Skip to main content

Phishing Simulation

Phishing simulation campaigns send controlled, harmless phishing emails to your managed users to measure their susceptibility and reinforce good habits through immediate training.

Campaign Lifecycle

Draft → Active → Completed
StatusDescription
DraftCreated but not yet sent
ActiveRunning — emails have been sent or are queued
CompletedCampaign closed; final metrics locked

Creating a Campaign

Navigate to SAT → Phishing Campaigns and click + Create Campaign.

FieldDescription
Campaign NameInternal name for tracking (e.g., "Q2 Executive Spear Phish — Acme")
Template TypeThe phishing scenario (see below)
Target UsersEmail addresses of users to target

Template Types

TemplateDescription
Credential HarvestLanding page prompts the user to enter their username and password
Malicious AttachmentEmail contains a simulated malicious attachment
Link ClickEmail contains a link; tracking fires when clicked
Data EntryLanding page requests sensitive information (e.g., credit card, SSN)
Reply ToTracks users who reply to the simulated phishing email

Reporting Metrics

Each completed campaign shows:

MetricDescription
Click RatePercentage of target users who clicked the phishing link
Report RatePercentage of users who reported the email as suspicious

The overall averages across all campaigns are displayed at the top of the Phishing Campaigns page.

💡A high click rate signals the need for more targeted SAT. A high report rate is a positive indicator that users are applying their training.

Auto-Enrollment in Remedial Training

Users who click a phishing simulation link are automatically enrolled in a remedial training campaign. This immediate response — education directly following a failure — is the most effective way to improve user behavior.

Safe Harbor Sending

Simulation emails are sent from a dedicated phishing simulation domain to ensure they do not interfere with your clients' real email reputation. The sending domain is isolated from your clients' production email infrastructure.

⚠️Never run phishing simulations without advance written consent from the target organization. The One Security's phishing module is designed for authorized security awareness training only.

Campaign Actions

ButtonAvailable WhenDescription
LaunchDraftSends or queues emails to all target users
CompleteActiveCloses the campaign and locks final metrics