Use case

Running your first phishing test

The first simulation sets the tone for the whole program. Here's how to run it safely, what to measure, and what to avoid.

Overview

The first phishing simulation an organization runs matters more than most of the ones that follow, because it sets expectations for the entire program. Too aggressive a template, no internal communication about the program's existence, or a scoring approach that feels punitive can undermine trust before the program has a chance to prove its value. Too easy a test, on the other hand, produces a flattering result that tells the security team nothing useful about actual exposure.

A good first test is calibrated to establish a baseline, not to catch as many people as possible. It should use a moderate-difficulty template relevant to your industry, cover a reasonable cross-section of the organization, and be paired with a clear internal message about why the program exists, so employees understand it as training rather than a trap. What gets measured in that first campaign, click rate, report rate, and time to report, becomes the baseline every future campaign is compared against.

Preparation is where most first tests are won or lost. Preflight checks validate the template, landing page, sending domain, recipient list, and schedule before anything goes out, so the failures that embarrass a new program, a broken link, an unverified domain, an empty recipient group, are caught before an employee ever receives a message. Starting from a calibrated global template rather than a lure built from scratch keeps the difficulty in a sensible range for a baseline instead of accidentally producing a test that almost nobody could pass.

Once the campaign is live, a real-time monitor shows sends, opens, clicks, submissions, and reports as they happen, so you are not waiting until it closes to understand how it went. Afterward, a generated report summarizes click rate, report rate, and department breakdown in a format you can share with leadership, and that first set of numbers becomes the baseline every future campaign is measured against. Crucially, including a reporting path from the start means you learn not only who clicked but who did the right thing.

How Claro helps

  • Preflight checks before launch

    Claro validates the template, landing page, sending domain, recipient list, and schedule before a campaign can go live, catching common setup mistakes before employees receive anything.

  • A library of calibrated templates

    Global templates spanning IT, HR, finance, and delivery scenarios let you choose a moderate-difficulty starting point instead of building a convincing lure from scratch.

  • A live monitor during the campaign

    The campaign monitor shows sends, opens, clicks, submissions, and reports as they happen, so you are not waiting until the campaign closes to see how it is going.

  • A first-campaign report you can share internally

    A generated report summarizes click rate, report rate, and department breakdown in a format suited for sharing with leadership after the first test, establishing the baseline for future comparisons.

  • A reporting path from day one

    Adding a report button through the Outlook add-in or Gmail extension means the first test measures reporting, not just clicking, so your baseline captures the behavior you actually want to grow.

  • A safe baseline you can build on

    Because the first campaign's numbers are stored as your reference point, later campaigns, training, and risk scores all measure movement against a real starting line rather than a guess.

Frequently asked questions

  • There is no universal target, since it depends on your industry, template difficulty, and whether employees have had prior awareness training. What matters more than the absolute number is that you have a documented baseline to compare future campaigns against.

See Claro in action

Book a walkthrough tailored to your program and your regulatory context.

Request a demo