How to run phishing simulations during a company merger

Run phishing simulations during a company merger in 2026 without wrecking trust: timeline, dual-brand rules, and a 45-day integration plan.

Mergers multiply inboxes, brands, and attackers who spoof “integration updates.” Running phishing simulations during a company merger without burning goodwill takes a narrower scope, clearer sponsors, and quieter metrics than a normal year.

Key takeaways

Why this matters

Attackers read the same press releases you do. “Action required: new SSO” and “payroll entity change” emails spike around announced deals. If your phishing simulations go dark for six months, you train staff to ignore the exact lures criminals are sending. If you go loud without a plan, you create HR incidents on top of integration stress.

In 2026, the teams that keep a thin, well-briefed simulation line through the merger protect both brands and both workforces.

What you will need

The steps

1. Put the freeze and resume dates in the integration calendar

Add simulation freeze and first joint pilot dates next to SSO cutover and payroll cutover. Security quiet periods that only live in a side spreadsheet get overridden by someone else’s “urgent awareness blast.”

Expected outcome: freeze and resume visible on the master integration plan for 2026.

Common mistake: an indefinite pause “until things settle” that quietly becomes two quarters.

2. Agree one joint metric and two veto rules

Before any post-close send, write: target report rate, maximum acceptable help-desk ticket spike, and who can halt a campaign. Both legacy leads sign. No metric means every result becomes a political argument.

Expected outcome: a half-page charter both sponsors can forward.

Common mistake: each side keeping separate scorecards that cannot be compared.

3. Build dual cohorts from real mail routing, not org charts

Until domains merge, segment by actual mailbox system. People mid-migration may sit in both — put them in one cohort only to avoid double hits. Exclude deal teams handling price-sensitive work if counsel requires it, and document the exclusion list.

Expected outcome: two clean lists with owners and a dated exclusion file.

Common mistake: uploading a week-old HR dump that still includes exited staff.

4. Brief managers in both cultures 5 business days ahead

Share the purpose (skill practice during a high-pretext period), the report path, and the freeze window. Ask managers to stop local forward-to-all “tests.” Unbriefed middle managers manufacture rumours faster than any template.

Expected outcome: manager note sent from both sponsor addresses.

Common mistake: only briefing the acquiring company’s managers.

5. Launch a soft joint pilot within 14 days after freeze ends

Use a medium-easy integration-themed lure (fake benefits portal or shared-drive access) on 10–15% of combined headcount split across both legacies. Track click, report, and remediation completion separately per legacy cohort so you can see culture gaps without public shaming.

Expected outcome: pilot data within three weeks of Day-1, not a six-month blank.

Common mistake: opening with a hard spear-phish referencing the real deal nickname.

6. Remediate privately; report jointly

Auto-assign short lessons to clickers. Publish only aggregate rates to leadership. Individual fail lists stay with direct managers and security — never in a combined Slack channel.

Use human risk reporting style rollups so the integration steering group sees one page, not two vendor PDFs.

Expected outcome: one joint slide at the next steering meeting.

Common mistake: leaderboard-style shame that poisons the “one company” message.

7. Step up cadence only after mail identity is stable

When the majority of staff share one primary domain and the help desk no longer swims in access tickets, move from pilot to monthly cadence with slowly harder templates. Keep one integration-themed lure in rotation for 90 days post-close — attackers will.

Expected outcome: standing monthly programme by day 45–60 when cutoverscooperate.

Common mistake: full hard-mode catalogue on day 10 while passwords still reset daily.

Troubleshooting

One legacy company refuses simulations. Offer a 30-day pilot with the softest template and the joint metric charter. Absolute refusal becomes a documented residual risk for the board.

Tickets explode after send one. Check whether the lure collided with a real IT email the same morning. Reschedule; do not defend a bad theatrics window.

Works councils or unions object. Involve them in the charter step. Frame as safety training during known fraud spikes, with no individual public scoring.

Domains still split at day 60. Stay on dual cohorts. Do not force a single campaign through a broken identity graph.

Attackers land a real BEC mid-programme. Pause sims 72 hours, push a factual all-staff note, then resume with a related soft template after the incident note.

Executives want to exempt themselves. Keep them in. Merger prestexts name executives on purpose.

Tools and resources

What to do next

If Day-1 is inside 30 days, write the freeze window and joint metric today. If you are already post-close with no simulations, run the soft joint pilot within two weeks — not after “the dust settles,” which is when attackers are most active.

FAQ

How do you run phishing simulations during a company merger in 2026? Freeze around Day-1, agree one joint metric, segment by real mail directories, brief both manager groups, and restart with a soft joint pilot within 14 days after freeze.

Should simulations stop entirely during a merger? Stop for a short defined freeze, not for the whole integration. Long blackouts leave staff exposed to real integration-themed fraud.

When is the first safe send after close? Typically within 14 days after a 5–7 day freeze, once help-desk severity for access issues is trending down.

Do we use one brand or two in the templates? Match the mailbox the person actually uses that week. Wrong-brand lures create confusion, not learning.

What if cultures treat “failing” differently? Ban public individual rankings. Report aggregates only and keep remediation private.

How hard should the first joint template be? Soft to medium. You are testing programme plumbing and psychological safety, not catching people at their worst week.

Who owns the programme after legal day-one? Name one accountable owner even if execution stays dual-tenant for a while. Dual ownership without a tie-break stalls every send.

Can MSPs run this for two client tenants that are merging? Yes — treat each tenant as a cohort, share the charter, and present one combined steering slide.

One last thing

The merger simulation failure that stings longest is not a high click rate. It is a surprise hard send landing the same morning as a real domain cutover email, which teaches everyone that security theatre competes with their job. Put the freeze on the master calendar, keep the first lure boring, and earn the right to go harder after identity stabilises in 2026.

Related guides

Ready to deploy

Same playbook.
Your brand.

Cyber Aware's Human Risk Score works the same way for every MSP partner - under your brand, on your cadence.