0xmichalis

Phishing Campaigns: Mistakes, Challenges, and Best Practices for Effective Training

This is my first post on my new blog, and I chose to share some personal ideas and experiences that represent me. Here’s to a great start! :)


Phishing

The Importance of Phishing Campaigns in Training

Phishing campaigns conducted within organizations for employee training and awareness are arguably among the most essential exercises that can be carried out. Their significance lies in the fact that they test and train the first line of defense in every organization: its employees.

Undoubtedly, the advanced technologies we have at our disposal for cybersecurity—such as next-generation firewalls, IPS/IDS, DLP, SIEM, and now all these enhanced with the power of Artificial Intelligence—are essential. However, when the human factor comes into contact with a threat or malicious action, that’s the pressure point where even a complete and well-structured defense and prevention system can collapse.


The Human Factor and Common Mistakes

Moreover, we cannot always predict or prevent the communication channels through which a malicious attack may be executed, and the target is almost always a human weakness. Therefore, organizing phishing campaigns for staff training, as closely as possible to real-world conditions, is an integral part of an organization’s protection.

My experience has shown that many organizations conduct exercises that are easily detected by employees. Usually, the recurring mistakes are as follows:

  1. Phishing emails that are easy to spot. For example, not enough attention has been paid to the appearance and language of the email, making it easy to suspect it is malicious.
  2. Warning banners have not been removed from the body of the email. This is like giving the problem along with its solution.
  3. Incorrect timing and target group selection. Many organizations simply send the same phishing email to all employees just to check off an exercise on their checklist. As a result, word quickly spreads that an exercise is underway, distorting the results.
  4. Ignoring essential metrics. Organizations often overlook two key metrics: the number of people who read the email and the number who ultimately report it as phishing.

All of the above lead to skewed results regarding the organization’s awareness and, unfortunately, present a misleading image of high readiness.


The Essence of Phishing Campaigns

In phishing campaign exercises, what I believe truly matters is this:

It’s better to fall for it during the exercise, so we’re safe in reality.

How can this be achieved? It’s relatively easy, as long as we make slight adjustments to our approach to conducting these exercises. Below, I present some suggestions on how an organization can appropriately modify its exercises to achieve more meaningful results.


Suggestions for Effective Phishing Campaigns

Phishing Emails

There should be emails that are obviously phishing at first, but as the exercises progress over time, the sophistication of the emails should also increase. The indicators that reveal an email as phishing should become fewer and more subtle. For example, small changes in the domain name, the absence of warning banners, or requests unrelated to the employee’s role can make them think twice. More effort should be put into making them presentable and realistic. Malicious actors have “unlimited” time to craft a well-made email that achieves their goals; we should also invest a significant amount of our time accordingly.

Timing

The timing of when emails are sent is essential. At the start or end of the day, before weekends or holidays, before or after scheduled annual leave—these are good times to catch employees off guard, as we want the phishing email to get “buried” among regular emails. Personally, I would choose to conduct the exercise during periods when the organization is not operating at normal pace, even when facing an issue, and everyone is rushing. The attacker has no sensitivities and will try to exploit every circumstance; likewise, we must train our staff to be vigilant during times of crisis or abnormality.

Target Group

Not all emails are for everyone. In each phishing campaign, a subset of employees should participate—at least 25% of the total number, plus newcomers and those who fell for it in the last exercise. This group should be divided smartly and randomly so that different phishing emails are sent to various teams.

Duration

The duration depends on the nature of the campaign and the period in which the exercise is conducted. One suggestion is that, near holidays, the duration should not exceed seven days, while during periods of high activity with scheduled leave, it can be 20 to 30 days. Additionally, in cases where extraordinary events are involved (e.g., goal setting, bonus discussions, organizational changes), the duration can be shorter, typically around 2 or 3 days.

Metrics

Of course, measuring how many employees were deceived by the phishing emails, how many reported them as phishing, and how many read them are essential metrics. However, we need to look a bit deeper to draw more reliable conclusions.

The number of employees who were deceived should be related to how many actually read the email:

Deceived Percentage=Number of employees deceivedNumber of employees who read the email

Similarly, the number who reported it should be related to how many read it:

Reporting Percentage=Number of employees who reported the emailNumber of employees who read the email

Another important indicator is the percentage of employees who were deceived and, among them, how many reported it:

Reporting Percentage among Deceived=Number of deceived employees who reported the emailNumber of employees deceived

Finally, the number of employees who did not read the email is essential, but not so much for cybersecurity as for their general responsiveness.


Conclusion

In summary, a proper phishing exercise may yield unpleasant results, but that’s what matters. With these undesirable results, we can set a more realistic roadmap to train the organization’s staff and proactively address weaknesses.