Step-by-step guide to launching a campaign
This article provides a step-by-step overview of the procedures for launching a phishing simulation campaign.
For the first campaign, it's important to know that the phishing simulation campaign is generated automatically the day after at least one Cyber Guru Phishing license is assigned.
Campaigns are identified sequentially: the first will be “Campaign: C-01”.
All campaigns after the first one become available only after more than 50% of the campaign duration has passed.
Steps to launch a simulation campaign
Go to the “Release Management” section and select the campaign you want to work on.
Review the templates suggested by the platform: select the ones you want or, if needed, recreate the campaign to get new templates.
Run a campaign test.
Check the test results.
Set the launch parameters (duration, dates, and send time).
Check the potential targets and make sure they match the assigned phishing licenses.
If everything looks good, approve the campaign.
Go to the Release Management section of the platform and find the campaign you want to work on.
The campaign will be visible with the status “To be approved”.
2. Review the templates suggested by the platform
Templates are automatically selected by the platform. It's recommended not to make changes, so the Machine Learning can work at its best, optimizing template selection over time based on user behavior.
Previewing a single template
To view a preview of a template, click the eye icon in the “Actions” column of the campaign.
The template list shows the test status of each template
✅ green: template successfully tested (all languages, no changes made after)
⚠️ yellow: template was modified but not retested
❌ red: test failed for all languages
If you have questions about a template's status, contact your CSM.
Disabling and/or re-enabling a template
You can disable a template by removing the checkmark in the “Status” column. This way, the template won't be sent to users during the campaign, but it can be re-enabled at any time.
Red alert preventing approval
If you disable too many templates, the platform will show a red alert indicating that the number of active templates is too low and the campaign cannot be approved.
To change the required minimum threshold, go to:
Company Management → Setup → Phishing → Minimum templates to include.
Black warning alert
If the campaign targets are spread across multiple countries, the system will automatically suggest a set of templates designed to cover all localizations.
If you disable too many templates, a black warning may appear (which does not block approval) indicating that, for some countries, the number of templates has dropped below the minimum threshold for that country. This does not necessarily mean there are no templates available for that country, just that the number is below the configured threshold.
In these cases, it's a good idea to:
check, for the country mentioned in the warning, that there is at least one template available in the required language/country;
keep in mind that there are also “all country” templates, valid for all countries, which can help provide coverage even when localized templates are limited.
Recreate a template or the entire campaign
To replace disabled templates, you can use the “Recreate” function, which allows the platform to suggest new templates to replace the ones you disabled.
How to do it: disable the templates you want to replace and click “Recreate” (top right).
Result: the platform will suggest new templates to replace the ones you disabled, keeping the other templates unchanged and active.
Recreate the entire campaign
How to do it: disable all active templates and click “Recreate”.
Result: a new campaign will be created with a set of new templates.
Important note
If a template was previously disabled and the campaign is recreated, that template will not be suggested again, as the platform interprets the disabling as a clear choice not to use it anymore.
To test a single template before officially sending it, open the preview using the eye icon and click on “Test template”. Enter the test recipient’s name and email to check the content and appearance of the message without involving the entire campaign.
If a template is available in multiple languages, you need to select the language you want to receive it in first, and only then proceed with the “Test template” action, so you can properly check the selected language version.
Testing the entire campaign
The entire campaign test is the fastest way, because it lets you send all “active” templates in the campaign in a single operation.
When testing, you can freely choose the recipients: they don’t have to be platform users or have a phishing license assigned. This allows you to run internal checks (content, layout, language, simulated sender, etc.) without involving the real campaign targets.
- Click on “Run Test”
- Enter one or more recipients (each name will be shown in the interface and can be edited or removed at any time)
- Specify the language (if templates are available in multiple languages, the platform will send the templates in the selected language, allowing you to properly check content and formatting for each localization).
4. Check the results of the campaign test
Once you’ve run the campaign test, you need to make sure that
you receive all the (active) templates expected in the test;
the templates display correctly (layout, images, text, language);
clicking the links takes you to the correct landing page.
Check interaction tracking for your first campaign
If this is your first campaign, you need to run a test to make sure interactions are being tracked correctly.
In the “Statistics > Phishing Report” section, by selecting “Test Campaigns Events” (visible to company admin or higher roles), you can download the file related to the test you ran.
If you’ve run multiple tests at different times, there will be multiple files available, one for each test. Test files are kept for about 7 days, after which they’ll no longer be available for download.
