Phishing Simulation Programs: Design, Metrics, and What Not to Do
A phishing simulation sends controlled, harmless lookalike messages to your own staff and measures what happens. Gophish is the common open-source platform for running them, but the platform is the easy part. Program design is what determines whether a simulation improves security or quietly damages the relationship between the security team and everyone else. How a simulation works The mechanics are the same as real phishing, minus the payload. You define a target group, compose a message, host a landing page on a domain you control, and send. Each recipient gets a uniquely tracked link, so the platform can record who opened the message, who clicked, who submitted data on the landing page, and who reported it. The landing page is where the training happens. Rather than a fake login that harvests credentials, a well-built simulation lands the user on a short page explaining what just happened and pointing out the specific cues in the message they missed. Delivery requires preparat...