Create a Sophos Phish Threat campaign
A Sophos Phish Threat campaign combines a clear learning objective with a simulated attack template or training-only content, defined recipients, and a limited evaluation period. The safe sequence is: define the objective, choose the campaign type and language, configure the attack and training—or training only, depending on the type—review the templates, select pilot recipients, send a test, and only then save the production schedule.
This guide covers a single campaign. Automatic enrollment of users created in Sophos Fusion (formerly Sophos Central) in the future and recurring workflows are covered in Create Phish Threat campaign series and are deliberately not enabled here.
Prerequisites
The license, administrative access, verified recipient domains, and delivery path must be set up in advance. Sophos Phish Threat: Getting started describes the necessary handoffs. Successful domain verification does not prove that delivery works, so use a controlled test mailbox first.
Optionally, start campaign creation from My Products > Email Security > Dashboard > At Risk Users > Train these users with Phish Threat. Risk signals are only a prioritization aid. You must still review the prepopulated target group, campaign purpose, and organizational approval. Restrict the risk list to responsible personnel and do not treat it as evidence of individual misconduct.
Prepare the campaign
Record the following decisions before the first click:
- Objective: Do you want to establish a baseline, test a particular attack pattern, or provide mandatory training?
- Pilot group: For the first run, use a small, representative group of users with accessible mailboxes.
- Measurement criterion: For example, click rate, entry of simulated credentials, opening an attachment, or completion of training.
- Period: Define the start, end, and sufficient time for training reminders.
- Communication: Inform the help desk, data protection team, and responsible administrators about the approved test without disclosing the specific scenario to recipients in advance. Limit recipient and result data to the approved purpose and the personnel who need it.
Recipient domains must be verified in Sophos Fusion. Phish Threat sends simulated phishing emails only to addresses in your own verified domains. For an Enterprise account, add and verify the domains in every sub-estate.
1. Choose the campaign name, type, and language
- In Sophos Fusion, go to My Products > Phish Threat > Campaigns.
- Select New Campaign and enter a unique name, for example
2026-Q4-Finance-Invoice-Pilot. - Select the campaign type that matches the objective:
- Phishing records users who follow a link in the simulated message.
- Credential Harvesting opens a simulated sign-in page. A user is recorded as caught when they enter credentials there; passwords are not collected. Never enter real credentials, even in a controlled test.
- Attachment records the relevant interaction with a simulated malicious attachment.
- Training provides anti-phishing training without a simulated attack.
- Choose the language for email templates and training modules.
- Select Next.
The language is set at campaign level. For target groups that speak different languages, separate campaigns are generally clearer than a template containing multiple languages.
2. Select up to five attacks for an attack campaign
This step applies to Phishing, Credential Harvesting, and Attachment. Under Choose Attack, filter templates by difficulty or attack type. Select Choose this attack for the required template. One campaign can contain up to five attacks; then select Next.
More templates are not automatically better. One attack is often enough for a pilot that can be evaluated clearly. Multiple attacks are useful when you deliberately want to compare different scenarios within the same target group. The sender, links, landing pages, and language of every selected attack must match the campaign objective.
A training-only campaign omits Choose Attack entirely. It contains no simulated attack; training content is selected immediately after the campaign type.
3. Configure training and reminders
Path A: Phishing, Credential Harvesting, or Attachment campaign
Under Choose Training, three options are available:
- Phish Threat training: Sophos provides the selected training content. Sophos recommends this option.
- Use my own training: Affected users first reach the Sophos - Security awareness training page and select Go to Training to open your self-hosted content.
- No training: After selecting a link, users see a simulated
404 Not Foundpage; no training is provided.
In an attack campaign, users are automatically enrolled in the selected courses when they fall for the simulated attack. For Phishing, they do not receive a separate initial training registration: interacting with the link triggers enrollment. They can then open the training from the original message or a training reminder.
For an Attachment campaign, the trigger depends on the interaction:
- On Windows, saving, opening, and editing the attachment trigger training enrollment.
- On macOS and in a web browser, saving and opening trigger training enrollment.
- Previewing the attachment alone does not trigger training enrollment.
Then:
- Select the training course for users who fail the simulated attack. You can filter the list by HTML or Video.
- Define the number and frequency of training reminders. The interval must fit within the planned campaign period.
- Select Next.
Path B: training-only campaign
For a Training campaign, select the training modules directly and then select Next. There is no attack template or enrollment trigger based on failing a simulated attack. The selected participants are enrolled in training and receive a registration email with access to the training when the campaign starts.
Configure training reminders to fit the campaign period. Unlike an attack campaign, this training path starts with the registration email rather than with a user’s interaction with a simulated attack.
Do not confuse training reminders to participants with Campaign Reminders. The latter are configured under Global Settings > Products and Services > Sophos Phish Threat > Campaign Reminders and remind selected administrators seven days before the campaign starts.
4. Customize templates and note account-wide effects
Under Customize, select Edit for an item. Depending on the attack type and training, you can edit the following components:
- Attack Email for all attack types;
- Attack Landing after the phishing link is selected;
- Custom Attachment for applicable attachment scenarios;
- Reminder Email for upcoming training or events;
- Caught Landing for users who fail the test;
- Training Landing for users automatically enrolled in training.
