- Print
- DarkLight
WHAT IS PHISHING SIMULATION?
Phishing is a type of cybercrime where attackers send fraudulent emails, pretending to be legitimate individuals or organizations, with the intent of tricking recipients into disclosing sensitive information, such as workplace credentials or payment card details. To help safeguard against such attacks, companies often run simulated phishing campaigns. These campaigns are designed to test employees' ability to recognize phishing attempts and avoid compromising confidential data.
In these simulations, employees receive mock phishing emails. If they click on a link within the email or submit their credentials through that link, they are considered to have failed the phishing test. Conversely, if an employee reports the email, views it without engaging, or takes no action, they are considered to have passed.
OBJECTIVE
The objective of this control is to assess whether employees and contractors can successfully identify and avoid phishing attempts during phishing simulation tests.
DATA SOURCES
- Proofpoint Training
- HRDS
- SAP Success Factors
- Ping one