In the file, you can see which emails were sent and to which users, with all the details for each template (for example, subject, simulated sender, and language). For each recipient, all interactions (open, click, reporting the email as suspicious) are recorded.
⚠️ It’s important to note that interactions recorded during campaign tests are not counted in real statistics.
5. Set campaign start parameters
After selecting the templates and running all necessary tests, you can set up the campaign start parameters:
Start date: this is the date when template sending will begin.
Send time: starting from the specified time on the selected date, the platform will begin sending.
Campaign duration: indicates how many days the platform should track user interactions with the received templates. Example: P30D means that for 30 days from the start of the campaign, interactions with the templates will be recorded.
-
Send duration: indicates over how many days the email sending should be spread. The value set must be less than the total campaign duration.
Rules and restrictions
You cannot set the start date to today or a date in the past.
It’s recommended to make all changes to the duration before approving the campaign.
6. Check Potential Targets and Template Coverage
Potential Targets
You need to check the “Potential Targets” field and make sure the number matches the total number of users who have been assigned a Cyber Guru Phishing license: potential targets are the users eligible to receive the campaign templates.
Note: It’s essential to assign users a Cyber Guru Phishing license so they’re included as potential targets. A user without a license will never be considered a target and won’t receive any simulation templates.
Recipient List
The quality of your recipient list directly affects the reputation of your sending domain and, as a result, the reliability of your simulation deliveries. Sending to invalid or inactive addresses is one of the strongest signals of reputational decline to email providers (e.g., Microsoft), and can cause delays in campaign delivery regardless of your technical setup.
.Recommendations:
- Remove inactive users before each campaign
- Avoid using lists exported a long time ago
- Regularly check the validity of uploaded addresses
Template Coverage
In addition to checking the number of potential targets, you can also see how many of them will actually receive a template during the campaign. This is called Current Coverage.
Coverage takes into account several factors that may reduce the number of users actually reached compared to the potential targets, including:
- the availability of templates compatible with each user’s country;
- the history of previous campaigns: the platform avoids sending a user a template they’ve already received in the past;
- whether or not a phone number is present in the user profile, in the case of SMS templates.
How to Check Coverage
To view current coverage, from the campaign detail screen (when the status is "To be approved"):
- Click the actions menu icon (⋮) at the top right of the campaign screen.
- Select "Current Coverage".
The platform will run a template assignment simulation and, after a few moments, will show the count "Current Coverage: N", where N is the number of users who would receive a template if the campaign were approved at that moment.
Note: this operation is a simulation for informational purposes and does not change the campaign in any way. Templates will only be actually assigned to users when the campaign is approved.
How to Interpret the Result
- Coverage equals potential targets: all users with a phishing license will receive a template. This is the ideal situation.
- Coverage is less than potential targets: some users won’t receive a template in this campaign. This can happen, for example, because all available templates have already been sent to those users in previous campaigns, or because there are no templates compatible with their country or language. In these cases, it’s a good idea to review your active template selection or contact your CSM for a more in-depth analysis.
⚠️ Important: the "Current Coverage" feature is available only for campaigns in the "To be approved" status. Once the campaign is approved, the button will no longer be visible.
7. Approve the Campaign
Once you’ve completed all the preliminary steps to launch the campaign (choosing templates, testing, setting the duration), you can approve it using the dedicated button.
Canceling Approval
The campaign moves from "To be approved" to "Approved" immediately. As long as the campaign hasn’t become "Active," you can still make changes to templates or targets, for example, and these will be applied accordingly (no need to revoke approval). However, to change the duration, you do need to disapprove the campaign.
Once the campaign status changes to "Active," you can no longer make any changes or cancel approval.
The only option will be to "Suspend" the campaign (the button will appear even if the sends haven’t started yet). If you need to make changes before the campaign starts sending, we recommend suspending the campaign and contacting Cyber Guru support.
The moment the campaign becomes active depends on two possible scenarios:
Case 1 – There’s already an active campaign
- After you approve it, the new campaign stays in "Approved" status and becomes "Active" on the first available day after the previous campaign ends.
Before it becomes "Active," you can:
- cancel approval;
- change its duration/template settings;
- update target data;
Case 2 – There’s no active campaign
- After you "Approve" it, the campaign becomes "Active" starting at midnight (about 12:00 AM) on the same day you approved it;
- The time between approval and midnight of the same day is the only window when you can cancel approval and change the duration/template and/or target settings
In any case, emails will only start sending on the date set during approval.