Attack components apply only to Phishing, Credential Harvesting, and Attachment. For a training-only campaign, review the registration email for direct access to training instead; this path has no Attack Email or Attack Landing.
In the attack email, you can edit the sender name, sender address, subject, and message body. For HTML changes, use Tools > Source code. Images must be uploaded as PNG files, and each template must not exceed 4 MB.
Important: Changes to Reminder Email, Caught Landing, and Training Landing become the default templates for all current and future campaigns in the account. Before saving, confirm that the change should apply account-wide. Use Restore to Product Default to restore the relevant product default.
Always use Save for the currently open landing page first. Only then can you edit the next landing page. With multiple attacks, Next remains disabled until all changes are saved.
Personalization, preview, and test
Use personalization fields only when the required user data is maintained in Sophos Fusion. Check {FirstName} and {LastName} in the test email in particular. For users synchronized through Active Directory, Central imports Display Name and splits it for these two variables. Therefore, maintain Display Name in the format Vorname Nachname. If that is not possible in the directory source, import users by CSV with correctly formatted names or remove the variables from the template. Then send another test email.
Preview every modified email and landing page. Then use the test function to send a test email to a controlled internal mailbox. Check:
- the visible sender name, sender address, and subject;
- resolution of all personalization fields;
- rendering on desktop and mobile devices;
- the link destination, landing page, and redirection to training;
- delivery to the inbox, junk folder, or quarantine.
A successful preview confirms only the rendering. The received test email also confirms the mail flow. Open test links only in the approved pilot mailbox so unintended interactions do not distort the subsequent evaluation.
After the test, select Save, followed by Next.
5. Enroll users and groups
Under Enroll Users, select the intended Users or Groups. For the first run, this should be the prepared pilot group.
- Sophos displays a warning for individual users with an unverified email domain and does not enroll them.
- If a group contains addresses from verified and unverified domains, Sophos enrolls only addresses from verified domains and displays a warning.
- Use Verify domains to start domain verification. Then return to Phish Threat and continue creating the campaign.
Leave Auto-enroll new users to this campaign disabled for this workflow. In a standalone campaign, users newly added to the Central account would be enrolled immediately and receive the first campaign email 24 hours later. The campaign would also remain active until ended manually. That differs from the fixed campaign period planned here and does not replace the deliberately reviewed recipient list for this run.
Select Next to go to Review and Schedule.
6. Review, schedule, and set the pass mark
Under Review and Schedule, review all the information entered so far. The schedule has two options:
- Launch at scheduled time: Set Start Date and End Date. A scheduled start must be at least one hour in the future and can only occur on the hour. The first emails begin sending at the start time.
- Launch immediately: The campaign is activated upon completion; an End Date is still required. Do not use this option until recipients, the template, and test delivery have received final approval.
After End Date, Sophos records no new campaign data and sends no further campaign or reminder emails. User actions after this date do not appear in campaign results. The end date must therefore fall after the last planned send and the scheduled training reminders.
Under Sending Increment, distribute messages in stages. Specify the percentage of recipients per stage and the interval between stages. The percentage can be reduced to 5 %. Sophos estimates how many days the full delivery will take. The estimated final delivery must occur before End Date.
Next, set the pass mark for each selected training module. The default for each training is 80 %; this mark assesses completion of the relevant training, not whether users passed the simulated phishing test. If you selected multiple training modules, select Next and set the score for each module separately. Align the marks with the campaign objective before launch; do not change them afterwards merely to obtain a preferred result.
Finally, select Done. This saves the configuration and activates or schedules it according to the selected launch option. Before this step, compare the campaign name, recipient count, launch method, and time zone with the approval once more.
Limit errors after saving
If you discover an error after selecting Done, immediately open the campaign under My Products > Phish Threat > Campaigns and select Pause. Emails already sent cannot be recalled. For staged delivery, pausing prevents only the remaining emails that have not yet been scheduled from being sent; first determine which recipients have already been contacted.
Use Edit to modify the remaining workflow of a paused campaign. The campaign type and Start Date cannot be changed, and recipients who have already been sent the campaign email cannot be removed. After making the correction, check the recipients, content, End Date, and remaining delivery before selecting Resume. A campaign that has already ended cannot be extended or edited; create a new campaign instead. Manage Phish Threat campaigns describes the complete lifecycle.
Validate the campaign
After selecting Done, do not rely solely on a confirmation message. Open the new entry under My Products > Phish Threat > Campaigns and verify the following:
- The campaign name, type, and language are correct; for an attack campaign, the number of attacks is also correct.
- The training, reminder interval, and pass mark match the approval.
- Only the expected users or groups are enrolled, and warnings about unverified domains have been resolved.
- The start date, end date, and time zone are correct.
- For Sending Increment, the percentage, interval, and estimated delivery duration fit within End Date.
- The status matches the selected launch: scheduled for a future date or started for an immediate launch.
- The controlled test mailbox received the test email, and the link, landing page, and training appeared as intended.
If a recipient is unexpectedly omitted, first check domain verification, the user’s email address, and group membership, then continue with Troubleshoot Phish Threat delivery errors. If {FirstName} or {LastName} is resolved incorrectly in a personalized test email, correct Display Name to the format Vorname Nachname for AD-synchronized users, or use a correctly formatted CSV import and test again. Use the campaign for the production target group only after the recipient list, test delivery, and time window are correct.