Experiences with simulated phishing
Are you assessing whether simulated phishing may be a good thing to do in your company? See this video for useful steps and input to prepare and launch your own internal phishing campaign.
At the PreParanoia conference, 21. mai 2019 in Oslo, the co-founder and CEO of Secure Practice, Erlend Andreas Gjære, held a talk titled «Experiences with simulated phishing». His entire presentation can be seen in the video below.
Is it okay to trick your own colleagues? With simulated phishing, this is precisely what we do, when sending employees fake emails to increase their awareness. Maybe you have tried something like this in your company already, or maybe you are still assessing whether this is really a good idea or not.
In any case, this talk will offer useful steps to prepare and launch your own internal phishing campaign. We will also discuss how to measure and get value from the results, including on the long term, and how to ensure all of this is done in a privacy friendly way with «teachable moments» for everyone.
Have had such a great couple of days hanging out with all the fun and friendly infosec people at @TheParanoiaConf this week. Next up: @OsloBSides! pic.twitter.com/QWCs9FINzK
— Erlend Andreas Gjære (@erlangsec) May 23, 2019
Contact the author:
Continue reading

Simulated phishing: How to design a suitable scam
How do you prepare the most effective phishing email to serve the goal of your exercise? In the third part of this series on simulated phishing, we describe various approaches to designing phishing content.

How to succeed with security behavior change
To stay safe online, people need to care more about the security decisions they face every day. But unless the obvious gains obviously exceed the required effort, change is often avoided. Luckily, behavior change in general has been subject to a lot of research, and here are some takeaways for information security professionals.

Simulated phishing: Communications strategy
How do you prepare an organization for you to try and trick them? In the second part of this series on simulated phishing, we provide the outline for a communications plan.
Ready to get started?
We have written a guide for you to get started with human-centered security. Access our free resource now, and learn:
- How to nurture drivers for employee engagement
- How to avoid common obstacles for reporting
- Practical examples and steps to get started