Skip to main content

What moves the effort of a phishing simulation programme

Very little of the effort in a phishing simulation scales with headcount. The six drivers that actually move it, and how to place a programme in a small, medium or large band before asking for a proposal.

By Parnika Kelkar
August 31, 20267 min read

The first question about a phishing simulation programme is how large it will be, and the number reached for is a headcount. It is the wrong number: very little of the work scales with how many people receive the message. It scales with how much of the campaign is built for this organisation specifically, how many channels are in scope, how often the round repeats, and how far the reporting goes past a single figure.

Every round has a heavy block and a light one. The heavy block is done once — the authorisation, the cohort scheme, the pretext, the sending infrastructure, the reporting format and the analysis. The light block is the send. Almost every decision that moves a programme's size moves the heavy block, which starts before any message exists.

Specific written permissions must be obtained from the auditee organization before conducting tests that involve survivability failures, denial-of-service (DoS), process testing, or social engineering.

That is CISG-2025-02, Version 1.0, 25 July 2025, §13.2.7(ii), p. 50. Reaching that signature means agreeing the population, the exclusions, the channels and the pretext boundaries — effort a larger population does not increase.

Population size counts for less than population complexity

Two thousand recipients and ten thousand recipients — one organisation, one language, one mail environment — are close to the same amount of work. The pretext is written once. The infrastructure is stood up once. The marginal recipient is nearly free; the first one carries everything.

What does grow with headcount is the operational tail: reported messages at the service desk, calls to the security contact, escalation traffic inside the window. Most of it lands on the organisation being tested, so plan for it.

Complexity is different: it multiplies the heavy block. Each of these turns one campaign into several.

  • Languages. A second language is a second pretext, a second landing page and a review by a native speaker. A translated message is a different test, not the same one rendered again.
  • Legal entities. Each has its own signatory for the §13.2.7(ii) permission, its own exclusions, and its own position on what may be imitated.
  • Countries and mail environments. Separate windows and holidays, results that may not pool into one figure; two tenants means two sets of delivery preparation and telemetry.
  • Contractor and outsourced populations. §15.2.2(iii), pp. 55–56, confines the test to employee groups explicitly included within the agreed audit scope, and excludes customers, business partners, vendors and other third parties unless specific written consent is obtained from the target organisation. That is settled group by group before an outsourced desk can be included.

An eight-hundred-person programme across five entities, four languages and three mail environments is more work than a ten-thousand-person programme in one company that speaks one language.

Pretext bespoke-ness, where the effort really goes

The dominant driver, and the one buyers most often leave unspecified. Three levels, far apart.

LevelWhat is builtWhat it takes
Generic lureA pretext that could go to any organisation — a delivery notice, a password expiry, a shared documentLeast. No discovery, no internal review, one build for the whole population
Organisation-specificA pretext drawn from the organisation's own systems, vendors and calendar: the tool people use, a supplier they deal with, a month in which it would plausibly arriveA discovery pass, a decision on which brands may be imitated, and a review by whoever fields the reaction
Per-target reconnaissanceA pretext per target or small group, built from what is discoverable about an individual's role and current workMost — the only level whose effort scales with target count, because research and pretext are per person

Most regulated programmes settle on the middle level. A generic lure measures whether people click on obviously external messages; a pretext built from the organisation's own furniture measures whether they can tell an internal-looking message from an internal one, which is what a real campaign tests. Getting there means learning the environment well enough to write it, then ruling themes out — pay, medical, redundancy, bereavement and impersonation of named individuals generate the complaints, and that is HR's call.

The third level is a different shape rather than a bigger one, and the one place population size and effort couple — which is why a spear phishing round is scoped over a small, chosen cohort. Difficulty band is part of the design too: holding it steady is what makes two quarters comparable.

Channel mix

Email is the baseline and, for most programmes, the whole of round one. SEBI's PR.AT Guidelines, pp. 103–104, describe awareness campaigns that "stress the avoidance of clicking on links and attachments in email". Every channel added past it brings three things of its own.

