Does your organization conduct regular phishing simulations for internal team members?
Sort by:
We run regular campaigns with an external partner several times a year. At the end of every year we send recognition to everyone who was successful in flagging all campaigns as phishing.
We run phishing simulations monthly, but for certain groups, not for everyone. We also do it based on seasonality, like tax season and the holiday season. We may do more targeted types of awareness training based on that.
At the companies where I was a board member and part of the cyber or risk committee, we did phishing simulations every quarter, and in fact board members were included in some of them. It was fun and they did fall prey to the simulation.
We do regular phishing simulations. It generally follows the training.
We perform phishing tests and whoever fails it is send back to the security awareness training :)