Most phishing simulation programs show a measurable drop in click rates within the first 90 days, with the steepest reduction in the first eight months — Cyber Aware's own benchmark for monthly-cadence programmes is an average 80% reduction in clicked links by month eight. The caveat is that the first month or two can look worse, not better: a first simulation often raises the click rate above your baseline because staff are seeing the exercise for the first time. Treat the 90-day mark as the first honest read, and month eight as the target state.
How long until phishing simulation training shows results?
The timeline, based on how monthly programmes typically run:
| Period | What you see | What it means |
|---|---|---|
| Month 1 | Click rate often at or above baseline | First exposure — staff have never been tested before |
| Months 2-3 | Click rate starts trending down as repeat simulations land | The programme is working; report the trend, not one number |
| Months 4-6 | Consistent cadence produces quarter-on-quarter drops | Risk reduction becomes visible in reporting |
| Months 8+ | Click rates stabilise at a much lower level | Cyber Aware's benchmark: ~80% average reduction in clicked links |
Why results vary between companies
- Cadence — monthly simulations outperform an annual test. A single annual campaign measures a moment, not a behaviour change.
- What happens after a click — programmes that auto-enrol clickers into a short remediation course convert mistakes into training immediately, which is what moves the next month's number.
- Template realism — generic templates teach people to spot bad grammar, not real attacks. Templates modelled on current scam patterns produce more honest (and more useful) click data.
- Template variety — repeating the same few emails teaches staff to recognise the template, not the tactic. Varied templates across difficulty levels keep the measurement honest.
- Reporting discipline — teams that track click and report rates per person per month can see change earlier than teams reading a single campaign total.
What to measure, month by month
- Click rate — the share of recipients who clicked a simulated link. This is the headline number and the one that should fall.
- Report rate — the share who reported the email. This should rise, often before the click rate falls; reporting is the behaviour you actually want.
- Repeat clickers — the small group who click repeatedly. A programme is working when this list shrinks month over month.
A platform like Cyber Aware reports all three after each campaign, so you can distinguish a real trend from one good or bad month.
What speeds results up
- Run monthly, not quarterly or annually.
- Auto-enrol anyone who clicks into a short training course the same week.
- Vary templates and difficulty instead of reusing a favourite.
- Celebrate reports, not just clean inboxes — reporting is the win.
FAQ
Why did our first phishing simulation get a high click rate? That is normal on a first-ever test. Staff are seeing the exercise for the first time, so treat month one as a baseline, not a verdict. The trend from month two onward is what matters.
How often should phishing simulations run to see results? Monthly. Cyber Aware's Auto Phish schedules a full year of varied campaigns from one setup, and the published benchmark — an average 80% reduction in clicked links — is measured on that monthly cadence within eight months.
Do click rates keep dropping forever? No. They stabilise at a low level once staff have seen a variety of real tactics. At that point report rate and repeat-clicker count become the more useful numbers to track.
Is one phishing campaign enough to change behaviour? No. A single campaign is a measurement, not a programme. Behaviour change comes from the combination of repeated simulations and immediate remediation training after each click.