I would like to announce the phishing simulations that i am preparing for the employees.<\/p>\n
Could anybody help with a fun engaging message? I would like the campaign to sound fun and I wish the employees would brag to eachother about how they nailed one.<\/p>\n
Then the plan is to tell them at the end of it how proud I am with the results, but that’s a different step.<\/p>\n
So the results are not as relevant as making it fun. I’m training and re-training them all the time so I am not into finding out who’s bad and should be pointed fingers and re-trained. It’s just another approach based on fun and achievement on their side.<\/p>\n
I can try serious and not announced in the future but it can only be fun the first time (if I manage to make it that way for them).<\/p>","upvoteCount":12,"answerCount":17,"datePublished":"2019-08-27T10:47:05.000Z","author":{"@type":"Person","name":"adrian62","url":"https://community.spiceworks.com/u/adrian62"},"suggestedAnswer":[{"@type":"Answer","text":"
I would like to announce the phishing simulations that i am preparing for the employees.<\/p>\n
Could anybody help with a fun engaging message? I would like the campaign to sound fun and I wish the employees would brag to eachother about how they nailed one.<\/p>\n
Then the plan is to tell them at the end of it how proud I am with the results, but that’s a different step.<\/p>\n
So the results are not as relevant as making it fun. I’m training and re-training them all the time so I am not into finding out who’s bad and should be pointed fingers and re-trained. It’s just another approach based on fun and achievement on their side.<\/p>\n
I can try serious and not announced in the future but it can only be fun the first time (if I manage to make it that way for them).<\/p>","upvoteCount":12,"datePublished":"2019-08-27T10:47:05.000Z","url":"https://community.spiceworks.com/t/ho-to-announce-phishing-simulation/727387/1","author":{"@type":"Person","name":"adrian62","url":"https://community.spiceworks.com/u/adrian62"}},{"@type":"Answer","text":"
I think announcing the campaign will make it way less effective. I would go ahead and complete the project and then reveal the results at the end.<\/p>","upvoteCount":8,"datePublished":"2019-08-27T10:54:09.000Z","url":"https://community.spiceworks.com/t/ho-to-announce-phishing-simulation/727387/2","author":{"@type":"Person","name":"bethgriffin2223","url":"https://community.spiceworks.com/u/bethgriffin2223"}},{"@type":"Answer","text":"
I agree with Beth. Announcing an attack is just going to make users prepare for it and be more diligent, the point of the simulated attack is to surprise your users so that results would be genuine. It would be like announcing a pop quiz the day before.<\/p>","upvoteCount":5,"datePublished":"2019-08-27T11:03:01.000Z","url":"https://community.spiceworks.com/t/ho-to-announce-phishing-simulation/727387/3","author":{"@type":"Person","name":"chadborgan5377","url":"https://community.spiceworks.com/u/chadborgan5377"}},{"@type":"Answer","text":"
I’m in the same boat as the replies above. Typically, we don’t recommend announcing a new phishing simulation, as it would not be an accurate<\/em> reflection of your organization’s vulnerability to a phishing attack. Afterwards, though, you can share out the results of the simulation to the rest of your organization if you choose to. You can then announce that you will be “periodically” sending out phishing tests, which will encourage your users to be more alert, but won’t necessarily train them to “watch out for the pop quiz.”<\/p>\n If you’re looking for any resources related to security awareness and phishing, feel free to check out Infosec’s Resource Center<\/a> ! We’ve got a ton of useful resources to help you with your campaign, including some posters<\/a> to hang around the office to promote awareness! If you’re interested, go ahead and give it a visit, and let me know if you have any questions!