Phishing Simulation
Scoping Template
A simulation is a measurement instrument, and everything that makes the number worth anything comes from conditions fixed before it runs. Click rate is what everybody quotes. Report rate — how many people told somebody — is the one that says whether the human layer works. This is the worksheet you fill in before commissioning one.
Phishing Simulation Scoping Template
Enter your work email for the printable pack — the objective archetypes, the population register and its denominator rule, the difficulty tiers, the measure set and outcome vocabulary, the authorisation and handling checklists, the evidence record, the remediation loop, and the worksheet you issue.
Check your inbox
We've emailed you a link to download Phishing Simulation Scoping Template.
The link expires in 48 hours. If it hasn't arrived in a few minutes, check your spam folder.
We couldn't send the download link. Please try again, or contact us and we'll email you Phishing Simulation Scoping Template.
The argument
Click rate measures a moment. Report rate measures the organisation
An organisation where a third of the population clicked and most of them told the incident team within minutes is in a materially better position than one where almost nobody clicked and nobody said anything. In the second case the next message — the one that is not a simulation — arrives unannounced and stays that way. The pack fixes the measure set in writing before dispatch, because a measure chosen afterwards is chosen by whoever liked the result.
Report rate
How many people told somebody.
The only measure that describes the organisation rather than the individual, because a report needs three things at once: a person deciding to speak, a route that exists and is known, and a team that receives and acts. All three are separately fixable. It is also the only number on the page that can go up when everything else does.
Time to first report
How long you were unaware.
Two timestamps on the same clock — dispatch, and arrival at the queue of a team that can act, rather than at the mailbox in front of it. Define the second one explicitly or a report sitting in a shared mailbox until Monday counts as an instant success.
The interaction-to-submission gap
Curiosity, against a credential in somebody else’s hands.
Two different failures with two different fixes. A wide gap says people stopped when they were asked for something. A narrow one is the finding with an operational consequence, and it points as much at the authentication behind the credential as at the person in front of it.
Reports arriving off-route
Whether the route people use is the one you published.
A process finding, never a person finding. If most reports reach a line manager first, then the route is the line manager and the published one is decoration. Counted separately, and never discarded.
Neither this page nor the document publishes a benchmark, and you should treat anybody else’s with care. A published rate carries five things with it — the scenario, the difficulty tier, the population, the denominator rule and the definition of what counted as an interaction — and a figure quoted without all five is not a comparison. Your own previous result, taken on the same definitions, is the only one that means anything.
What it settles
Six decisions, and each one constrains the next
Settle the objective and the population narrows; settle the population and the scenario narrows; settle the scenario and the measure set is nearly written. Scoped in the other direction — a campaign booked, a number produced, an objective supplied afterwards for the summary slide — the result cannot be defended the second time it is questioned.
01
The objective, and the three others it is not
A baseline before anything changes, evidence for a named obligation, a test of whether the reporting route works, or a re-measurement of one population after an incident. Four different exercises with four different populations, scenarios and reports — and an exercise with all four objectives has none.
02
The population, and the denominator underneath it
Whole organisation, function, or role-based by what a person can actually do. Then the part that moves quietly: bounces, departures, shared mailboxes, mail rules and absence all change the number a rate is divided by, and none of them is a behaviour. Two exercises whose denominators were built differently cannot be compared, however alike the percentages look.
03
Scenario difficulty, fixed before dispatch
The most alarming pretext available will catch people, and the result then says only that a sufficiently good message works. The pack fixes a difficulty tier in advance and prints it beside every rate, because a rate without its tier cannot be compared with anything — including your own last exercise.
04
What is measured, agreed in writing
Click rate is the number everybody quotes and the least useful. Report rate, time to first report, reports arriving off the published route, and the gap between an interaction and a credential submission are the four that describe the organisation rather than the individual. A measure chosen after the exercise is chosen by whoever liked the result.
05
Authorisation, employment and handling
Who signs, which employment and works-council obligations reach the exercise, what the provider may collect, and the decision that individual results are not a performance-management instrument. That one is made before dispatch, because the answer changes what may be collected at all.
06
The evidence record, and the loop after it
Scope, date, population, method, results and what changed afterwards — written while the exercise runs, into the statement of work rather than asked for at the debrief. Then how to take the next measurement so the two can honestly be compared.
Contents
Eleven sections, nine of them things you fill in
It is a working document, not a guide. Section 1 is the boundary you read before answering anything, and section 11 is the only page where we describe what we do. Section 10 detaches and goes to the provider; section 7 is what you hold them to when the work comes back.
1. What this measures
The boundary, read before anything is filled in: a simulation is a measurement, training is an intervention, and where the same party designs the intervention and grades it the grade means very little.
2. The objective
Four worked archetypes against what each one changes, then the fields — the objective in one sentence, who asked it, what has changed since the last measurement, and what this exercise will not answer.
3. Population and sampling
Three ways to define a population and what each cannot tell you, eight sampling tests, and a register with the rule, the size, the rotation and every exclusion with its reason.
4. Scenario design
Four difficulty tiers described by what a recipient has to notice, eight scenario tests including the prohibited pretexts, and a register carrying the evidence behind each scenario and its approval date.
5. What is measured
Ten measures across three groups, a seven-state outcome vocabulary so the awkward answer has a word, and a results record — one row per population, never one per person.
