Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Why You Should Phish In Your Own
Articles Attacks Phishing

Why You Should Phish In Your Own

Manuel SanchezBy Manuel SanchezOctober 10, 2023Updated:August 24, 20245 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Phishing Attacks
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Phishing – that scourge of the internet for several decades now – remains the most popular attack vector when it comes to bad actors trying to get their hands on confidential information. The targets span commercial enterprises, to government agencies (just ask the Police Service of Northern Ireland, which recently suffered a devastating data breach traced to phishing).

New generative AI-powered tools like FraudGPT are only accelerating the problem by allowing cybercriminals to create increasingly well-crafted and targeted phishing emails at scale. This means there are no longer as many of the typo-riddled messages of yore to help wave a cautionary flag when someone receives a message in their inbox. Even more concerning, generative AI can be instructed to mimic the tone or style of various people or personas – e.g., “Draft an email that sounds like it’s coming from the general counsel at company X” – enabling it to create uncannily persuasive and convincing messages.

Given the unrelenting nature of this onslaught, should organizations embrace phishing simulations as part of their security programs?  

It might sound counterintuitive, but given how many organizations still struggle with phishing, casting some phishing lines into their own pond could help prepare users without the costly effects of a real bad actor attack.

A “heat map” of risk

The logic behind fighting phishing with more phishing is actually fairly straightforward: It’s a way to identify where within the organization there might potentially be some areas of risk.

If you send out a simulated phishing email, who are the individuals or groups that are likely to click on links? Would it primarily be those working from home, for example, versus those based in the office? Would it lean more towards the junior staff, or would it lean more towards the senior leaders in the company? Maybe there’s a particularly high concentration in one specific department, whether it’s the accounts payable team, the corporate legal department, or HR.

Knowledge is power – and once you identify where areas of potential risk lie, you’ll have a “heat map” of the organization and its more vulnerable areas. From there, you can take steps towards understanding why those particular groups or individuals are more susceptible to phishing and raising their awareness about the very real threat that phishing poses.

Proper positioning

Sounds straightforward enough – but putting phishing simulations into practice within your own organization requires a little bit of finesse.

There might be some camps within the organization who are opposed to phishing simulations, feeling that it sends the wrong message to employees – simultaneously saying “We don’t trust you” and “You people don’t know what you’re doing.”

That’s not what this is about. No one is trying to create an environment of mistrust or to call anyone’s competence into question. This is about strengthening the overall security posture of the organization, and user awareness training – including phishing simulations – is a valuable piece of the puzzle. That’s precisely how the simulations should be positioned.

Keep some compassion

That being said, the phishing simulations need to be conducted in the proper way, with some compassion for the end users. The idea here is not to “name and shame” individuals and announce that “John from accounting clicked the link in the phishing email we sent out” or to publish the name of the department with the worst track record of clicking on links in your weekly newsletter.

Instead, work to identify the individuals that you need to educate, but also try to understand why they may have clicked on those links. It might not be lack of tech savviness or even a lack of training – maybe they were having a super stressful day and their attention momentarily faltered. Maybe one department is chronically understaffed, so they’re perpetually distracted, which leads to greater susceptibility to cleverly-written, convincing-sounding phishing emails

Again, naming and shaming is not the goal here. Phishing simulations are a way for people to safely make mistakes, with an end goal of making the organization’s defenses stronger.

Better together

As a final point, phishing simulations should not be run on a standalone basis: They need to be accompanied by ongoing organization-wide user education and awareness about phishing. Tests and training should go hand in hand.

Also, as crucial as simulations are, having the right technology in place that can monitor where sensitive content is stored and integrate with the enterprise security stack is also critical for today’s organizations and can help blunt some of the impact of phishing. Real-time threat monitoring and analytics, for example, can detect the anomalous activity of a bad actor downloading hundreds of classified documents using stolen login credentials, allowing the organization to quickly take steps towards remediation.

Phish away

Ultimately, phishing simulations are a tool at organizations’ disposal – but like any tool, it needs to be used properly. Incorporating phishing simulations in a careful and considered manner, as part of a larger user education and awareness campaign around cybersecurity, will only help an organization to strengthen its defenses and better safeguard its sensitive information. Organizations should have little hesitation when it comes to phishing in their own ponds.

Manuel Sanchez
Manuel Sanchez

Manuel Sanchez is Information Security & Compliance Specialist at iManage with extensive professional experience in information security, governance, and compliance.

  • Manuel Sanchez
    The Cybersecurity Reset of 2026: Why Resilience, Not Prevention, Will Define the Next Era of Enterprise Defense
  • Manuel Sanchez
    Why ROT is a Risk Enterprises Shouldn’t Ignore
  • Manuel Sanchez
    The EU AI Act Reshapes Global Enterprise Data Management
  • Manuel Sanchez
    Data Governance and the Mandate for Tougher Security in 2025

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

New Phishing Kit Starkiller Defeats Multi-Factor Authentication

February 23, 20264 Mins Read

ReliaQuest Uncovers Social Media Phishing Campaign Built on Trusted Tools

January 22, 20266 Mins Read

What Happens after a Phishing Email Lands in Your Inbox?

January 5, 20266 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}