What moves the effort of a phishing simulation programme
Very little of the effort in a phishing simulation scales with headcount. The six drivers that actually move it, and how to place a programme in a small, medium or large band before asking for a proposal.
The first question about a phishing simulation programme is how large it will be, and the number reached for is a headcount. It is the wrong number: very little of the work scales with how many people receive the message. It scales with how much of the campaign is built for this organisation specifically, how many channels are in scope, how often the round repeats, and how far the reporting goes past a single figure.
Every round has a heavy block and a light one. The heavy block is done once — the authorisation, the cohort scheme, the pretext, the sending infrastructure, the reporting format and the analysis. The light block is the send. Almost every decision that moves a programme's size moves the heavy block, which starts before any message exists.
Specific written permissions must be obtained from the auditee organization before conducting tests that involve survivability failures, denial-of-service (DoS), process testing, or social engineering.
That is CISG-2025-02, Version 1.0, 25 July 2025, §13.2.7(ii), p. 50. Reaching that signature means agreeing the population, the exclusions, the channels and the pretext boundaries — effort a larger population does not increase.
Population size counts for less than population complexity
Two thousand recipients and ten thousand recipients — one organisation, one language, one mail environment — are close to the same amount of work. The pretext is written once. The infrastructure is stood up once. The marginal recipient is nearly free; the first one carries everything.
What does grow with headcount is the operational tail: reported messages at the service desk, calls to the security contact, escalation traffic inside the window. Most of it lands on the organisation being tested, so plan for it.
Complexity is different: it multiplies the heavy block. Each of these turns one campaign into several.
- Languages. A second language is a second pretext, a second landing page and a review by a native speaker. A translated message is a different test, not the same one rendered again.
- Legal entities. Each has its own signatory for the §13.2.7(ii) permission, its own exclusions, and its own position on what may be imitated.
- Countries and mail environments. Separate windows and holidays, results that may not pool into one figure; two tenants means two sets of delivery preparation and telemetry.
- Contractor and outsourced populations. §15.2.2(iii), pp. 55–56, confines the test to employee groups explicitly included within the agreed audit scope, and excludes customers, business partners, vendors and other third parties unless specific written consent is obtained from the target organisation. That is settled group by group before an outsourced desk can be included.
An eight-hundred-person programme across five entities, four languages and three mail environments is more work than a ten-thousand-person programme in one company that speaks one language.
Pretext bespoke-ness, where the effort really goes
The dominant driver, and the one buyers most often leave unspecified. Three levels, far apart.
| Level | What is built | What it takes |
|---|---|---|
| Generic lure | A pretext that could go to any organisation — a delivery notice, a password expiry, a shared document | Least. No discovery, no internal review, one build for the whole population |
| Organisation-specific | A pretext drawn from the organisation's own systems, vendors and calendar: the tool people use, a supplier they deal with, a month in which it would plausibly arrive | A discovery pass, a decision on which brands may be imitated, and a review by whoever fields the reaction |
| Per-target reconnaissance | A pretext per target or small group, built from what is discoverable about an individual's role and current work | Most — the only level whose effort scales with target count, because research and pretext are per person |
Most regulated programmes settle on the middle level. A generic lure measures whether people click on obviously external messages; a pretext built from the organisation's own furniture measures whether they can tell an internal-looking message from an internal one, which is what a real campaign tests. Getting there means learning the environment well enough to write it, then ruling themes out — pay, medical, redundancy, bereavement and impersonation of named individuals generate the complaints, and that is HR's call.
The third level is a different shape rather than a bigger one, and the one place population size and effort couple — which is why a spear phishing round is scoped over a small, chosen cohort. Difficulty band is part of the design too: holding it steady is what makes two quarters comparable.
Channel mix
Email is the baseline and, for most programmes, the whole of round one. SEBI's PR.AT Guidelines, pp. 103–104, describe awareness campaigns that "stress the avoidance of clicking on links and attachments in email". Every channel added past it brings three things of its own.
- Its own authorisation. §13.2.7(ii) attaches to the test actually run, so a channel has to be named in the permission before it can be exercised.
- Its own preparation. Vishing needs call scripts, a named procedure and version under test, and a decision on what the caller may claim. Physical pretexting needs site-level authorisation, a named site contact and a carry letter.
- Its own execution window. An email round can go out in an afternoon. Calls happen one at a time, in working hours; a site visit needs someone present. Elapsed time does not compress.
