Phishing Simulation
Test your organization's resilience to phishing attacks with realistic simulation campaigns that measure awareness and improve security behavior.
Phishing Simulation Featuresβ
Email Templatesβ
Pre-built phishing scenarios:
- Generic phishing
- Brand impersonation
- Urgent action requests
- Prize/reward scams
- Invoice/payment requests
Custom Templatesβ
Create your own:
- Custom email content
- Branded templates
- Targeted scenarios
- Multi-language support
Landing Pagesβ
Simulated phishing destinations:
- Credential harvesting pages
- Download pages
- Survey forms
- Branded login pages
Tracking Capabilitiesβ
Measure user behavior:
- Email opened
- Link clicked
- Credentials entered
- Attachments opened
- Report to security
Running Phishing Campaignsβ
Creating a Campaignβ
- Navigate to Attack Simulation β Phishing
- Click New Campaign
- Configure campaign:
- Name and description
- Template selection
- Target audience
- Schedule
- Review and launch
Selecting Targetsβ
Target Optionsβ
- All users
- Specific departments
- Random sampling
- Custom groups
- Exclude VIPs
Target Considerationsβ
- Representative sample
- Various departments
- Different risk levels
- Repeat testing
Campaign Configurationβ
Timingβ
- Send all at once
- Staggered delivery
- Time zone consideration
- Business hours only
Durationβ
- Campaign length
- Tracking period
- Follow-up timing
Campaign Typesβ
Awareness Testingβ
Measure baseline awareness:
- General phishing attempt
- Measure click rates
- Track credential submission
- Identify training needs
Spear Phishingβ
Targeted attacks:
- Personalized content
- Role-specific scenarios
- Executive targeting
- Custom pretexts
Credential Harvestingβ
Test credential protection:
- Fake login pages
- SSO impersonation
- Password capture
- MFA bypass attempts
Payload Deliveryβ
Test endpoint protection:
- Simulated attachments
- Macro-enabled documents
- Executable links
- Download tracking
Results and Metricsβ
Campaign Dashboardβ
- Emails sent
- Emails opened
- Links clicked
- Credentials captured
- Reports to security
User-Level Resultsβ
For each participant:
- Actions taken
- Time to action
- Previous history
- Risk score
Department Analysisβ
Compare across groups:
- Click rates by department
- Credential submission rates
- Reporting rates
- Improvement trends
Trend Analysisβ
Track over time:
- Campaign comparison
- Improvement metrics
- Seasonal patterns
- Training effectiveness
Training Integrationβ
Just-in-Time Trainingβ
When users click:
- Immediate education
- What they missed
- Correct behavior
- Report mechanism
Follow-up Trainingβ
Based on results:
- Targeted training assignments
- Risk-based curriculum
- Progress tracking
- Certification
Positive Reinforcementβ
Recognize good behavior:
- Acknowledge reporting
- Security champions
- Team recognition
- Gamification
Reportingβ
Executive Reportsβ
- Campaign summary
- Risk assessment
- Comparison to industry
- Recommendations
Technical Reportsβ
- Detailed metrics
- User-level data
- Trend analysis
- Training recommendations
Compliance Reportsβ
- Testing evidence
- Awareness metrics
- Training completion
- Audit support
Best Practicesβ
- Regular campaigns - Test frequently
- Vary scenarios - Different phishing types
- Educate, don't punish - Focus on learning
- Measure improvement - Track progress
- Recognize reporters - Encourage reporting
- Use real examples - Relevant scenarios
Related: