杏吧传媒

Search
searchclose icon
huntress logo

Mistakes to Mastery: Get to Know Phishing Defense Coaching from 杏吧传媒 SAT

Glitch effectGlitch effectGlitch effect

From scam messages to fake websites, if you鈥檙e online long enough, you鈥檒l encounter phishing. And that鈥檚 why security awareness training (SAT) exists. The goal of any SAT program is to help end users make smarter decisions when conducting themselves online. However, we鈥檙e all human, and nothing that involves humans is perfect. People will always make mistakes, especially when it comes to phishing emails. There will even be repeat offenders. That鈥檚 why we use phishing scenarios in 杏吧传媒 Security Awareness Training to identify your highest-risk users before they click on a real phish.

Mistakes are a natural part of the learning process, but it鈥檚 easy to stifle an opportunity to make a meaningful behavioral change when someone is made to feel bad for clicking on a phishing simulation email. Instead, these mistakes should be viewed as a chance to coach someone on how to understand how they were tricked and what they can do to avoid these situations in the future鈥攖hat鈥檚 the philosophy behind Phishing Defense Coaching.聽

How Does Phishing Defense Coaching Work?

Most phishing simulation tools will send learners an alarming message that reprimands them for clicking, provide no follow-up for compromised learners, or assign them to a generic 鈥渞ecovery training鈥 that doesn鈥檛 do much to correct potentially harmful behaviors.

With 杏吧传媒 SAT, a learner who clicks on one of our phishing scenarios will automatically be enrolled in Phishing Defense Coaching. This will bring them to a virtual coaching session led by a 杏吧传媒 Threat Researcher who tailors coaching to the specific scenario the learner interacted with.聽

First, learners will be introduced to their coach and made aware that the link they clicked was a phish but, fortunately, just a test.

From there, learners will be asked to disclose why they clicked on the email. This is an important step because it not only determines the custom learning path they鈥檒l be placed in but also compels the learner to rethink their motive for clicking while also providing the admins insight into those motives.

After selecting one or more reasons, the learner instantly receives coaching from a 杏吧传媒 Threat Researcher who鈥檚 experienced in red team penetration testing and well-versed in thinking like a hacker. They鈥檒l address the learner鈥檚 specific reason(s) for clicking the link and explain how hackers will exploit that mistake to take advantage of them. They鈥檒l also coach the learner on how to correct this behavior in the future.

Learners will then complete a brief knowledge check before examining the email they interacted with. The coach shows them the exact phishing scenario they clicked on and highlights the areas containing potential phishing indicators so they know what to look for going forward. The learner can determine if the email may be malicious by identifying these potential risks鈥攕uch as the sender鈥檚 email address or a sense of urgency in the message.

By walking learners through the same scenario they interacted with, the coaches help learners contextualize things they should鈥檝e looked out for based on their real experience. It also helps them understand that phishing attacks can be highly sophisticated and difficult to spot, which gives them the confidence to identify and prevent risks moving forward.

Once learners have completed their coaching session, they self-report how prepared they feel to identify future phishing attacks. Admins can use this information to determine which users feel comfortable preventing future phishing attempts and which could benefit from more training.

Here鈥檚 What We鈥檝e Seen so Far

A bonus from Phishing Defense Coaching is the direct learner feedback and data available to admins and our team at 杏吧传媒 to help with the continued optimization of your training programs. During the open beta of Phishing Defense Coaching, we saw:

  • A total of 181 learners were compromised by a phishing simulation and enrolled in Phishing Defense Coaching.聽
  • When asked, 鈥淲hat made you decide to click on the link?鈥 learners reported (note that learners can select multiple options):
    - 鈥淚 didn鈥檛 look closely enough鈥 (29%)聽
    - 鈥淚t seemed important鈥 (19%)
    - 鈥淚 was in a hurry鈥 (9%)
    - 鈥淚t felt urgent鈥 (3%)
    - 鈥淚 thought I was in trouble鈥 (1%)
    - 鈥淚t was exciting鈥 (2%)
    - 鈥淪omething else鈥 (36%)
  • When asked to rate how prepared they feel identifying a future phishing attack on a scale of 1 (鈥渘ot prepared鈥) to 5 (鈥渧ery prepared鈥), learners generally leaned towards 鈥渧ery prepared鈥:
    - 1 (1%)
    - 2 (1%)
    - 3 (3%)
    - 4 (27%)
    - 5 (67%)
__wf_reserved_inherit

By understanding their learners鈥 confidence in identifying a future phishing attack, as well as the motivators driving them to click links, admins can better identify their users鈥 areas of potential risk and work to mitigate them. This is also valuable to the 杏吧传媒 SAT team, as it helps us identify broader trends across the learner base to optimize training programs and produce better security outcomes for your teams.

Try it out with a self-guided tour.

聽 聽 聽 聽 聽 聽 聽 聽 聽 聽 聽 聽 聽 聽 聽 聽 聽 聽 聽 聽 聽
聽 聽 聽 聽 聽 聽 聽 聽
聽 聽 聽 聽 聽 聽 聽 聽
Take a tour of product
聽 聽 聽 聽 聽 聽 聽 聽 聽 聽 聽 聽 聽 聽 聽 聽 聽 聽
聽 聽 聽 聽 聽 聽 聽 聽
聽 聽 聽 聽 聽 聽 聽 聽 聽
聽 聽 聽 聽 聽 聽 聽 聽 聽 聽 聽 聽 聽 聽 聽 聽 聽
聽 聽 聽 聽 聽 聽 聽
聽 聽 聽 聽 聽

Phishing Defense Coaching is just the latest cool feature we鈥檝e added to 杏吧传媒 SAT. And it鈥檚 now available at no additional cost with all Managed Phishing scenarios in 杏吧传媒 SAT.聽

Experience the difference of Phishing Defense Coaching when you sign up for your free trial of 杏吧传媒 SAT.聽聽
Share

Sign Up for 杏吧传媒 Updates

Get insider access to 杏吧传媒 tradecraft, killer events, and the freshest blog updates.

By submitting this form, you accept our Terms of Service & Privacy Policy
Oops! Something went wrong while submitting the form.
杏吧传媒 at work