Skip to content

Phishing Simulation — Quarterly Cadence

Purpose

Phishing simulations measure the realistic, current-day risk of a user clicking a malicious link, opening a payload, or entering credentials into a fake portal. Running them on a predictable quarterly cadence produces a trended metric for SOC2 and HIPAA evidence, and — more importantly — identifies who needs immediate remedial training before a real attacker finds them.

This document defines the quarterly cadence, metrics, remediation workflow, and annual evidence summary for Cirius Group.

Related story: EMAILSEC-011. Related: compliance/security-awareness-training-eval.md (platform recommendation: KnowBe4).


Cadence

  • Frequency: Four simulations per year — one per quarter
  • Target weeks:
    • Q1: Third week of February
    • Q2: Third week of May
    • Q3: Third week of August
    • Q4: Third week of November
  • Audience: 100% of staff (20 users today; no exclusions — executives included)
  • Avoid: Holiday weeks, week of DR test, week of audit fieldwork
  • Owner: Rory (security). Delegate template selection but not review of results.

Why third week of the quarter-middle month

First weeks of a month are bloated with recurring meetings. Last weeks conflict with month-end. Middle-month third weeks are the lowest-noise window.


Template Rotation

Rotate template difficulty across the year so the baseline tracks realistic attacker sophistication, not the same lure repeated.

QuarterDifficultyTheme
Q1MediumGeneric business service (DocuSign, Adobe Sign, Teams voicemail)
Q2Medium–HardTargeted — appears to come from a known vendor or internal system
Q3MediumSeasonal lure (tax, benefits enrollment, holiday shipping)
Q4HardSpear — impersonates Rory or a known named party, uses real
         internal context (role, project) from OSINT on LinkedIn |

Do not warn users ahead of time. The simulation is meant to reflect what they would see from an attacker. Do brief the executive sponsor that the simulation is running so unexpected escalations do not disrupt the test.


Metrics to Track

Capture per-simulation and track year-over-year.

Per simulation

MetricDefinitionTarget
Delivery rateSimulations that reached the inbox (not filtered by Defender)≥ 95%
Open rateUsers who opened the emailTrend only
Click rateUsers who clicked the primary link≤ 10% by Q4 of year 1; ≤ 5% ongoing
Credential entry rateUsers who entered credentials on the fake portal0% is the target; ≤ 1% ongoing
Report rateUsers who reported the email via the Report Phish button≥ 30% rising to ≥ 50%
Time-to-first-reportMinutes from send to first user reportTrend only; faster is better

Per user

  • last_click_date — most recent simulated-phish click
  • last_report_date — most recent correct report
  • click_streak — consecutive simulations clicked without reporting (escalation trigger at 2+)
  • training_assigned_for — which remedial modules were assigned from the last click, with completion status

Quarterly review

Produce a one-page summary after each simulation:

  • Metrics table (above)
  • Who clicked, who reported, who did both
  • Any user on a click_streak of 2+ — flag to Rory for a 1:1 conversation
  • Quarter-over-quarter trend chart for click and report rates

Remediation Workflow

On click

  • [ ] Immediate: KnowBe4 (or chosen platform) auto-assigns a 5–10 minute targeted remediation module on the specific lure type (credential, attachment, link)
  • [ ] User receives an email acknowledging the click was a simulation and explaining the teaching moment
  • [ ] Module due date: 7 days from click
  • [ ] If overdue: escalate to Rory for a direct conversation

On credential entry

  • [ ] Immediate: Auto-assign the same remediation module plus a 10-minute credential-handling module
  • [ ] Within 2 business days: Rory books a 15-minute 1:1 with the user to walk through what happened. No blame — goal is to understand why the lure worked and to make the user feel comfortable reporting next time
  • [ ] If the user holds privileged access (domain admin, PIM-eligible, break glass): Rory reviews whether any real credentials are exposed and triggers password rotation regardless of simulation context

On repeat offense (2+ clicks in a rolling 12-month window)

  • [ ] Rory 1:1 with user and the user's manager
  • [ ] Extended training plan — a short weekly module for 4 weeks
  • [ ] If the user holds privileged access, temporarily remove elevated rights and restore only after completion of the extended plan

On report (correct identification)

  • [ ] Acknowledge the report in the platform — small positive reinforcement email from the system
  • [ ] Leaderboard the top reporters in the quarterly report (opt-in only — never publish clickers)

Annual Summary (SOC2 / HIPAA Evidence)

In January of each year, produce a single annual summary covering the prior year's four simulations.

Required contents:

  1. Table of all four quarterly simulations with their metrics
  2. Year-end click rate, report rate, credential-entry rate
  3. Trend chart showing quarterly movement in the three headline metrics
  4. Count of users who entered remedial training in each quarter
  5. Count of repeat offenders and the remediation they received
  6. Training completion rate on assigned modules (target ≥ 95%)
  7. Statement of whether targets were met and what the plan is for the next year

File as: SharePoint → Compliance → Phishing Simulations → <YYYY>-annual- summary.pdf. Link from the SOC2 evidence binder under CC7.2 / CC7.3.

Who signs: Rory and Adriana.


Reporting and Evidence Locations

ArtifactLocationRetention
Raw simulation results (CSV per simulation)KnowBe4 console export + SharePoint → Compliance → Phishing Simulations → <YYYY>-Q<N>6 years
Per-simulation one-page summarySharePoint (same folder)6 years
Training completion roster per simulationKnowBe4 export + SharePoint (same folder)6 years
Annual summarySharePoint and SOC2 binder6 years

Handoff to SOC2 Auditor

Auditors typically ask for:

  1. Evidence that phishing simulations happen (annual summary + one CSV export for proof of a specific quarter)
  2. Evidence that remediation happens when users click (CSV export with remediation module assignments timestamps)
  3. Evidence that privileged users are not exempt (roster showing execs, admins, and all staff included)

The annual summary plus one quarter's raw CSV is usually sufficient. Do not provide names to auditors except under a scoped confidentiality arrangement; offer aggregate statistics first.


SOC2 / HIPAA Mapping

  • HIPAA 164.308(a)(5)(ii)(B) — protection from malicious software (awareness)
  • HIPAA 164.308(a)(5)(ii)(D) — password management (handling of credentials)
  • SOC2 CC1.4 — workforce competence
  • SOC2 CC7.2 — monitoring for anomalies / user behavioral risk
  • SOC2 CC7.3 — identification and analysis of security events (reported phishes)

Internal use only — Cirius Group