166 terms · 75/46/45
Defense № 038 · class: people

Phishing Simulations

Regular testing of employees with simulated phishing messages.

Term

description · examples · notes

Regular testing of employees with simulated phishing messages.

Description

Measures click rates, reporting rates, and credential submissions by department.

Results are used for targeted additional training.

Simulations gradually increase in complexity — from generic to targeted.

Tools: KnowBe4, Proofpoint, GoPhish (open-source).

What people often say

  • The goal is not punishing employees — it is measuring and improving.
  • Simulations without follow-up training have limited effect.

Covers / does not cover

Covers

  • Testing employee resistance to phishing
  • Measuring improvement over time
  • Identifying most vulnerable groups

Does not cover

  • Technical email filtering (that is email-security)
  • Protection from phishing that bypasses employees
  • Testing technical infrastructure
Composite

Threats

reduces 6

Techniques

neutralizes 2

Techniques it neutralizes. Select one to open its page.