How to keep phishing simulations current with new scam tactics

Keep phishing simulations current in 2026: a monthly threat scan, template refresh queue, and six-step cadence that tracks live scam tactics.

Stale templates train staff to spot last year’s scams. Keeping phishing simulations current with new scam tactics is how you stop the programme becoming a ritual nobody fears — and nobody learns from — in 2026.

Key takeaways

Why this matters

Attackers refresh pretexts weekly. Deepfake CEOs, QR-code parking fines, and vendor portal quarks do not wait for your annual content update. A library frozen in 2024 teaches pattern recognition for threats staff no longer receive.

In 2026, programmes that treat the template list as a living queue outperform programmes that treat it as a content pack. Pair phishing simulations with a fixed refresh cadence and cyberaware.com-style short lessons so every new lure has a matching micro-module waiting.

What you will need

The steps

1. Inventory every live template and tag its age

Export the current library. Columns: name, lure type (invoice, IT reset, HR, vendor, payroll), created date, last send, last click rate, last report rate, owner. Flag anything not sent in 90 days or never customised past the vendor default.

Expected outcome: one sheet ranking templates by age and performance before you write anything new.

Common mistake: adding new templates on top of a bloated library nobody has retired.

2. Run a 60-minute monthly threat scan on a fixed date

First Tuesday of each month in 2026, collect:

  1. Top five real phishing subjects from your help desk or SOC that week
  2. Two external alerts relevant to your sector or region
  3. One tactic shift (QR, smishing, callback, deepfake voice) you have not simulated in 90 days

Capture each as a one-line brief: who it targets, what it asks for, which internal brand it spoofs.

Expected outcome: three candidate lures written as briefs, not full emails yet.

Common mistake: scrolling social media for inspiration instead of your own ticket queue.

3. Promote one brief into a full template within seven days

Write the chosen lure using only public or synthetic detail — never a real customer name or live invoice. Match tone to the legit channel (finance verbs for AP, IT verbs for help desk). Peer-review with one non-security person for obviousness. Stage it in the platform the same week.

Expected outcome: one new or heavily rewritten template live before day 10 of the month.

Common mistake: waiting for perfect design assets and slipping a full month.

4. Send on a standing cadence, not a big-bang day

Keep your regular simulation rhythm (monthly or bi-weekly). Insert the new template into the next scheduled slot for a risk-appropriate cohort — finance gets bank-change first, all-staff gets the softer variant two weeks later. Auto-enrol clickers into a matching short lesson.

Expected outcome: new tactic reaches learners inside 14 days of the threat scan.

Common mistake: parking new templates in “draft” for a quarterly mega-campaign.

5. Score freshness and behaviour in one view

Each month record: share of sends using templates under 60 days old, click rate trend, report rate trend. Fold overdue training and phishing fails into human risk reporting so leadership sees whether fresher lures moved behaviour, not only whether you shipped content.

Expected outcome: a one-page freshness score next to click/report numbers at every QBR.

Common mistake: celebrating a new template count while report rate never leaves single digits.

6. Retire or rewrite losers on a 90-day rule

Any template older than 90 days with click rate under 3% and report rate under 5% is either too obvious or invisible (often filtered). Rewrite or archive it. Do not keep trophy templates that no longer teach.

Expected outcome: library stays under a fixed cap (for example 40 active) with a visible rewrite queue.

Common mistake: infinite library growth that makes “current” impossible to define.

Troubleshooting

Legal blocks every custom template. Pre-approve three lure categories (IT, vendor, HR) once per year so monthly swaps stay inside the envelope.

Help desk drowns in false incident tickets after a fresh hard lure. Brief managers 48 hours ahead and put the report button path in the post-click coach screen.

You have no abuse tickets to mine. Start with three public patterns from IC3 and ACSC advisories, then add internal tickets as they appear in 2026.

Click rates crash to zero on new sends. Check filtering before declaring victory — whitelist simulation infrastructure first.

MSPs juggling many clients cannot scan monthly per tenant. Run one shared monthly scan, then localise display names and logos per client in under an hour each.

Staff say simulations are unfair. Publish the refresh rule: we simulate what hit peers this month. Fairness is relevance, not softness.

Tools and resources

What to do next

Lock the first-Tuesday scan on the team calendar for the rest of 2026, promote one July or August lure this week, and attach freshness % to your next leadership pack. Currency is a calendar habit, not a project.

FAQ

How do you keep phishing simulations current with new scam tactics in 2026? Run a monthly 60-minute threat scan, ship one new or rewritten template within seven days, insert it into the standing cadence, and retire flat templates after 90 days.

How often should templates be refreshed? At least one substantive refresh every 30 days, with a hard review of anything unused or underperforming at 90 days.

Where should new lure ideas come from? Your own help desk and SOC tickets first, then sector alerts and trusted vendor research — not random social feeds.

Do we need deepfake video simulations immediately? Start with callback and invoice pretexts most teams already face. Add deepfake-themed email or meeting lures once the monthly machine works.

What report rate should we target? Push above 20% reporting on current templates while click rate trends down across a quarter.

Can small teams run this without a threat intel function? Yes. One owner, three source tabs, and a one-page brief format is enough.

Should every client or business unit get unique templates? Localise names and logos; keep the core pretext shared so the monthly scan scales.

How does training stay aligned when lures change? Assign a matching micro-lesson the same week as the send so the coach moment explains the new tactic, not a generic 2024 slide.

One last thing

The quiet failure mode is a beautiful library dashboard and a send history full of three favourite templates from last spring. If more than half your 2026 sends are older than 60 days, you are running nostalgia, not defence. Put template age next to click rate on the scorecard — that single column keeps the programme honest.

Related guides

Ready to deploy

Same playbook.
Your brand.

Cyber Aware's Human Risk Score works the same way for every MSP partner - under your brand, on your cadence.