Stale templates train staff to spot last year’s scams. Keeping phishing simulations current with new scam tactics is how you stop the programme becoming a ritual nobody fears — and nobody learns from — in 2026.
Key takeaways
- Refresh at least one template every 30 days from live lures your industry is seeing now.
- Verizon’s 2026 DBIR put the human element in 62% of breaches — simulations that lag live tactics miss that risk.
- Run a 60-minute monthly threat review, not an annual library dump.
- Score template age, click rate, and report rate together; retire anything older than 90 days with flat metrics.
- Map new lures to short remediation lessons the same week you send them.
Why this matters
Attackers refresh pretexts weekly. Deepfake CEOs, QR-code parking fines, and vendor portal quarks do not wait for your annual content update. A library frozen in 2024 teaches pattern recognition for threats staff no longer receive.
In 2026, programmes that treat the template list as a living queue outperform programmes that treat it as a content pack. Pair phishing simulations with a fixed refresh cadence and cyberaware.com-style short lessons so every new lure has a matching micro-module waiting.
What you will need
- A named owner for the monthly threat scan (security or MSP ops, not “whoever has time”)
- Access to three free feed sources: your own abuse desk tickets, industry ISAC or ACSC alerts, and one vendor threat blog you already trust
- A template inventory sheet with created date, last used date, click rate, report rate
- A simulation platform that can stage new sends inside seven days of writing
- Security awareness training modules short enough to pair with a fresh lure the same week
- Thirty minutes on a recurring calendar with one executive sponsor who will unstick legal delays
The steps
1. Inventory every live template and tag its age
Export the current library. Columns: name, lure type (invoice, IT reset, HR, vendor, payroll), created date, last send, last click rate, last report rate, owner. Flag anything not sent in 90 days or never customised past the vendor default.
Expected outcome: one sheet ranking templates by age and performance before you write anything new.
Common mistake: adding new templates on top of a bloated library nobody has retired.
2. Run a 60-minute monthly threat scan on a fixed date
First Tuesday of each month in 2026, collect:
- Top five real phishing subjects from your help desk or SOC that week
- Two external alerts relevant to your sector or region
- One tactic shift (QR, smishing, callback, deepfake voice) you have not simulated in 90 days
Capture each as a one-line brief: who it targets, what it asks for, which internal brand it spoofs.
Expected outcome: three candidate lures written as briefs, not full emails yet.
Common mistake: scrolling social media for inspiration instead of your own ticket queue.
3. Promote one brief into a full template within seven days
Write the chosen lure using only public or synthetic detail — never a real customer name or live invoice. Match tone to the legit channel (finance verbs for AP, IT verbs for help desk). Peer-review with one non-security person for obviousness. Stage it in the platform the same week.
Expected outcome: one new or heavily rewritten template live before day 10 of the month.
Common mistake: waiting for perfect design assets and slipping a full month.
4. Send on a standing cadence, not a big-bang day
Keep your regular simulation rhythm (monthly or bi-weekly). Insert the new template into the next scheduled slot for a risk-appropriate cohort — finance gets bank-change first, all-staff gets the softer variant two weeks later. Auto-enrol clickers into a matching short lesson.
Expected outcome: new tactic reaches learners inside 14 days of the threat scan.
Common mistake: parking new templates in “draft” for a quarterly mega-campaign.
5. Score freshness and behaviour in one view
Each month record: share of sends using templates under 60 days old, click rate trend, report rate trend. Fold overdue training and phishing fails into human risk reporting so leadership sees whether fresher lures moved behaviour, not only whether you shipped content.
Expected outcome: a one-page freshness score next to click/report numbers at every QBR.
Common mistake: celebrating a new template count while report rate never leaves single digits.
6. Retire or rewrite losers on a 90-day rule
Any template older than 90 days with click rate under 3% and report rate under 5% is either too obvious or invisible (often filtered). Rewrite or archive it. Do not keep trophy templates that no longer teach.
Expected outcome: library stays under a fixed cap (for example 40 active) with a visible rewrite queue.
Common mistake: infinite library growth that makes “current” impossible to define.
Troubleshooting
Legal blocks every custom template. Pre-approve three lure categories (IT, vendor, HR) once per year so monthly swaps stay inside the envelope.
Help desk drowns in false incident tickets after a fresh hard lure. Brief managers 48 hours ahead and put the report button path in the post-click coach screen.
You have no abuse tickets to mine. Start with three public patterns from IC3 and ACSC advisories, then add internal tickets as they appear in 2026.
Click rates crash to zero on new sends. Check filtering before declaring victory — whitelist simulation infrastructure first.
MSPs juggling many clients cannot scan monthly per tenant. Run one shared monthly scan, then localise display names and logos per client in under an hour each.
Staff say simulations are unfair. Publish the refresh rule: we simulate what hit peers this month. Fairness is relevance, not softness.
Tools and resources
- Phishing simulation platform with fast template staging and auto-remediation
- Short story-led training modules tied to each lure type
- Human risk scores combining training and phishing fails
- Monthly threat-scan agenda and template inventory sheet
- FBI IC3 and ACSC public advisories for regional tactics
- Compare notes on platform automation before you renew tooling
What to do next
Lock the first-Tuesday scan on the team calendar for the rest of 2026, promote one July or August lure this week, and attach freshness % to your next leadership pack. Currency is a calendar habit, not a project.
FAQ
How do you keep phishing simulations current with new scam tactics in 2026? Run a monthly 60-minute threat scan, ship one new or rewritten template within seven days, insert it into the standing cadence, and retire flat templates after 90 days.
How often should templates be refreshed? At least one substantive refresh every 30 days, with a hard review of anything unused or underperforming at 90 days.
Where should new lure ideas come from? Your own help desk and SOC tickets first, then sector alerts and trusted vendor research — not random social feeds.
Do we need deepfake video simulations immediately? Start with callback and invoice pretexts most teams already face. Add deepfake-themed email or meeting lures once the monthly machine works.
What report rate should we target? Push above 20% reporting on current templates while click rate trends down across a quarter.
Can small teams run this without a threat intel function? Yes. One owner, three source tabs, and a one-page brief format is enough.
Should every client or business unit get unique templates? Localise names and logos; keep the core pretext shared so the monthly scan scales.
How does training stay aligned when lures change? Assign a matching micro-lesson the same week as the send so the coach moment explains the new tactic, not a generic 2024 slide.
One last thing
The quiet failure mode is a beautiful library dashboard and a send history full of three favourite templates from last spring. If more than half your 2026 sends are older than 60 days, you are running nostalgia, not defence. Put template age next to click rate on the scorecard — that single column keeps the programme honest.