Skip to main content

How to maximise the engagement rate of your HRR phishing simulations

Written by Kerryn Zendera
Updated over a week ago

A strong Human Risk Report depends on creating a realistic view of human risk. If your phishing simulation has low engagement because emails are not delivered, poorly timed, or too generic, the report may not demonstrate the full picture.

This resource helps you improve the engagement rate of your HRR phishing simulations so prospects see more meaningful results and you have a stronger basis for the follow-up conversation.

Why this matters

A more effective phishing simulation helps you:

  • Create a clearer proof point for the prospect

  • Show more realistic exposure to phishing risk

  • Build a stronger case for next steps

  • Support a more compelling HRR follow-up conversation

How to improve engagement

  • Make sure emails reach end users
    Before anything else, check that phishing emails can be delivered successfully. Allow-list usecure IPs and domains, and make sure Microsoft 365 is not quarantining or flagging messages unnecessarily.

  • Use information about the prospect
    End users are more likely to engage with emails that feel familiar. Use details such as the company name, internal departments, or recognisable services where appropriate.

  • Choose a relevant template
    The phishing email should feel believable and contextually relevant. Pick a template that matches the prospect’s environment, or create a custom version where needed.

  • Send at the right time
    Timing affects engagement. Send during working hours, when users are more likely to open and interact with messages.

Keep the goal in mind

The purpose of the phishing simulation is not just to generate clicks. It is to create a more credible picture of human risk so the prospect understands why action is needed.

Did this answer your question?