What happens between signing and the first campaign

Cocina profesional preparada minutos antes del servicio, con las bandejas de ingredientes alineadas sobre la mesa de acero y el pase vacío al fondo, sin nadie cocinando todavía

What happens between signing and the first campaign

What happens between signing and the first campaign

The contract is signed and platform access is handed over that same day. The first campaign, though, takes a while to go out.

That stretch between signing and the first campaign going out is where much of what follows gets decided, and it usually sits outside anyone’s plan. The standard, by contrast, treats it as formal work. Revision 1 of NIST SP 800-50, Building a Cybersecurity and Privacy Learning Program, published in September 2024, organizes the program along the five phases of the ADDIE model (analysis, design, development, implementation and evaluation). The first two finish before a single piece of content reaches anyone.

At SMARTFENSE we see that stretch every week, across rollouts in organizations of very different sizes. The time between signing and the first send almost never depends on the platform. It depends on decisions only the organization doing the contracting can make.

How long does it actually take to launch a security awareness program?

It comes down to those decisions, not to the technical rollout.

Creating the environment, loading the content catalog and getting the platform running is a matter of hours. What stretches the calendar is everything else. Who joins the program, with what data, cleared by whom, and under what internal message.

A team that arrives with a clean people list, sponsorship settled and IT signed off can start within days. When those three factors get sorted out after signing, the launch turns into a project with a calendar of its own. What separates one case from the other is not the software.

What does the vendor handle, and what can only your organization handle?

The split is sharper than it looks, and it is worth putting in writing before the kickoff meeting.

The vendor handles Only your organization handles
Environment, content catalog and platform configuration Who belongs in the program and how they are grouped
Simulation templates, reports and automations The quality and upkeep of the people directory
Technical deliverability documentation Applying that configuration to your mail and your network
Onboarding, admin training and support Internal sponsorship and the message that announces it
Calendar and frequency best practices The dates your organization can actually sustain

The practical reading of that table is that the right-hand column cannot be delegated. A vendor can advise, document and support. It cannot decide who joins the program, nor secure leadership backing on your behalf.

Why is the user list the most common bottleneck?

Because it is the one input nobody but the organization can produce, and it is almost always in worse shape than assumed.

NIST places this task as the second step of the analysis phase, ahead of any content: identify the learning program audience. In practice, that identification surfaces things that were hidden. People who left the organization and are still in the directory. Mailboxes shared by an entire department. Contractors nobody is sure should receive training. Sites with an empty country field, which later make it impossible to segment by language, for instance.

None of that is a platform problem, yet all of it lands on the platform. If the directory comes in dirty, the first reports will describe a data problem instead of a behavior problem, which is exactly what the program set out to measure.

It is worth solving before the first send rather than after. Defining the audience of an awareness program with real criteria, even if it costs two weeks, saves a year of metrics that cannot be defended.

What has to be closed with IT before the first simulation?

Three things, and all three live outside the awareness platform.

  1. Deliverability. Simulation emails have to reach the inbox. That requires the team running the mail server to authorize the program’s sends and exclude them from filtering, with the scope agreed in writing.
  2. Web access. Simulation landing pages have to open from the corporate network. If the web filter blocks them, the simulation measures the proxy configuration instead of how people react.
  3. Sending domain. It pays to decide early which domain the program’s notifications go out under, because it shapes how much the target audience trusts them. We covered it in why a dedicated domain drives program adoption.

These three tasks tend to be short for IT and slow to schedule. That is the real reason they become the most expensive blocker of the launch: not difficulty, but sitting in another team’s queue behind its own priorities.

Orchestra musicians tuning their instruments to the note the oboe sets, before the audience is let into the hall

Who has to agree before the first email goes out?

More people than usually show up at the kickoff meeting.

Security drives the program but rarely controls the channels it travels through. HR has a say over any activity that is mandatory for staff. Internal communications decides how it is announced. In some organizations, employee representatives have to be informed before a simulation runs, and in several countries that step is not optional.

None of those conversations is long if it starts early. All of them get long once the first campaign is already scheduled. When a program launches without internal agreement, the first incident is not technical. It is a complaint that reaches leadership and stalls the entire calendar.

That is why the sponsor matters so much. They do not have to come from the security team. They have to carry enough authority to get those three areas in the same room and leave with a decision.

Is it better to open with training or with a simulation?

With training, unless you have a concrete reason to do otherwise.

A simulation as first contact arrives before anyone knows a program exists. It measures well, because it captures an unbiased baseline, but it leaves people feeling tested without notice. That opening is expensive in trust, and trust is what carries the program through the rest of the year.

Opening with training content, announced by the sponsor, sets expectations straight. People know a program is coming, what it is for and what is expected of them. The simulation follows on prepared ground, and its results read without noise.

There is one reasonable exception. When leadership asks for an initial measurement to justify the investment, the baseline has to be taken before any training, because afterwards it is no longer a baseline. In that case it pays to agree in advance what will and will not be done with the results, something we work through in is your awareness program measuring what matters.

The launch is part of the program too

The weeks before the first send are not dead time spent waiting for the program to start. They are the program’s first phase, and NIST treats them as such.

When that phase is done well, the rest of the year resembles the plan. Segmentation works, reports read without caveats, and the campaign calendar holds without monthly renegotiation. When it is skipped, it comes back later as data nobody defends and campaigns that keep slipping.

If you are about to start, the useful conversation is not about the platform. It is about the directory, the sponsorship and IT’s schedule. Once that is settled, the rest is a matter of days.

Frequently asked questions

How long does it take from contracting an awareness platform to sending the first campaign?
It depends on how many internal decisions are already made at signing. The technical rollout takes hours. What sets the timeline is having a clean people list, a sponsor with authority, and deliverability tasks booked with IT.

What is the analysis phase of an awareness program?
It is the first of the five ADDIE phases that NIST SP 800-50 Rev. 1 applies to these programs. It covers identifying learning needs, defining the audience, matching the two, assessing current knowledge levels and determining the gaps. It finishes before the content is deployed.

Why does the initial user upload fail?
Because the corporate directory is rarely built for segmenting training. It usually holds people who have left, shared mailboxes, contractors with no defined criteria, and empty fields that make it impossible to group by site or language.

What does IT need to configure before a phishing simulation?
Authorize the program’s sends so they reach the inbox, allow navigation to the landing pages from the corporate network, and agree on the domain the communications go out under.

Is it better to start with a simulation or with training?
With training in most cases, because it sets expectations before any evaluation. A simulation as the starting point only makes sense when an unbiased baseline is needed, and it is worth agreeing up front how the results will be used.

Leonardo Bally

COO (Chief Operating Officer) de SMARTFENSE. Lidera y supervisa las operaciones diarias de los equipos de soporte técnico, implementación y formación técnica/comercial. Cuenta con más de 15 años de experiencia en el sector IT y en el desarrollo de equipos con formación técnica y analítica.

Leave a Reply