Here's how to run a simulated phishing campaign to test and train your employees before they receive an actual phishing email.
What is a Phishing Campaign?
To be clear, when we say “phishing campaign,” we’re not referring to malicious, black-hat phishing campaigns. A simulated phishing campaign is part of an internal training program to raise employee awareness about real-world phishing attacks and proper instruction on how to recognize them.
According to a study cited by TechRepublic, while 1 in 3 untrained employees were likely to fall for a phishing or social engineering scam in 2021, that number decreased significantly to an average just under 5% after one year of security awareness training.
Phishing awareness training can reduce security risks caused by social engineering attacks designed to manipulate recipients into forfeiting login credentials, making wire transfers, or installing malware under the misguided belief they're acting on requests from known individuals or brands.
And despite being two and a half years into the global pandemic, cybersecurity firms are still finding that the effectiveness of COVID-19 as a phishing pretext is STILL prevalent, as evidenced by a 521% spike in COVID test-related phishing attacks from late 2021 to early 2022, as cited in another study by TechRepublic. This again underscores the need for phishing simulations more than ever.
How to Run a Phishing Campaign
A phishing campaign is a great resource to teach your employees how to identify, respond, and report a phishing email.
Phishing Campaign Simulators
If you would rather a program set up your campaign for you, there are a number of options out there. While there are some free programs, the paid versions are more reliable. They may also include email templates, pre-made web pages for phishing links to go to, and specific data about your company’s phishing rates. Offerings range from basic tools for crafting and sending a mock phishing email to several recipients using a specified email server, all the way to SaaS-based phishing simulation platforms for managing multiple, enterprise-scale phishing campaigns.
How Can Security Awareness Training Help Your Organization?
REQUEST A FREE TERRANOVA SIMULATION
Protect from Phishing at the Outset
Phishing awareness training for your employees is critically important, but it should be viewed as your last line of defense, not your first. The best strategy is to implement a layered approach to security that includes multiple solutions, such as antivirus defenses for ransomware/crimeware; secure email gateways for incoming malware attacks; network forensics capabilities for advanced persistent threats; and more. They should also include identity-based defenses that work to keep some of today’s most sophisticated, impersonation-based phishing attacks, such as business email compromise, from ever reaching employee inboxes in the first place.
For instance, our own solution, Cloud Email Protection not only protects against highly-targeted BEC attacks–including those launched from hijacked email accounts belonging to senior executives or trusted outside vendors. Phishing simulation solutions that are integrated with systems like this provide the best of both worlds by enabling organizations to use actual, real-world phishing campaigns in their simulations—giving employees, and their companies, a leg up against threat actors.
To read last year's Terranova Security's 2023 Gone Phishing Tournament report, click here.