Phishing tests are controlled sending of prepared messages to employees, which shows in numbers how many of them fall for fraud attempts. Instead of asking the team whether they can recognize phishing, the organization checks it on real reactions: clicks on the link, open attachments and data entered on the fake website.
The simulation does not involve any leakage or harm to the company. Messages are created solely to record the recipient’s behavior, and the collected data is included in a report showing where the gap begins between the written security policy and the employee’s everyday reflexes.
What does a phishing test measure?
A phishing test provides specific, comparable metrics rather than a general impression of a team’s “alertness.” The most important of them are:
- click percentage – how many recipients opened the link or attachment
- percentage of data provided – how many entered the login and password on the fake login page,
- percentage of reports – how many employees recognized the message and reported it in accordance with the procedure,
- response time – how quickly the first report of a suspicious message appeared.
The comparison of these numbers says the most. A high percentage of clicks with a low percentage of reports signals that the company has problems not only with recognizing fraud, but also with the lack of the habit of reacting.
What baits do phishing tests use?
A credible simulation resembles messages that actually circulate in company mailboxes. That’s why phishing campaigns use several types of bait:
- link to a fake website – e.g. alleged notification of a shipment, invoice or blocked account
- attachment – a file “to be checked urgently”, imitating an offer or internal document,
- login page – a copy of the email panel, bank or tool used in the company,
- spear phishing – a message prepared for a specific person, impersonating a superior or regular contractor.
The more difficult it is to distinguish bait from real correspondence, the more honest the test gives a picture of vulnerability.
How do phishing tests differ from social engineering tests?
Phishing tests examine one attack channel, i.e. email and SMS messages. Social engineering tests cover a much wider range of manipulations, including telephone calls and attempts to physically enter the premises. Phishing is the most common and easiest to measure form of social engineering, so it is sometimes an entry point into a broader resilience study.
Continuous education also differs from a one-time test. Practical Anti-Phishing Training repeats the simulations regularly and closes them with a short training right after the failure, thanks to which it changes habits and not only describes their state. Additionally, simulations include phishing, smishing, vishing and Teams attacks.
Who conducts phishing tests and with what?
Phishing tests can be conducted in-house or outsourced to an external team, and the choice depends on how much work the organization wants to leave to its own IT.
- Commercial platforms and supplier services – prepare a campaign from A to Z, including automatic sending, group segmentation and reports that help meet legal regulations for security awareness.
One of such solutions is the Polish platform for simulating cyberattacks, i.e. Practical Anti-Phishing Training, which offers two implementation models: Cloud model (SaaS) – the platform works on the supplier’s side, without installation at the client; quick launch, and the campaign is fully managed by the SECAWA team. A variant for most companies that want to reduce the burden on their IT team. On-premise model – a platform installed in the organization’s infrastructure, data from the simulation does not leave it. For entities with increased security requirements, e.g. critical infrastructure or organizations processing classified information.
- Open-source tools – free of charge, allow you to build a campaign on your own, but require configuration, original scenarios and independent analysis of results.
Stand-alone campaigns tempt you with the lack of a license fee, but they consume the team’s time and are easy to produce repetitive, quickly recognized scenarios. The service provided by SECAWA specialists takes over the preparation, sending and interpretation of data from the IT and departments href=”http://secawa.com/en/blog/responsibilities-and-scope-of-the-ciso-cso-role/”>CISO.
Why does a company need phishing tests?
Phishing tests turn the feeling “no one would click here” into a hard number that can be presented to the management board and auditors. Three reasons matter:
- The scale of the threat. Phishing is responsible for most incidents starting with a human, and the number of campaigns in Poland is growing, as documented by statistics from the CERT Polska report.
- Education focus. The result indicates the roles and departments that most need support, e.g. by learning phishing recognition principles.
- Documentation for audit. The report helps demonstrate activities for security awareness required by GDPR, NIS-2, DORA or ISO 27001. The test itself does not ensure compliance, but is a documented element of it.
Frequently asked questions
What percentage of clicks is good in a phishing test?
There is no single threshold value. The direction of changes is important: a decrease in the percentage of clicks and an increase in notifications in subsequent campaigns. The first test is treated as a reference point, not as an assessment of the team.
Is a free tool enough for the test?
For simple, internal tests, yes. With a larger scale, group segmentation and reporting for the management, commercial platforms or an external service that removes the support from the IT team are more convenient.
Are phishing tests GDPR compliant?
Yes, if the simulation data is processed in a controlled manner, i.e. anonymized or encrypted, with access only by the organization. The purpose of the test is to educate and measure risk, not to collect passwords.
Where to start phishing tests?
The simplest way is a single, free simulation on a selected group of employees, which shows the scale of risk and the method of reporting results.