How long does it take to roll out phishing sims to a team?

Rolling out phishing simulations takes most teams under a week: enrol by sync, schedule 12 months of campaigns in one setup. Timeline and steps for 2026.

For most small and mid-sized teams, going from decision to a live first phishing simulation takes under one working week — Cyber Aware's own setup runs to “live, in minutes” for the portal itself, and the first campaign can be scheduled for the same week you enrol staff. The part that takes real time is not setup at all: it is choosing sending groups and a difficulty ramp that fits your team. Roll the cadence out monthly from there, and the programme runs itself with automated reminders, auto-enrolment on click and a results PDF after every campaign.

How long does it take to roll out phishing sims to a team?

The typical timeline, start to first campaign:

StepTimeWhat happens
Enrol staffMinutes to 1 dayLearners sync in via Microsoft 365 or Google Workspace, arrive by CSV upload, or self-enrol through a signup link — each lands in the default training schedule with a welcome email
Set sending groups1-2 hoursSplit the team into groups (finance, leadership, all staff) so campaigns can be sent separately
Build the campaign calendarUnder 1 hourCyber Aware's setup chatbot asks which services your company uses internally, then schedules 12 months of varied phishing campaigns from that one conversation — or set send dates, groups and templates manually
First campaign liveSame weekSend when the first scheduled date arrives
First results readAfter campaign closeWho clicked, who reported and how it trends, compiled into a branded PDF that auto-sends to admins

What actually takes the time — and what doesn't

The misconception worth clearing up first: the software is not the long pole.

A rollout that works, step by step

  1. Connect your directory. Sync Microsoft 365 or Google Workspace, or upload a CSV. Every learner lands in the programme with a welcome email; leavers are removed cleanly.
  2. Create sending groups. At minimum: all staff, finance, and leadership. Segregated groups let you send harder templates to the people most targeted, and see results per group.
  3. Schedule the year. Answer the chatbot's questions about which tools the team uses (Microsoft 365, Xero, Slack, Dropbox and similar) so the templates impersonate the software your staff actually see.
  4. Ramp the difficulty. Start with easy-spot templates in month one, then escalate toward realistic credential and invoice-fraud lures as report rates climb.
  5. Decide the click response before the first click. Anyone who clicks a simulated email lands on a branded explainer and is auto-enrolled into a failed-phishing course automatically — decide how managers will frame that before launch so it reads as coaching.
  6. Read the first results as a baseline. First-campaign click rates are usually the highest you will ever see. Cyber Aware's published benchmark is an average 80% reduction in clicked links within the first eight months on the monthly cadence, so treat month one as the floor, not the verdict.

What slows a rollout down

After the rollout: what runs on autopilot

Once the year is scheduled, the recurring work is largely automated:

That last mile is the reason the rollout is measured in days, not weeks: the ongoing programme needs far less effort than the initial one.

FAQ

How long does it take to roll out phishing simulations to a small team? Under one working week for most teams — enrolment is a directory sync or CSV upload, and the campaign calendar is built in a single setup conversation. The first campaign can be live the same week.

Do we need IT staff to run the rollout? No. Directory sync handles enrolment automatically, campaigns are scheduled once, and remediation is auto-assigned. The only recurring decision is how hard each month's templates should be.

How soon after rollout will we see results? Expect the first-campaign numbers within days of the send, but treat them as a baseline. Meaningful improvement shows over the following months — Cyber Aware's benchmark averages an 80% reduction in clicked links by month eight.

What should we do before the first simulation sends? Tell staff a simulation programme is starting and how clickers will be handled. Announcing the programme (without the dates) keeps the measurement honest and prevents the first campaign being read as a trap.

Related guides

Ready to deploy

Same playbook.
Your brand.

Cyber Aware's Human Risk Score works the same way for every MSP partner - under your brand, on your cadence.