Running your first phishing test
The first simulation sets the tone for the whole program. Here's how to run it safely, what to measure, and what to avoid.
Overview
The first phishing simulation an organization runs matters more than most of the ones that follow, because it sets expectations for the entire program. Too aggressive a template, no internal communication about the program's existence, or a scoring approach that feels punitive can undermine trust before the program has a chance to prove its value. Too easy a test, on the other hand, produces a flattering result that tells the security team nothing useful about actual exposure.
A good first test is calibrated to establish a baseline, not to catch as many people as possible. It should use a moderate-difficulty template relevant to your industry, cover a reasonable cross-section of the organization, and be paired with a clear internal message about why the program exists, so employees understand it as training rather than a trap. What gets measured in that first campaign, click rate, report rate, and time to report, becomes the baseline every future campaign is compared against.
Preparation is where most first tests are won or lost. Preflight checks validate the template, landing page, sending domain, recipient list, and schedule before anything goes out, so the failures that embarrass a new program, a broken link, an unverified domain, an empty recipient group, are caught before an employee ever receives a message. Starting from a calibrated global template rather than a lure built from scratch keeps the difficulty in a sensible range for a baseline instead of accidentally producing a test that almost nobody could pass.
Once the campaign is live, a real-time monitor shows sends, opens, clicks, submissions, and reports as they happen, so you are not waiting until it closes to understand how it went. Afterward, a generated report summarizes click rate, report rate, and department breakdown in a format you can share with leadership, and that first set of numbers becomes the baseline every future campaign is measured against. Crucially, including a reporting path from the start means you learn not only who clicked but who did the right thing.
How Claro helps
Preflight checks before launch
Claro validates the template, landing page, sending domain, recipient list, and schedule before a campaign can go live, catching common setup mistakes before employees receive anything.
A library of calibrated templates
Global templates spanning IT, HR, finance, and delivery scenarios let you choose a moderate-difficulty starting point instead of building a convincing lure from scratch.
A live monitor during the campaign
The campaign monitor shows sends, opens, clicks, submissions, and reports as they happen, so you are not waiting until the campaign closes to see how it is going.
A first-campaign report you can share internally
A generated report summarizes click rate, report rate, and department breakdown in a format suited for sharing with leadership after the first test, establishing the baseline for future comparisons.
A reporting path from day one
Adding a report button through the Outlook add-in or Gmail extension means the first test measures reporting, not just clicking, so your baseline captures the behavior you actually want to grow.
A safe baseline you can build on
Because the first campaign's numbers are stored as your reference point, later campaigns, training, and risk scores all measure movement against a real starting line rather than a guess.
Frequently asked questions
There is no universal target, since it depends on your industry, template difficulty, and whether employees have had prior awareness training. What matters more than the absolute number is that you have a documented baseline to compare future campaigns against.
Related pages
Onboarding Security Awareness
Auto-enroll new hires in baseline training and their first simulation from day one.
Learn moreBoard & Regulator Reporting
Turn simulation, training, and risk data into board-ready and audit-ready evidence for OJK, BSSN, UU PDP, and ISO 27001.
Learn moreProtecting Remote & Hybrid Teams
Reach distributed staff with consistent phishing simulation and awareness across email, WhatsApp, and phone.
Learn moreSee Claro in action
Book a walkthrough tailored to your program and your regulatory context.
Request a demo