Support desk — Monday to Friday, 08:30 to 17:30Client AreaGet help now →

Launch a phishing simulation in usecure

Launch a phishing simulation in usecure – EasyLifeIT guide
For IT administratorsAbout ten minutesusecure

A phishing simulation is only worth running if the result tells you something you did not already know. That depends less on the template you pick than on three settings people skip: how the sends are spread out, whether inline training is switched on, and whether you told anyone it was coming. Get those right and you get a genuine baseline. Get them wrong and you get a number that means nothing.

Before you start

  • Do not warn the users. Tell the senior person who needs to know, and nobody else. A warned population gives you a flattering number and no information.
  • Do decide what you will do with the result before you run it. If the answer is nothing, do not run it.
  • Never use it as a disciplinary tool. The moment people believe clicking gets them in trouble, they stop reporting real phishing, and you have made the business less safe rather than more.

Building the simulation

  1. Start a new one. Go to uPhish, then Create simulation.
  2. Choose the attack type. Landing Page sends them to a fake sign in page. Attachment Open tracks who opens a file. Attachment Open + Landing Page does both. Start with Landing Page for a first run, because it is the closest to how real credential theft works.
  3. Pick a template. Choose from the supplied templates or from Your Saved Templates if you have built your own. Pick something plausible for the time of year and the business, not the most obvious one in the list.
  4. Fill in the details. Simulation name, subject line, sender name and email address, and the landing page domain. There is a Use a custom sender email address option if you need the from address to look like something specific.
  5. Send yourself a test. Use Send test email and actually read it on a phone as well as a desktop. This is where you catch the broken formatting that would have given it away.
  6. Choose who gets it. Send to All Users, or Select Recipients for a department or a group.
  7. Set the timing. Pick the date and time to start, then set how many hours the emails should be spread over, and whether to send only during working hours.
  8. Create it. Click Create Simulation.
Spread the sends out

If everyone gets the email at 09:02, the third person to click will be telling the office about it by 09:10 and your results are worthless from that point on. Spread the distribution over several hours. It is the single biggest difference between a simulation that measures something and one that measures how fast gossip travels.

Turn inline training on

Under Settings, uPhish, Inline Training, you can have anyone who falls for the simulation automatically enrolled onto training. usecure’s recommendation, and ours, is Phishing Incremental Inline Training, which steps people up through levels if they are caught more than once.

This matters because it changes what the simulation is for. Without it you have a test. With it you have a teaching moment landing at the exact second somebody is most receptive to it, which is right after they have realised they were caught.

What the platform does and does not record

Worth knowing, and worth repeating to anyone in the business who asks awkward questions about it, because the answer is reassuring.

  • Opens are tracked with a pixel in the email, and are also inferred if somebody later clicks.
  • Clicks are recorded when the user arrives on the landing page, and a click is inferred automatically at that point.
  • Compromise depends on the attack type you chose.
  • usecure does not collect or store anything users type into the phishing landing pages. Nobody is harvesting your colleagues’ real passwords.
  • Opening an attachment in Protected View blocks the visit and compromise events. They are only recorded once Enable Editing has been pressed, so attachment based results under-report by design.

Reading the results

Simulation performance appears in the reporting area, filterable by group and by template, showing opens, clicks and the compromised rate over time. The number to watch is not the first one. A single simulation gives you a baseline and nothing else; the trend over three or four is what tells you whether anything is improving.

Tell people afterwards

Share the headline result with the whole business, with no names, and say plainly that a percentage of people clicked and that this is normal. It removes the shame, it makes the next one more accurate, and it is the thing that gets people reporting real phishing to you.

Common questions

Our email filter blocked the simulation.
The sending domains usually need allow-listing before the first run. Tell us and we will sort it, otherwise your result measures your filter rather than your people.
Somebody reported it as phishing. Does that count?
It is the outcome you actually want. Report rate is a better measure of a healthy business than click rate is of an unhealthy one.
How often should we run these?
Monthly is common and quarterly is plenty for most small businesses. More often than monthly and people simply learn to distrust all internal email, which has its own costs.
Can you run these for us?
Yes. If we manage your usecure we will run the programme, handle the allow-listing and send you the trend rather than the raw numbers.

If you need a hand

Call the service desk on 03333 22 11 00 or email support@easylifeit.com.

Take this guide with you

A clean branded copy you can print or save as a PDF, with our service desk details on every page.

Get the PDF

Steps and option names checked against usecure’s help centre, Creating a phishing simulation and How we track phishing simulations, September 2026. usecure change the console periodically; if a label here does not match, the setting has usually moved rather than gone.

Found this useful?

We write these because the same questions keep coming up. If one of them is yours, the answer is usually a short conversation away.

Keep reading