<\/p>","upvoteCount":3,"datePublished":"2019-08-27T11:22:06.000Z","url":"https://community.spiceworks.com/t/ho-to-announce-phishing-simulation/727387/4","author":{"@type":"Person","name":"sam-infosec","url":"https://community.spiceworks.com/u/sam-infosec"}},{"@type":"Answer","text":" Make sure you notify HR that there will be simulations in the future. Some people are a little sensitive and if they feel as though they’ve been “tricked” they might get offended. Just ensure that HR knows so in the case that does in fact come up, you yourself will be covered. Also, you’ll need to know what to do in case of a failure – will the employee be required to take follow on, remedial training? What if they fail again? Make sure you have some policies set aside, with HR/management approval, that you can fall back on.<\/p>","upvoteCount":2,"datePublished":"2019-08-27T11:31:18.000Z","url":"https://community.spiceworks.com/t/ho-to-announce-phishing-simulation/727387/5","author":{"@type":"Person","name":"connorfraser","url":"https://community.spiceworks.com/u/connorfraser"}},{"@type":"Answer","text":" most people don’t announce individual campaigns, but a lot of people announce the overall project or make a game out of yearly results, etc. One person on spiceworks even gave out trophies and other awards for whoever got the most points for the year. The points were based on not clicking, sending phish alerts, whether any information is entered into links, etc. etc.<\/p>","upvoteCount":3,"datePublished":"2019-08-27T11:38:09.000Z","url":"https://community.spiceworks.com/t/ho-to-announce-phishing-simulation/727387/6","author":{"@type":"Person","name":"brodyweber","url":"https://community.spiceworks.com/u/brodyweber"}},{"@type":"Answer","text":" Telling staff you are doing it negates doing it. Don’t tell them, you want it to be as real as it can be.<\/p>\n When have you ever had an email from a hacker warning you they are about to try and break in?<\/p>","upvoteCount":1,"datePublished":"2019-08-27T12:03:07.000Z","url":"https://community.spiceworks.com/t/ho-to-announce-phishing-simulation/727387/7","author":{"@type":"Person","name":"Rod-IT","url":"https://community.spiceworks.com/u/Rod-IT"}},{"@type":"Answer","text":" Echoing the other comments; definitely don’t announce it. You want to train them to not be complacent; announcing it only reinforces that complacency. We’ve ran campaigns where only IT management knew about it so we could see how the help desk staff would react.<\/p>\n Security isn’t meant to be fun; phishing threats are a huge issue and can cause major disruption in a corporation.<\/p>","upvoteCount":1,"datePublished":"2019-08-27T12:06:41.000Z","url":"https://community.spiceworks.com/t/ho-to-announce-phishing-simulation/727387/8","author":{"@type":"Person","name":"capef3ar","url":"https://community.spiceworks.com/u/capef3ar"}},{"@type":"Answer","text":" Bad idea to announce as you’re trying to gather what the human factors are and to see if the training is working. Besides you’ll get better results<\/p>","upvoteCount":1,"datePublished":"2019-08-27T13:01:28.000Z","url":"https://community.spiceworks.com/t/ho-to-announce-phishing-simulation/727387/9","author":{"@type":"Person","name":"vitob","url":"https://community.spiceworks.com/u/vitob"}},{"@type":"Answer","text":" I would start the campaign, give it a couple cycles before announcing anything. Let some people start to get cocky.<\/p>\n I made the fatal mistake of telling the security team at my office that I could not be gotten easily, if at all. They proceeded to launch a 2 month long spearphishing campaign against me. They caught me one morning with a VERY well crafted fake email from someone I had been working with securing credentials for a customer. I hadn’t had my coffee yet for the day and just was quickly reviewing my emails, only to click absentmindedly and receive a rickroll video.<\/p>\n Needless to say, I ponied up and got them both the cases of beer I had promised.<\/p>\n On the bright side, they know that I’m very wary of emails, and now ask me for help in catching some of the more difficult people here, undoubtedly under the hopes I’ll let my guard down.<\/p>\n You could always do an award after a set period of time to the person who was caught the least, as a way to generate excitement.<\/p>","upvoteCount":3,"datePublished":"2019-08-27T13:51:33.000Z","url":"https://community.spiceworks.com/t/ho-to-announce-phishing-simulation/727387/10","author":{"@type":"Person","name":"michaelhowland4","url":"https://community.spiceworks.com/u/michaelhowland4"}},{"@type":"Answer","text":"