The bottom line: monthly for the general population and every two weeks for high-exposure roles, varying difficulty so people never learn to recognize the drill
How often should you send phishing simulations? The operating answer that most mature programs now share is simple: one simulation a month for the general population and one every two weeks for high-exposure roles (finance, leadership, human resources and IT support), always varying the difficulty and the pretext so people learn to spot the attack, not the format of your drill. The first step is not opening the template catalog, it is deciding who is most exposed, because the right cadence depends on role before it depends on the calendar. What follows develops that answer: why frequency matters, how it breaks down by role, how to avoid fatigue, and how to tell whether it is actually working.
Why once a year changes nothing
Annual training is still the default in many companies, and it is also the model that moves behavior the least. The reason is rhythm and memory: someone who gets a single reminder a year has no way to keep the reflex alive when the real email arrives eleven months later. And the real email never stopped coming. CISA estimates that more than 90 percent of successful cyberattacks start with a phishing email, so the channel that annual practice touches once is the same channel almost everything comes through.
Worse, that channel has grown more dangerous, not less. The Microsoft Digital Defense Report 2025 found that AI-driven phishing is now three times more effective than traditional campaigns. Practicing once a year against an adversary that sharpens its craft every month is like rehearsing the evacuation in January for a fire in December. Frequency is not a matter of discipline for its own sake, it is what keeps the reflex level with the attack.
Human risk is managed automatically.
Turn human risk into your first line of defense.
Book a demoFree demo · 30 minutes · No commitment
Cadence by role: finance, leadership and HR versus everyone else
The human factor is not spread evenly across teams. Cisco's 90-5-5 framework, which estimates that close to 90 percent of breaches involve a human factor, describes the problem at the company level; role-based cadence brings it down to the person. Not everyone faces the same level of attack, so it makes no sense to test everyone at the same frequency.
Roles with access to money, to sensitive data, or to the power to approve access get attacked more often and more precisely. The finance team is the target of business email compromise (BEC), where an attacker impersonates a vendor or an executive to reroute a payment. Leadership concentrates the authority a pretext exploits to skip controls. HR handles personal data and opens attachments from strangers as part of the job, from resumes to supporting documents. IT support can reset passwords and second factors, which makes it the key many attackers chase by phone.
For these groups, a two-week cadence keeps the reflex awake without overwhelming them. For the rest of the organization, once a month sustains the habit without becoming noise.
| Group | Suggested cadence | Why |
|---|---|---|
| Finance, leadership, HR and IT support | Every two weeks | They face more frequent, targeted attacks such as BEC and help-desk fraud |
| General population | Once a month | Sustains the habit without saturating or creating noise |
| New hire | First simulation within their first 30 days | It is their window of greatest exposure and should not wait for the next quarterly cycle |
Simulation fatigue: the risk of repeating the same style
Raising frequency has a limit, and it is not the one most people imagine. The problem is not the number of emails, it is repeating the same style. If every drill arrives with the same sender, the same tone and the same hook, people stop learning to detect attacks and start learning to detect your drills, which is a useless skill on the day of the real attack.
That is why a healthy cadence rarely exceeds one to three simulations per person per month, and above all it varies three things on each send: the pretext (authority, urgency, curiosity, reward), the apparent channel and the difficulty. That variation, tuned to each person's role and behavior, is what keeps the lure from becoming predictable.
Fatigue is also emotional. A program that only punishes failure breeds resentment, and with it come false reports and people who learn to hide the mistake instead of flagging it. Simulation exists to measure and to teach, not to trap, and the tone of the follow-up decides whether the team cooperates or shuts down. A well-calibrated cadence shows in the tone as much as in the number.
Where the retest comes in: repeating is not the same as testing the lesson again
It is worth separating two things that often get confused: repeating a simulation and running a retest. Repeating means sending another drill in the next cycle. A retest is deliberate: when someone falls for a lure, weeks later they receive a simulation of the same category and difficulty, but with a different template and context, to check whether they learned the mechanism of the deception rather than memorizing that one email.
The distinction has backing. Peer-reviewed evidence (Ho et al., IEEE S&P 2025; Lain et al., IEEE S&P 2022) shows that completing training does not on its own predict a reduction in real failures; what proves the change is testing behavior again. Without a retest, cadence measures activity: how many emails went out. With a retest, cadence measures learning: whether the person resists the same deception when they are no longer expecting it. That is why frequency and retest are parts of the same mechanism, not two separate decisions, and why click rate, report rate and retest are read together rather than in isolation.
How to tell whether the cadence is working
A cadence works when behavior metrics improve steadily, not when the calendar is full. A human risk management (HRM) program watches three signals together. First, the click rate in high-exposure roles drops and stays low across several sends, not in a single lucky month. Second, the report rate rises: people not only avoid falling, they raise the alarm, turning each employee into a sensor. Third, and most important, those who failed and then passed a retest of the same category stop reoffending.
If you raise frequency and none of the three moves, the problem is not the cadence, it is the content or the follow-up. And if the click rate falls but the report rate does not rise, you may be training people to recognize your drills rather than attacks. If you want to go deeper on how many employees you need for the measurement to be valid and other common questions, we gathered them in our human risk management FAQ.
At Fensivo we treat cadence as part of a cycle, not a loose calendar. Each person receives one to three email phishing simulations a month, chosen by their role, their prior behavior and the platforms their company actually uses, and anyone who fails enters a retest of the same category weeks later to confirm the change held. You can see how it fits an operation of 25 to 500 employees in our use cases.
So the question is not only how often you send simulations. It is this: is your current cadence measuring what your people learned, or just proving that your calendar is full?
Human risk is managed automatically.
Turn human risk into your first line of defense.
Book a demoFree demo · 30 minutes · No commitment