Vishing is best scoped as a test of a process rather than a person — whether the service desk's verification procedure holds under pressure. That is the framing CERT-In's engagement types support at §6, pp. 14–17, items (x) Process Security Testing and (xvi) Red Team Assessment, a list given as "including, but not limited to".
Cadence, and the part that runs the other way
Cadence is read off the instrument that binds the entity. The RBI Directions, 2026, issued 31 July 2026, require a commercial bank to "evaluate the awareness level of employees periodically" at ¶202 — the same sentence at ¶201 for payments banks and small finance banks, and ¶197 for credit information companies. NBFCs carry ¶36, p. 19: a "formal mechanism to measure and track the effectiveness of such training through periodic assessments or testing", plus an "up-to-date repository of the training and awareness status of all users". SEBI's CSCRF, v1.0, 20 August 2024, says at §3.2 PR.AT, p. 63, that such programmes "shall be conducted on a periodic basis", while row 9 of its periodic-compliance table reads "Cybersecurity training program (PR.AT.S1) — All REs — Annually".
What repetition does to effort runs against expectation. Round one carries the whole heavy block. Later rounds inherit the authorisation, the cohort scheme, the infrastructure and the report format, leaving a new pretext, the send, the analysis and a trend line. Per-round effort falls after the first round; total effort rises with the number of rounds. A quarterly programme is not four one-offs: it is one first round, three lighter ones, and the standing work of keeping the ¶36 repository current.
Reporting depth
Reporting changes what a round is worth more than anything else in it. Three depths.
- Population summary. The figures for the population as a whole. §15.2.2(iii) requires that testing aimed at general staff "must utilize anonymized or statistical techniques—ensuring no individual is personally identified or penalized", so this is the floor everything else is built on.
- Cohort breakdown. Effort tracks the number of cohorts rather than the headcount, and the cohorts worth drawing are the ones the clause is written about: for a commercial bank, ¶203's new recruits and lower and middle management, and ¶204's Board members and Senior Management; for a Level III or Level IV urban co-operative bank, the upper management named at ¶156. Drawn on those lines the result is evidence against a paragraph rather than a report somebody must translate.
- Purple-team detection walkthrough. A working session with the organisation's own security and mail teams over what the gateway did, what was quarantined, what alerted, and what happened to the messages people reported. The most effort-heavy option by a distance, and usually where the value is once the click figure is known.
Packaging the result as an audit artefact — population, dates, the authorisation reference, the retention position over identified data — costs little at the start and a great deal a year later.
So: small, medium or large
Read down the column that matches most of your answers.
| Driver | Small | Medium | Large |
|---|---|---|---|
| Population | One entity, one language, one mail environment | One or two entities, up to two languages | Several entities, languages or countries; contractors needing a consent position |
| Pretext | Generic lure, one difficulty band | Built from the organisation's own systems, vendors and calendar | Organisation-specific, plus per-target reconnaissance for a chosen cohort |
| Channels | Email, plus vishing against one named procedure | Email, vishing and physical pretexting, each separately authorised | |
| Cadence | A single round, or a baseline | Half-yearly or quarterly, with a maintained repository | Quarterly across entities, on a compliance calendar |
| Reporting | Population summary | Cohort breakdown mapped to the clause, with an evidence pack | Cohort breakdown plus a purple-team walkthrough |
Few programmes sit in one column. A common shape is a small population with large reporting — one entity, one language, an organisation-specific pretext, email only, a detection walkthrough — more work than a ten-thousand-recipient round ending at a summary figure, and worth more.
Five answers make any two proposals comparable: the population by cohort with counts, the pretext level, the channels, the rounds in the first year, and the reporting depth. Leave any of them open and each firm will assume a different one, reasonably, and the quotes will describe different pieces of work.
About the author
Parnika Kelkar
Head — People & Culture
Senior HR generalist partnering with leadership to drive talent acquisition, policy design, compliance, and an engaging workplace culture at Security Brigade.
Continue reading
All articles →Spear phishing versus bulk simulation: what changes in the test and in the numbers
A spear campaign and a bulk campaign measure different things over different populations. Why their rates cannot share a trend line, and how a six-person cohort is reported when a percentage would identify people.
Scoping a phishing simulation programme in India
What has to be decided before the first send: the population and its cohorts, the scope boundary, the cadence, the channels, the exclusions, the escalation contacts and the written authorisation CERT-In requires.
Measuring the executive population
RBI ¶204 addresses the Board and Senior Management separately, and CERT-In's reporting rule makes a percentage over twelve people an individual result. What an executive exercise reports instead.