Phishing Simulation Programs
A phishing simulation program is an authorized, recurring security practice that sends controlled deceptive messages to approved populations, measures reporting and interaction events, and feeds those results into training, process fixes, and technical controls. It is a managed program with rules of engagement, privacy limits, and metric discipline, not a one-off trick played on staff.
itOffensive security and application security | OpenSkills.info
Course pathWalk it in order
Look it upDip in anytime
Go furtherLeaves this page
Don't Panic
Don't Panic - Phishing Simulation Programs
A phishing simulation program is not a licensed practical joke at enterprise scale. It is authorized, recurring measurement: approved people receive controlled deceptive messages, the program records defined events, and somebody is supposed to fix a control afterward.
Before these programs, organizations mostly hoped training slides would stick and then argued about who "should have known better" after a real incident. The simulation loop exists because hope is not a denominator. You need delivery counts, interaction counts, and report counts that survive contact with filters, mobile clients, and fear of blame.
Three ideas carry the rest. First, rules of engagement bound the work: population, channel, data you may store, and stop conditions. A platform schedule is not permission. Second, the event model matters more than the lure prose. Eligible, delivered, interacted, reported, trained: if you cannot define those, you cannot interpret a dashboard. Third, an interaction is exposure context, not a moral verdict. NIST's line about improving security rather than singling out individuals is the difference between a program and a public shaming ritual.
The surprise for many readers is that the scary part is rarely writing a clever subject line. The scary part is discovering that the official report action fails on the cohort's mobile client, or that leadership wants a named leaderboard, or that the landing page quietly asked for a password "just this once." Safe programs keep landing pages inert, keep incident response awake, and treat a reported simulation as a successful control action.
If you open one more tab, read the intro for the control loop, then the cheatsheet when you are mid-cycle. Field Notes is where the judgment calls live (why report-path health beats click vanity, why RoE churn is the real operational hazard). The quiz checks whether you still reach for denominators after all this cheerfulness.
Where this skill leads
Relevant careers
See how this topic contributes to broader role-level skill maps.
Sources
- https://csrc.nist.gov/pubs/sp/800/115/final
Supports
- Assessment planning, execution, analysis, reporting, and rules of engagement
- Social engineering as an authorized testing technique
- Program inheritance of assessment discipline
- https://tsapps.nist.gov/publication/get_pdf.cfm?pub_id=152164
Supports
- Social-engineering definition and human-element testing
- Caution against singling out individuals
- Rules-of-engagement constraints and management approval
- Quiz answers about authorization, safe landing design, and shaming metrics
- https://csrc.nist.gov/pubs/sp/800/50/r1/final
Supports
- Cybersecurity and privacy learning program life cycle
- Behavior goals, measurement, and limits of completion counts
- Cohort and program framing for awareness-linked simulation
- https://www.cisa.gov/resources-tools/services/phishing-campaign-assessment
Supports
- Phishing Campaign Assessment as evaluating susceptibility and reaction to phishing email
- Reference shape for organizational simulation engagements
- https://www.cisa.gov/sites/default/files/2022-11/Capacity_Enhancement_Guide-Counter-Phishing_Recommendations_for_Federal_Agencies_1_0.pdf
Supports
- Counter-phishing program context linking simulation evidence to reporting and response
- https://learn.microsoft.com/en-us/defender-office-365/attack-simulation-training-get-started
Supports
- Managed simulation recipients, schedules, payload classes, and training responses
- Landscape placement for Attack Simulation Training
- https://learn.microsoft.com/en-us/defender-office-365/attack-simulation-training-insights
Supports
- Delivered, clicked, compromised, training, and repeat-simulation reporting views
- Denominator discipline in quiz and cheatsheet metrics
- https://getgophish.com/documentation/
Supports
- Self-hosted phishing campaign tooling for authorized organizational testing
- Awesome Links and Landscape placement for Gophish
- https://attack.mitre.org/techniques/T1566/
Supports
- Attacker phishing technique framing for scenario class design
- https://github.com/sindresorhus/awesome
Supports
- Discovery route to security Awesome lists
- https://github.com/sbilly/awesome-security
Supports
- Discovery of Gophish in Social Engineering tooling
- https://github.com/eudk/awesome-cybersecurity-tools
Supports
- Discovery of King Phisher in phishing campaign tooling
- https://github.com/CrimsonForge-io/king-phisher
Supports
- King Phisher campaign toolkit and maintainer notice that it is no longer maintained
- https://www.knowbe4.com/products/phishing-security-test
Supports
- KnowBe4 phishing-security testing Landscape placement
- https://www.proofpoint.com/us/products/mitigate-human-risk
Supports
- Proofpoint human-risk and simulation follow-up Landscape placement
- https://cofense.com/product/phishme/
Supports
- Cofense PhishMe Landscape placement
- https://www.hoxhunt.com/platform
Supports
- Hoxhunt simulation and reporting Landscape placement
