Blogs Phishing Simulation Gover...
A phishing exercise can reveal more than who clicked. Without clear decision rights and boundaries, however, the same exercise can create privacy concerns, confuse incident response, or reward a lower click rate without proving safer behavior.
Phishing simulation governance is the operating model that defines why an exercise runs and who approves it. It also defines what data it may collect, how teams respond, and how results lead to measured behavior change. It treats a simulation as one signal within Human Risk Management (HRM), not as a complete verdict on an individual or team.
That distinction shifts the conversation from campaign mechanics to accountable oversight. The first step is to define what the exercise is allowed to measure, influence, and escalate, so every later decision has a defensible purpose.
See how Living Security supports responsible human risk management
Human Risk Management governance determines why a phishing simulation exists, who is accountable for it, what evidence it should produce, and where its boundaries lie. It is not the same as choosing an email theme, scheduling a send, or configuring a reporting workflow. Those are campaign tactics. Governance connects the exercise to business risk and ensures the results are interpreted responsibly.
A simulation should be treated as one signal within a broader human-risk program, not as a verdict on an individual or a complete measure of security. California guidance describes phishing exercises as a way to measure employee understanding, observe progress in user behavior, and support reductions in security incidents and malware attacks. Those are governance outcomes, because they shape what leaders approve, measure, and improve. The guidance applies to California agencies and state entities, so organizations elsewhere should use it as a reference rather than assume its requirements are universal. Read the standard.
NIST authors describe embedded phishing training as a way to deliver awareness content, but caution organizations to understand what that training can and cannot do. Users cannot reasonably be expected to avoid every phishing scam. And a click can reflect the context and premise of a message as much as a stable personal tendency. That is why a single click rate should not trigger a broad risk judgment.

In practice, phishing risk management governance sets the decision rights around objectives, approvals, privacy safeguards, escalation, measurement, and follow-up. It asks whether the exercise will help people recognize and report threats, whether its design is proportionate, and how the organization will act on what it learns. The campaign is the test; governance is the system that makes the test useful, fair, and connected to behavior change.
Governance starts by defining what the exercise is meant to improve and who is accountable for deciding whether it should proceed. An outcome-based objective might be to improve reporting behavior, strengthen recognition of a defined threat pattern, or reduce repeat exposure in a group with a specific access context. A click rate can be one signal, but it should not become the program's sole verdict.
Assign one accountable owner for the exercise and document the decision rights around that owner. Specify who can approve the objective, audience, message, landing experience, timing, data collection, and follow-up. California guidance, for example, calls for security officers to approve each exercise and its email templates. That requirement applies to the agencies and state entities within its scope, not universally to every organization. The broader governance lesson is to require explicit approval rather than allowing a campaign to move from idea to execution without accountable review.
A written plan turns that principle into evidence. At minimum, record the desired outcome, population, owner, approvers, decision criteria, communications plan, stop conditions, and measures for review. Include pre- and post-exercise messages and protocols so stakeholders know how the activity will be introduced, managed, and closed. The guidance also emphasizes steps before and after execution, including controls that properly manage the test. These details make the exercise auditable and help connect the activity to a broader human risk management framework.
Finally, treat exceptions as governed decisions, not informal workarounds. If an organization varies from an applicable standard, document the reason, the risk assessment, the compensating control, and the person who accepted the risk. Where applicable, include a Plan of Action and Milestones (POAM), as California's standard describes. This creates a clear record of why the exception exists, what will change, and when the decision will be revisited.
Responsible simulations begin with proportionality. Collect only the information needed to answer the governance question, such as whether a message reached a defined audience, how people responded, and what coaching may help. A click should be treated as a context-specific signal, not a permanent verdict about an individual. Keep the purpose focused on improving behavior and reducing exposure, rather than turning a learning exercise into an undisclosed personnel record.
That boundary should be explicit before launch. Separate coaching workflows from punitive personnel action, and document who can see individual-level results, who receives aggregated findings, and who can approve an exception. Privacy, legal, people, and security stakeholders should review scenarios that could create confusion or harm. California guidance advises against sensitive or inappropriate material and specifically calls out union names, legal or contractual issues, political themes, and commercial trademarks without approval. Those are useful guardrails for any program, even though the guidance itself applies to California state entities and should not be treated as a universal legal mandate. Review the source guidance for the exact scope and wording.
Access controls matter as much as scenario design. Limit forwarding so a test message does not circulate beyond its intended audience. Prevent shared mailboxes or broad distribution lists from turning a controlled exercise into an avoidable disruption. Define the retention and cleanup approach in advance: identify what evidence is needed for learning and assurance. Who owns it, how long it remains available, and when test messages and unnecessary copies are removed. The same California guidance recommends controlling forwarding and removing exercise emails from employee and shared mailboxes after completion.
These safeguards make privacy-aware behavior governance practical. The goal is not to eliminate useful measurement. It is to make every data point purposeful, access-limited, reviewable, and connected to a defined improvement decision.
Approval is not a ceremonial step in phishing simulation governance. It is the point where security, business owners, privacy stakeholders, and incident responders agree on the exercise's purpose, scope, timing, and boundaries. Put the accountable owner in writing, identify who can approve a change, and preserve the final message set and audience list as the version of record.
Coordination should include the teams most likely to encounter the exercise as a real event. California guidance recommends advance notice to affected business areas, including the IT help desk and the information security office. Those teams need enough context to distinguish an approved exercise from a live phishing report without broadly disclosing the test to participants. The guidance specifically names these groups as coordination points.
Define stop conditions before launch. Examples include an unexpected operational impact, a message reaching an excluded audience, a suspected compromise, or a surge of reports that requires incident handling. The help desk should know where to route questions, while the security office should own the decision to pause, investigate, or resume. Do not let a campaign operator improvise those decisions during an active event.
