Appearance
Phishing Simulation — Quarterly Cadence
Purpose
Phishing simulations measure the realistic, current-day risk of a user clicking a malicious link, opening a payload, or entering credentials into a fake portal. Running them on a predictable quarterly cadence produces a trended metric for SOC2 and HIPAA evidence, and — more importantly — identifies who needs immediate remedial training before a real attacker finds them.
This document defines the quarterly cadence, metrics, remediation workflow, and annual evidence summary for Cirius Group.
Related story: EMAILSEC-011. Related: compliance/security-awareness-training-eval.md (platform recommendation: KnowBe4).
Cadence
- Frequency: Four simulations per year — one per quarter
- Target weeks:
- Q1: Third week of February
- Q2: Third week of May
- Q3: Third week of August
- Q4: Third week of November
- Audience: 100% of staff (20 users today; no exclusions — executives included)
- Avoid: Holiday weeks, week of DR test, week of audit fieldwork
- Owner: Rory (security). Delegate template selection but not review of results.
Why third week of the quarter-middle month
First weeks of a month are bloated with recurring meetings. Last weeks conflict with month-end. Middle-month third weeks are the lowest-noise window.
Template Rotation
Rotate template difficulty across the year so the baseline tracks realistic attacker sophistication, not the same lure repeated.
| Quarter | Difficulty | Theme |
|---|---|---|
| Q1 | Medium | Generic business service (DocuSign, Adobe Sign, Teams voicemail) |
| Q2 | Medium–Hard | Targeted — appears to come from a known vendor or internal system |
| Q3 | Medium | Seasonal lure (tax, benefits enrollment, holiday shipping) |
| Q4 | Hard | Spear — impersonates Rory or a known named party, uses real |
internal context (role, project) from OSINT on LinkedIn |
Do not warn users ahead of time. The simulation is meant to reflect what they would see from an attacker. Do brief the executive sponsor that the simulation is running so unexpected escalations do not disrupt the test.
Metrics to Track
Capture per-simulation and track year-over-year.
Per simulation
| Metric | Definition | Target |
|---|---|---|
| Delivery rate | Simulations that reached the inbox (not filtered by Defender) | ≥ 95% |
| Open rate | Users who opened the email | Trend only |
| Click rate | Users who clicked the primary link | ≤ 10% by Q4 of year 1; ≤ 5% ongoing |
| Credential entry rate | Users who entered credentials on the fake portal | 0% is the target; ≤ 1% ongoing |
| Report rate | Users who reported the email via the Report Phish button | ≥ 30% rising to ≥ 50% |
| Time-to-first-report | Minutes from send to first user report | Trend only; faster is better |
Per user
last_click_date— most recent simulated-phish clicklast_report_date— most recent correct reportclick_streak— consecutive simulations clicked without reporting (escalation trigger at 2+)training_assigned_for— which remedial modules were assigned from the last click, with completion status
Quarterly review
Produce a one-page summary after each simulation:
- Metrics table (above)
- Who clicked, who reported, who did both
- Any user on a
click_streakof 2+ — flag to Rory for a 1:1 conversation - Quarter-over-quarter trend chart for click and report rates
Remediation Workflow
On click
- [ ] Immediate: KnowBe4 (or chosen platform) auto-assigns a 5–10 minute targeted remediation module on the specific lure type (credential, attachment, link)
- [ ] User receives an email acknowledging the click was a simulation and explaining the teaching moment
- [ ] Module due date: 7 days from click
- [ ] If overdue: escalate to Rory for a direct conversation
On credential entry
- [ ] Immediate: Auto-assign the same remediation module plus a 10-minute credential-handling module
- [ ] Within 2 business days: Rory books a 15-minute 1:1 with the user to walk through what happened. No blame — goal is to understand why the lure worked and to make the user feel comfortable reporting next time
- [ ] If the user holds privileged access (domain admin, PIM-eligible, break glass): Rory reviews whether any real credentials are exposed and triggers password rotation regardless of simulation context
On repeat offense (2+ clicks in a rolling 12-month window)
- [ ] Rory 1:1 with user and the user's manager
- [ ] Extended training plan — a short weekly module for 4 weeks
- [ ] If the user holds privileged access, temporarily remove elevated rights and restore only after completion of the extended plan
On report (correct identification)
- [ ] Acknowledge the report in the platform — small positive reinforcement email from the system
- [ ] Leaderboard the top reporters in the quarterly report (opt-in only — never publish clickers)
Annual Summary (SOC2 / HIPAA Evidence)
In January of each year, produce a single annual summary covering the prior year's four simulations.
Required contents:
- Table of all four quarterly simulations with their metrics
- Year-end click rate, report rate, credential-entry rate
- Trend chart showing quarterly movement in the three headline metrics
- Count of users who entered remedial training in each quarter
- Count of repeat offenders and the remediation they received
- Training completion rate on assigned modules (target ≥ 95%)
- Statement of whether targets were met and what the plan is for the next year
File as: SharePoint → Compliance → Phishing Simulations → <YYYY>-annual- summary.pdf. Link from the SOC2 evidence binder under CC7.2 / CC7.3.
Who signs: Rory and Adriana.
Reporting and Evidence Locations
| Artifact | Location | Retention |
|---|---|---|
| Raw simulation results (CSV per simulation) | KnowBe4 console export + SharePoint → Compliance → Phishing Simulations → <YYYY>-Q<N> | 6 years |
| Per-simulation one-page summary | SharePoint (same folder) | 6 years |
| Training completion roster per simulation | KnowBe4 export + SharePoint (same folder) | 6 years |
| Annual summary | SharePoint and SOC2 binder | 6 years |
Handoff to SOC2 Auditor
Auditors typically ask for:
- Evidence that phishing simulations happen (annual summary + one CSV export for proof of a specific quarter)
- Evidence that remediation happens when users click (CSV export with remediation module assignments timestamps)
- Evidence that privileged users are not exempt (roster showing execs, admins, and all staff included)
The annual summary plus one quarter's raw CSV is usually sufficient. Do not provide names to auditors except under a scoped confidentiality arrangement; offer aggregate statistics first.
SOC2 / HIPAA Mapping
- HIPAA 164.308(a)(5)(ii)(B) — protection from malicious software (awareness)
- HIPAA 164.308(a)(5)(ii)(D) — password management (handling of credentials)
- SOC2 CC1.4 — workforce competence
- SOC2 CC7.2 — monitoring for anomalies / user behavioral risk
- SOC2 CC7.3 — identification and analysis of security events (reported phishes)