Phishing Simulation for SMEs, Setup, KPIs, Reporting
Introduction
Phishing simulations are the most effective tool to measure and improve workforce phishing resilience systematically. For Swiss SMEs, companies with 10 to 250 staff, which is the BFS micro, small and mid-sized enterprise segment, the question is often: how do we start without disrupting operations, antagonising staff representatives, or running a tool monster? This article delivers a pragmatic setup that is productive within 30 days and shows measurable effects after 6 months.
This article covers:
- Legal and staff-representation aspects of phishing simulations in Switzerland.
- Tool selection for SMEs: build vs buy, dominant vendors.
- Campaign cadence, lure types, difficulty levels.
- Just-in-time training and repeat-clicker coaching.
- KPI set and quarterly reporting to the management body.
Normative anchors are ISO/IEC 27001:2022 Annex A.6.3 (awareness), ISO/IEC 27002:2022 clause 6.3, NIST SP 800-50r1, Art. 8 DSG (data security), Art. 32 GDPR (technical and organisational measures), Art. 21(2)(g) NIS2, and BACS / NCSC SME cybersecurity recommendations. The recommendations are based on real roll-outs at Swiss SMEs over the past three years.
Legal and HR aspects
Phishing simulations process employee data and intervene materially in the employment relationship. Items to settle before programme start:
- Data protection: click data, reporting data and learning-progress data are personal data. There must be a legal basis (typically Art. 6(1)(f) DSG, legitimate interest of the employer in security), employee information, and a processor agreement under Art. 9 DSG with the tool vendor.
- Employment law: phishing simulations are not "employee surveillance" in the sense of Art. 26 ArGV 3, provided evaluation is aggregated and does not feed personalised disciplinary measures. A "Wall of Shame" or disciplinary measures for individual clicks are problematic and counterproductive.
- Staff representation: at firms with staff representation (especially from 50 FTE): early engagement and written agreement on purpose, processing, evaluation level and consequences for staff.
- Workforce information: communicate once before programme start that a phishing-awareness programme with simulations is in place. Timing and content of individual campaigns remain confidential (otherwise there is no test value).
- Tone: clear message: "Those who click are not punished. We want to learn how to protect each other better."
A one-page "phishing simulation policy," signed by HR and the security owner, creates transparency and reduces downstream friction sharply.
Tool selection for SMEs
For an SME with 30-250 staff a dedicated SaaS tool is almost always the right call. Build vs buy: building one's own (GoPhish, Phishious etc.) is technically feasible, but usually fails on maintenance, tracking quality and content update cadence. Market options for SMEs:
- KnowBe4: SME-suitable with the "Diamond" or "Platinum" tier. Very broad lure library, good DE/FR/IT localisation. Price indication: CHF 25-45 per user per year.
- SoSafe: very SME-friendly, DACH vendor from Cologne, fast onboarding (productive in 1-2 weeks), strong reporting. Price indication: CHF 30-50 per user.
- Hoxhunt: gamified approach, high employee acceptance, continuous micro-trainings. Price indication: CHF 35-55 per user, often slightly higher.
- G DATA Security Awareness: German vendor, SME-suitable, strong German-language content. Price indication: CHF 20-40 per user.
- Lucy Security: Swiss vendor based in Zug, strongly SME-oriented. Preferred by Swiss SMEs wanting Swiss data residency and Swiss support.
Selection criteria for SMEs: fast onboarding, DE/FR/IT content, simple admin UI, phish-report button for Outlook and/or Gmail, just-in-time training, clear reporting. Tooling investment for a 100-FTE SME is typically CHF 3,000-6,000 per year for the platform plus around 0.1-0.2 FTE for operations.
Campaign cadence and lure types
A proven annual plan for an SME:
- Month 1, Baseline campaign: generic, easily recognisable phishing email (e.g. "Your password is expiring"). Captures the baseline click and report rates before training has kicked in.
- Month 2, Brand spoofing: lure imitates a well-known Swiss brand (Swiss Post, Swisscom, SBB). Medium difficulty.
- Month 3, Internal spoofing: lure imitates an internal sender (CEO, IT helpdesk, HR). Elevated difficulty, simulates CEO-fraud scenario.
- Month 4, Topical seasonality: lure with current relevance (taxes, salary statement, Christmas, summer holidays).
- Month 5, Spear-phishing light: personalised lure with first names, department references. High difficulty.
- Month 6, Multi-channel: phishing email plus simulated SMS or LinkedIn contact (smishing, social pretexts).
- Months 7-12: repetition with adjusted difficulty and new themes.
