most.
FAQ
How often should we run phishing training?
A full session once or twice a year, with short simulations and reinforcement monthly or quarterly in between, plus an immediate refresher after any real incident.
What's a good free tool for simulations?
GoPhish is the best-known open-source option, though it needs some technical setup. Smaller teams can also run a careful manual test from a separate domain.
Should we punish people who click?
No. Punishment reduces reporting, which is the behavior that actually protects you. Use short refreshers and positive reinforcement instead.
What click rate should we aim for?
Lower is better, but treat reporting rate as the primary measure of a healthy program. Plenty of teams with low click rates still have poor early warning.
Can training replace technical controls?
No. Training is the last layer. Domain authentication, 2FA with security keys for high-risk accounts, and monitoring for suspicious activity come first.
What are the newest tactics we should teach?
QR codes leading to fake login pages, AI-written lures with no grammatical tells, repeated MFA prompts, requests to authorize third-party apps, and emails that push you to phone a fraudulent number.
Do small teams need this?
Yes. Attacks are automated across thousands of small domains, and small teams often have one person who can move money.
How do we know it's working?
Compare your baseline to later results across all four metrics, and watch how quickly real phishing attempts get reported.
Build the Training on Secure Foundations
Awareness training works best on top of a platform that makes the right behavior easy. NevTan Mail gives you secure, ad-free email on your own domain, with aliases and groups so a reporting address like phishing@ takes seconds to set up, Admin and Super Admin roles, guided SPF/DKIM/DMARC setup to make spoofing your domain harder, two-factor authentication with security key support, Sentinel monitoring for suspicious account activity, and a calendar for scheduling your sessions. Up to 10 mailboxes are free forever.
Related reading: Two-factor authentication rollout guide · Protecting your company from business email compromise · All articles