  • Its own authorisation. §13.2.7(ii) attaches to the test actually run, so a channel has to be named in the permission before it can be exercised.
  • Its own preparation. Vishing needs call scripts, a named procedure and version under test, and a decision on what the caller may claim. Physical pretexting needs site-level authorisation, a named site contact and a carry letter.
  • Its own execution window. An email round can go out in an afternoon. Calls happen one at a time, in working hours; a site visit needs someone present. Elapsed time does not compress.

Vishing is best scoped as a test of a process rather than a person — whether the service desk's verification procedure holds under pressure. That is the framing CERT-In's engagement types support at §6, pp. 14–17, items (x) Process Security Testing and (xvi) Red Team Assessment, a list given as "including, but not limited to".

Cadence, and the part that runs the other way

Cadence is read off the instrument that binds the entity. The RBI Directions, 2026, issued 31 July 2026, require a commercial bank to "evaluate the awareness level of employees periodically" at ¶202 — the same sentence at ¶201 for payments banks and small finance banks, and ¶197 for credit information companies. NBFCs carry ¶36, p. 19: a "formal mechanism to measure and track the effectiveness of such training through periodic assessments or testing", plus an "up-to-date repository of the training and awareness status of all users". SEBI's CSCRF, v1.0, 20 August 2024, says at §3.2 PR.AT, p. 63, that such programmes "shall be conducted on a periodic basis", while row 9 of its periodic-compliance table reads "Cybersecurity training program (PR.AT.S1) — All REs — Annually".

What repetition does to effort runs against expectation. Round one carries the whole heavy block. Later rounds inherit the authorisation, the cohort scheme, the infrastructure and the report format, leaving a new pretext, the send, the analysis and a trend line. Per-round effort falls after the first round; total effort rises with the number of rounds. A quarterly programme is not four one-offs: it is one first round, three lighter ones, and the standing work of keeping the ¶36 repository current.

Reporting depth

Reporting changes what a round is worth more than anything else in it. Three depths.

  • Population summary. The figures for the population as a whole. §15.2.2(iii) requires that testing aimed at general staff "must utilize anonymized or statistical techniques—ensuring no individual is personally identified or penalized", so this is the floor everything else is built on.
  • Cohort breakdown. Effort tracks the number of cohorts rather than the headcount, and the cohorts worth drawing are the ones the clause is written about: for a commercial bank, ¶203's new recruits and lower and middle management, and ¶204's Board members and Senior Management; for a Level III or Level IV urban co-operative bank, the upper management named at ¶156. Drawn on those lines the result is evidence against a paragraph rather than a report somebody must translate.
  • Purple-team detection walkthrough. A working session with the organisation's own security and mail teams over what the gateway did, what was quarantined, what alerted, and what happened to the messages people reported. The most effort-heavy option by a distance, and usually where the value is once the click figure is known.

Packaging the result as an audit artefact — population, dates, the authorisation reference, the retention position over identified data — costs little at the start and a great deal a year later.

So: small, medium or large

Read down the column that matches most of your answers.

DriverSmallMediumLarge
PopulationOne entity, one language, one mail environmentOne or two entities, up to two languagesSeveral entities, languages or countries; contractors needing a consent position
PretextGeneric lure, one difficulty bandBuilt from the organisation's own systems, vendors and calendarOrganisation-specific, plus per-target reconnaissance for a chosen cohort
ChannelsEmailEmail, plus vishing against one named procedureEmail, vishing and physical pretexting, each separately authorised
CadenceA single round, or a baselineHalf-yearly or quarterly, with a maintained repositoryQuarterly across entities, on a compliance calendar
ReportingPopulation summaryCohort breakdown mapped to the clause, with an evidence packCohort breakdown plus a purple-team walkthrough

Few programmes sit in one column. A common shape is a small population with large reporting — one entity, one language, an organisation-specific pretext, email only, a detection walkthrough — more work than a ten-thousand-recipient round ending at a summary figure, and worth more.

Five answers make any two proposals comparable: the population by cohort with counts, the pretext level, the channels, the rounds in the first year, and the reporting depth. Leave any of them open and each firm will assume a different one, reasonably, and the quotes will describe different pieces of work.

About the author

Parnika Kelkar

Head — People & Culture

Senior HR generalist partnering with leadership to drive talent acquisition, policy design, compliance, and an engaging workplace culture at Security Brigade.