Terminology Index

Glossary

1801 terms

Open concept maps

Showing 1153-1184 of 1801 terms

P
32

Phishing Simulation

Sending controlled, fake phishing emails to staff to measure susceptibility and reinforce training, a security-awareness tool used carefully to build resilience without blaming or demoralizing employees.

Phishing simulations test and train employees by sending benign mock-phishing messages and measuring who clicks or reports, then delivering teachable moments. Used well, with a just culture, sensible difficulty, and a focus on learning rather than punishment, they raise awareness, improve reporting rates, and provide metrics on human risk over time. Used poorly (as gotchas), they breed resentment and erode trust. They are a common awareness-program and GRC tool when applied thoughtfully.

Introduced in: Security Awareness and Culture, GRC Capstone: Building a Security Program

Examples

  • Sending a controlled mock-phishing email to measure click rates.
  • Delivering a teachable moment after a simulated click.
  • Tracking reporting rates over time to gauge awareness improvement.

No related terms linked yet.