Build change control around material differences. A new audience, altered premise, changed timing, or revised landing experience should return to the relevant approvers rather than being treated as a minor edit. California's guidance calls for approval of the exercise and its templates, and says notification should include the proposed emails. It also states that the exercise must not begin before the required notice. In that California public-sector context, the notice is at least 72 hours before the exercise, not a universal enterprise rule. Use the applicable jurisdiction and internal policy to set the actual threshold.
Finally, document the escalation boundary: what the program team handles, what belongs to the help desk, and what becomes a security incident. That clarity protects response teams from confusion and keeps a learning exercise from obscuring a genuine threat.
A click rate is useful activity data, but it is not a complete risk measure. It tells leaders that a tracked interaction occurred in a particular scenario. It does not, by itself, show whether people recognized the warning signs, reported the message, changed their response later, or helped reduce real incidents. A governance model should therefore connect measurement to decisions, not treat one percentage as a verdict on an individual or team.
| Measure | What it shows | Governance question |
|---|---|---|
| Activity | Interactions such as opens, clicks, submitted information, or reports during the exercise. | Did the exercise produce the intended observable response? |
| Behavior | Whether users recognized the message, reported it, followed the expected process, and improved across comparable exercises. | Is behavior moving toward the safer action, and where is reinforcement needed? |
| Exposure and context | Role, workflow, message type, timing, and other conditions that help explain why a response occurred. | Was the result shaped by a relevant work context, or by the design of the test? |
| Outcome | Lessons from responses and, where appropriate, changes in security incidents or malware exposure. | Did the program contribute to meaningful risk reduction? |
California guidance frames exercises as a way to measure employee understanding, track progress in user behavior, and support efforts to reduce security incidents and malware attacks. Its guidance also recommends observers, note-takers, or application logs to capture different response types and lessons learned. Those layers help a review group distinguish a design problem from a coaching opportunity and decide whether to adjust content, provide targeted follow-up, or change escalation rules.
For a deeper measurement framework, see phishing program performance metrics. The goal is not to collect every possible signal. It is to maintain enough evidence for accountable leaders to make a proportionate decision.
The message sent after a simulation should turn a result into a useful next step. Give immediate, plain-language feedback that explains the cues employees could have noticed, how to report a suspected phish, and where to get help. The goal is learning, not embarrassment. A simulation is one signal inside a broader Human Risk Management program, not a complete verdict about a person.
Follow-up should be proportionate to the behavior and its context. A click may indicate a moment of pressure, an unfamiliar workflow, or a message that closely matched the employee's normal responsibilities. A program can consider identity, access level, role, recent threat exposure, and recurrence before deciding what support is appropriate. That does not mean creating a permanent label. It means using available context to provide relevant coaching and protect the business without turning an exercise into surveillance.
Track whether the same behavior recurs across campaigns, then offer focused reinforcement rather than assigning identical mandatory training to everyone. A healthcare-system study followed 5,416 employees across 20 campaigns and found that click rates decreased for each group. However, mandatory training introduced after campaign 15 did not substantially affect click rates, and employees previously classified as offenders remained more likely to click. Those findings support reviewing the intervention itself, not simply escalating the penalty.
Research also argues for testing what actually helps. In a field experiment involving more than 10,000 employees of a Dutch ministry, both information and simulated experience reduced password disclosure. Combining them did not produce a larger impact than either approach alone. The result is not a universal formula, but it is a reminder to measure each follow-up pathway and retain the ones that improve behavior in your environment. For practical guidance on employee phishing simulation training, connect feedback to reporting practice, access risk, and the next review cycle.
Finally, define a non-punitive escalation boundary. Repeated risky behavior may warrant manager or security review when access or exposure makes the risk material, but the reason and decision owner should be documented. Close the loop by recording the coaching provided, the behavior observed, and the next check, while limiting access to that record.
Strong phishing simulation governance is easier to sustain when it operates as a cycle rather than a one-time approval. Each round should create evidence for the next decision, while keeping disruption and employee exposure proportionate to the learning objective.
Talk with Living Security about a people-first HRM approach
It defines why simulations run, who approves them, which audiences and scenarios are in scope. How privacy is protected, when a test must stop, and how results lead to follow-up. A written plan should cover pre- and post-exercise communications, operating protocols, decision rights, and review of exceptions.
The accountable security owner should coordinate approval with the relevant privacy, legal, people, communications, and technology stakeholders. California guidance provides one example of formal oversight: it calls for approval of each exercise and its email templates by designated information security officers. But that requirement is not universal across organizations. California phishing training guidance
Use the least intrusive scenario that supports the objective, avoid sensitive or inappropriate themes, restrict access to individual results, and define retention before launch. Contain test messages and remove them from employee and shared mailboxes after the exercise, controls recommended in California guidance. California phishing training guidance
Measure the behavior the program is meant to improve, such as reporting, credential submission, safe verification, repeat responses, and time to contain a report. Pair activity data with employee understanding and security outcomes. California's standard identifies understanding, user behavior, and reduced security incidents as distinct measurement goals. California phishing exercise standard
A responsible phishing simulation program works best when governance, privacy, measurement, and behavior change stay connected. Living Security can help your team see how a people-first approach supports clearer decisions and more useful follow-up.
Request a demo of Living Security's Human Risk Management platform
Crystal Turnbull is Director of Marketing at Living Security, where she leads go-to-market strategy for the Human Risk Management platform. She partners closely with CISOs and security leaders through executive roundtables and industry events, helping organizations reduce human risk through behavior-driven security programs. Crystal brings over 10 years of experience across lifecycle marketing, customer marketing, demand generation, and ABM.