6. Authorisation and handling
Three checklist groups: authorisation and consultation, what the provider may collect, and what the results are used for. Plus the anti-pattern, stated plainly.
7. Evidence and reporting
The eight elements a third party will accept, each with two columns — is it in the statement of work, and did it arrive in the report. This is the section the whole pack exists for.
8. The obligations behind it
RBI’s 2026 Directions, the SEBI CSCRF, CERT-In’s audit policy guidelines and ISO/IEC 27001:2022 — each quoted affirmatively, with its paragraph or standard reference and its own verb.
9. The remediation loop
Six things a result can point at and who owns each, then eight tests for holding the comparison still so that next year’s easier scenario cannot read as an improvement.
10. The scoping worksheet
The detachable page you issue: objective, population rule, denominator rule, exclusions, scenario, tier, channel, window, caps, measure set, handling, reporting format, re-measurement date, signature.
11. Where we fit
What a measurement engagement covers and what it produces — and, in the same block, what it is not for.
The anti-pattern
A simulation used punitively destroys the thing it measures
People who expect a consequence stop reporting — first their own mistakes, then anything ambiguous — and report rate is the number the exercise existed to move. The damage does not stay inside the exercise either: the reporting route is the same one a real incident arrives on, and a population that has learnt not to use it has learnt that for both.
So the decision is made before dispatch, written down, and said out loud when the results are published: individual results are not a performance-management instrument. Section 6 of the pack is the sheet that records it, alongside the employment, consultation and data handling positions that have to be settled in the same pass.
What the evidence answers to
Stated in the instrument’s own verb
Section 8 of the pack sets each of these out with its paragraph or standard reference and the regulator’s own wording, so a sentence lifted into a board paper can be found in the original. Several apply by entity class, so confirm which instrument names you before relying on a number.
RBI Directions, 2026
Shall Commercial Banks ¶202 · RBI/DoS/2026-27/410“The bank shall evaluate the awareness level of employees periodically.” The requirement is fixed and the method is left to the bank. Paragraph 201, immediately before it, requires that “the bank shall encourage the reporting of suspicious behaviour incidents to the incident management team” — which is what makes report rate the measure closest to a written obligation. Both appear in the sibling instruments under their own numbering: ¶¶200–201 for small finance banks and payments banks, ¶¶196–197 for credit information companies.
RBI Directions, 2026
Shall, with a may Commercial Banks ¶¶194 and 197Two verbs in two sentences. Paragraph 194 requires a set of prospective and retrospective measures and names “extent of user awareness training” among its illustrative examples. Paragraph 197 requires the adequacy of the cybersecurity framework to be assessed through indicators, and provides that “the awareness among the stakeholders including employees may also form a part of this assessment”. The assessment is required; treating employee awareness as part of it is permitted. Quote the paragraph, not a summary of it.
SEBI CSCRF
Shall GV.RM guidelines, Risk Management item 1(e)The regulator names the instrument in its own example: “REs shall periodically assess level of employee cybersecurity awareness, for e.g., through phishing test success rate, etc.” The requirement is the periodic assessment; the phishing test is offered as an illustration of how it may be done. Cybersecurity and Cyber Resilience Framework, SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113, 20 August 2024.
CERT-In audit policy guidelines
Must CISG-2025-02 §15.2.2(iii), 25 July 2025The strictest constraints in the pack, and they sit at the individual. Social engineering and process testing “should be conducted in a controlled and ethical manner”, and where general staff are targeted “such testing must utilize anonymized or statistical techniques—ensuring no individual is personally identified or penalized. The purpose is to evaluate overall awareness and the effectiveness of security processes, not to single out individuals.” It must target only employees explicitly inside the agreed audit scope, and must not reach customers, business partners, vendors or other third parties without specific written consent. Security Brigade is CERT-In empanelled and works to these guidelines.
ISO/IEC 27001:2022
Control Annex A 6.3 and Clause 9.1Annex A 6.3 requires awareness, education and training for personnel and relevant interested parties, updated as the policies change — and what an auditor samples is the evidence that it happened. Clause 9.1 requires the organisation to determine what is monitored and measured, including the objectives and the controls, and to define methods that produce comparable results. Comparability is the requirement section 9 of the pack is built around.
Instruments and paragraph numbers were checked against the issuing authorities’ own text on the review date printed in the document. Regulators amend, and consolidated instruments replace circulars that a great deal of published commentary still cites — check each paragraph against the source before it goes into a board paper or a tender response.
What it is, and what it is not
We measure the human layer. We do not train it
A training programme is an intervention; a simulation is a measurement of what an intervention has or has not achieved. We do not write, licence, host or assess awareness curricula, and nothing in this pack designs one — if what you need is a curriculum, that is somebody else’s engagement, and this is still the thing that tells you afterwards whether it worked. Awareness material appears once in the document, as one of six things a result can point at.
It is a governance and scoping pack for the buyer, so it also contains no pretexts, no tooling and no campaign instructions. Those belong in the provider’s test plan, written after the scope is fixed and governed by the authorisation register. And it names no provider: every field, register and gate in it is one we would be content to be held to, which is the only reason a document like this is worth forwarding to a colleague.
Have to show the human layer was tested?
Tell us who the evidence has to satisfy and which populations are in scope. Those two decide the measure set, the handling rules and the reporting format — and they are the fields that decide what the engagement costs.
Describe the measurement