Run phishing simulations monthly. That is the short answer, and it is not a productivity ritual — it is the cadence behind the strongest result in the industry: Cyber Aware's benchmark of an average 80% reduction in clicked links by month eight, measured on monthly programmes. Quarterly simulations produce a snapshot; monthly ones produce a habit. This guide explains why frequency beats intensity, what the data shows at each cadence, and how to run a monthly programme without fatiguing your staff.
Why frequency beats intensity
Recognition of a phishing email is a reflex, not a fact someone memorises. Reflexes are built by short, frequent exposure — the same way a musician keeps technique with daily practice, not one long lesson a year. Someone who completes a 30-minute annual course forgets most of it within weeks, because the knowledge is never rehearsed at the moment it matters: when a suspicious email lands.
Four simulations a year teach your team to spot four specific emails. Twelve slightly different scenarios teach them to spot the tactics behind hundreds of variants, because each campaign refreshes the pattern while the previous one is still fresh. And each campaign doubles as a measurement: without a monthly read on click rate, report rate and repeat clickers, you cannot tell whether your training is working or quietly eroding.
What the cadence data shows
| Cadence | What typically happens | Why it happens |
|---|---|---|
| Annual | Click rates stay high year after year; staff forget the exercise between rounds | Knowledge decays in weeks; the course is a one-off event, not a habit |
| Quarterly | Click rate improves between the first and second campaign, then plateaus | Improvement is real but the gap between exposures lets behaviour drift back |
| Monthly | Cyber Aware benchmark: an average 80% reduction in clicked links by month eight, with report rates climbing past 50% | Every month rehearses recognition, refreshes tactics and measures the trend |
| Weekly | Not recommended for most teams | Fatigue sets in; reporting quality drops and staff start tuning the exercise out |
Read the annual row carefully, because it is the most common default. A once-a-year exercise measures a moment, and the eleven months in between are unmeasured and untrained.
Monthly without fatigue: six rules
The objection to monthly simulations is almost always the same: will our staff get tired of it? Handled well, they do not — fatigue comes from repetition of the same trick, not from frequency itself.
- Vary the templates every month. Rotate through the scams actually circulating — invoice fraud, MFA prompts, courier notifications, shared-document requests. Difficulty should escalate as report rate climbs; never rerun last year's email.
- Keep the training that follows short. When someone clicks, enrol them in a five-to-ten minute course on exactly that tactic, the same week — not a 45-minute annual module. Cyber Aware's phishing simulations do this enrolment automatically.
- Celebrate reporters by name. A short shout-out after each campaign builds the reporting habit that matters more than the click number.
- Never punish a click. The moment a simulation feels like a trap with consequences, reporting dries up — and the next real attack goes unreported.
- Read the trend, not the single result. One hard campaign dips the numbers; the six-month line is the verdict. Human risk reporting shows click rate, report rate and repeat clickers per person per month.
- Run leadership through the same programme. When the managing director appears in the same chart, the exercise stops being an IT chore.
What to do between campaigns
Monthly simulation does not mean monthly-only attention. Three lightweight habits keep momentum between sends:
- Review last month's numbers before building this month's campaign. If repeat clickers concentrate in one department, the next template should target that department's actual scam exposure.
- Broadcast real phishing reports internally. When an employee reports a real suspicious email, tell the company. Nothing teaches faster than a live example that just hit their own inbox.
- Keep new starters on a fast track. Anyone hired since the last campaign should get an introductory simulation within their first month rather than waiting for the next company-wide send.
How this pairs with training cadence
Simulations and training work as one loop: the simulation measures the reflex, the training repairs it. The matching guidance on training is the same cadence — monthly micro-training plus monthly simulations is the 2026 default, and completion matters more than content length. Cyber Aware's security awareness training pairs short courses with the simulation schedule so the two reinforce each other rather than compete for attention. If you are comparing platforms before committing to a cadence, the comparison page breaks down how Cyber Aware stacks up on simulation frequency, auto-enrolment and reporting.
FAQ
Is monthly too often for a small team? No — a monthly campaign takes each person under a minute unless they click, and small teams usually see the fastest improvement because results are visible to everyone. Start with easy templates in month one and escalate.
What about quarterly, which most vendors offer by default? Quarterly is better than annual, but the plateau is real: click rates typically stop improving after the second or third round. If quarterly is where you must start, treat it as a stepping stone to monthly rather than a destination.
Do staff need to know simulations are coming? They should know the programme exists and that simulations run regularly — but not when. Surprise is what makes the rehearsal realistic; transparency about the programme is what keeps it fair.
How long until we see results? Click rates usually fall noticeably within the first two to three monthly campaigns; the 80% reduction benchmark is measured at month eight. The report rate rising is the earliest signal the culture is working — often visible from month two.
What if someone fails every month? Treat it as a coaching signal, not a disciplinary one. Escalating, targeted training on the tactics that catch them — plus a conversation about their actual inbox risks — resolves the majority of repeat clickers within a quarter.