Difficulty should rise over time, otherwise staff get used to easy lures and then fall to real sophisticated attacks. Starting with "You have won CHF 50,000" and staying there teaches nothing relevant. Realistic lures, AI-generated, well-written German emails with correct logo layout and HTTPS lure pages, are the norm in 2025.
Just-in-time training and repeat clickers
Someone who clicks a simulation should not receive a generic e-learning days later, but an immediate short explanation of what would have given the lure away. Effectiveness of just-in-time training (JIT): 3-5x higher than delayed training, because the learning context is directly connected.
Practical JIT setup:
- Clicking the lure link leads to a short learning unit (60-90 seconds) with the three key warning signs of the specific lure.
- Quiz question to consolidate.
- "Understood" confirmation and return to inbox.
- No personalised public callout.
Repeat-clicker coaching: someone clicking in two of three consecutive campaigns receives an additional longer training module (10-15 min). Someone clicking in four of six receives a personal coaching conversation with the security owner, not disciplinary but supportive ("What makes these lures particularly attractive to you? What help do you need?"). Experience shows 80-90% of repeat clickers respond positively to such coaching because they are frustrated themselves. Disciplinary escalation remains the absolute exception (e.g. an employee with 100% click-rate over 12 months who refuses coaching).
Click-rate and report-rate as KPI pair
The most important KPI pair in phishing simulations is click-rate vs report-rate. Both are measured as percentages of recipients:
- Click-rate (lower = better): share clicking the lure link. Swiss SME baseline: 12-25% in month 1. After 6 months of programme: 4-10%. After 12 months: 2-6%.
- Report-rate (higher = better): share reporting the email via the phish-report button. Baseline: 2-8%. After 6 months: 15-30%. After 12 months: 30-50%.
Secondary KPIs complement the picture:
- Time-to-report (median): median time from email receipt to report click. Target: under 30 min after 12 months.
- Credential-submission rate: share who, after clicking, also submit credentials. Should sit materially below click-rate (awareness that login pages should be inspected).
- Repeat-clicker share: share clicking in several consecutive campaigns. Target: under 5%.
- Training completion rate: share completing assigned modules. Target: above 95% within 30 days.
Industry benchmarks (Industry Phishing Benchmarks 2024-2025): financial-services firms typically achieve the lowest click rates (3-7%), hospitality and retail the highest (15-25%). Swiss SMEs tend to land about 2-3 percentage points below the international median, helped by higher education levels and smaller structures.
Quarterly reporting to the management body
Reporting must let the management body understand within five minutes what is happening and what to do. Recommended structure:
- KPI dashboard (1 slide): click rate, report rate, time-to-report and completion rate current quarter vs prior quarter and vs annual plan.
- Trend (1 slide): 12-month trend line for the two main KPIs.
- Campaign highlights (1 slide): which lures worked best (highest click rate)? What were the learnings?
- Real incidents (1 slide): were real phishing emails reported via the phish-report button this quarter? Which threat patterns?
- Risk translation and roadmap (1 slide): what does this mean for our business risk? Planned adjustments, new themes.
Important: no slides with Wall-of-Shame data (e.g. "Marketing clicks most"), because that drives the management body discussion in the wrong direction. Where department data is shown, frame it as "differential coaching need," not blame.
For regulated industries (financial services under FINMA supervision) phishing reporting becomes part of operational risk reporting under FINMA Circular 23/01 and ties into SOC reporting. For DORA-obliged entities, KPI documentation is part of the resilience-testing programme under DORA Art. 24-25.
How SIDD supports you
SIDD supports Swiss SMEs in building and running phishing-simulation programmes. We start with a two-hour scoping call, clarify legal prerequisites (data protection, staff representation), select the right tool with you (KnowBe4, SoSafe, Hoxhunt, Lucy or G DATA), and design the 12-month campaign plan with rising difficulty and Swiss-relevant lures.
For the initial phase we take over the set-up, technical onboarding (DNS whitelisting, phish-report-button roll-out, auto-provisioning via Entra ID or Google Workspace), build of the first three campaigns and training of your internal programme manager. On request we run the programme on a managed-service basis with quarterly reports to your management body.
Phishing simulations are one building block of a broader awareness programme, see our article on security awareness training. For integrated cybersecurity workshops on site, see IT security workshop for SMEs. Arrange a non-binding first conversation at /kontakt or request a fixed-price quote for a 12-month programme at /offerte. Typical entry for a 100-FTE SME: set-up CHF 4,500, monthly managed service CHF 800-1,200, plus tooling, total annual budget around CHF 18,000-25,000.
