operations · simulations

Why we script phishing drills like rehearsal notes

By Leah Ortega ·

Hero artwork for Why we script phishing drills like rehearsal notes

Operations leaders often ask for phishing drills that feel fair. We start from the same premise as a fire drill: announce the format, publish the window, and debrief immediately.

The second paragraph focuses on language. Blame-heavy copy tanks participation. We swap scoreboards for qualitative notes tied to specific training modules.

The third paragraph covers measurement. Completion rates matter less than whether teams report faster. We track time-to-report and qualitative tags instead of leaderboards.

Finally, we remind admins that simulations should never mirror active incidents. Clear separation keeps trust intact while still exercising muscle memory.

Back to field notes