Skip to main content
Skip table of contents

How to set up Phishing Simulation

Should you choose the SoSafe Default Setup or Custom Setup?
SoSafe Default Setup is a better choice when you don’t need customization. To get started, choose a start date and get the awareness training configurations based on the subscribed package.

Custom Setup is better when you want to customize content selection, start/ end dates, and individual reporting.

Where to configure Phishing Simulation training?

Awareness training requires targeting at least one active user. Before proceeding with the awareness training setup, you must complete Step 1 (Add users).

Learn how to add the first users in the How to Manage Users article.

You can create your first Phishing Simulation training from the following locations:

  1. Dashboard

    1. Go to the Dashboard menu item, Setup Awareness Training section, Custom Setup, and click the button New Phishing Simulation (1).

    2. You can select to Run a 2-week assessment training (2) if you are not sure yet what to choose. It will help to evaluate the user’s phishing awareness.

image-20250417-171030.png

Options available in the Custom Setup reflect the package purchased:

  • Phishing Simulation + E-Learning

  • Phishing Simulation

  • E-Learning

  1. Go to the Phishing Simulation menu item and click the New Phishing Simulation button to create a Phishing Simulation training.

    image-20250417-171133.png

Create a Phishing Simulation training

  1. Click the New Phishing Simulation button

  2. On the Name and dates page:

    1. Add a Training name

    2. Select the Start date and End date.

    3. Click the checkbox End training on the client’s subscription end date to prefill the training end date automatically. Note that the end date cannot exceed the client’s subscription end date.

    4. Click Next

      name.png

You can create multiple Phishing Simulation trainings. Choose a training name that you can easily recognize when reviewing the Phishing Analytics results.

  1. On the Select email templates page:

    1. Use anchor links (1) on the left to navigate through year 1, year 2, and year 3 recommendations.

    2. Use Categories (2) to filter the Phishing Simulation templates by category. All categories are shown by default.

    3. Use list/ card view (3) for template display as per your preference.

    4. Click Preview (4) to view the template details.

    5. Select the checkboxes (5) for the templates you want to add to the Phishing Simulation training.

We recommend distributing the simulation templates across multiple years based on each client’s maturity level and previous exposure to phishing simulations. This approach helps ensure sustained user engagement and better long-term knowledge retention.

The platform offers a recommended distribution to help with this process, but ultimately, it's up to you to choose which templates to incorporate into the awareness training.

image-20250417-172213.png
  1. Click on Training summary (6) to see the summary of templates that will be added to the Phishing Simulation training.

image-20250417-172405.png

How many templates should you add to a Phishing Simulation?

We recommend sending out between 1 and 2 phishing simulation emails per month. You can check the average cadence in the Training summary.

  1. Click the Next button after you finish the template selection.

  2. On the Reporting setting page:

    1. Training results are set to be Anonymous by default.

    2. Select Individual to track employees' clicks and interactions at the employee level..

    3. Click the Next button to move to the final step.

The reporting setting selection should be based on each client's legal and compliance requirements.

These reporting settings are configured independently for each training and cannot be changed after the training starts.

reporting.png
  1. On the Training summary page, click the Save & launch button to launch the Phishing Simulation training.

image-20250417-172959.png

Whitelisting is a critical step for Phishing Simulation training that prevents emails from being blocked by spam filters, firewalls, or security settings. If you haven’t configured whitelisting yet, you’ll need to finish it before the Phishing Simulation start date. Learn more in the Partner Platform Whitelisting Guide.

What to Read Next and Related Articles

JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.