Emails can now be individualized and aligned with internal communication patterns
G DATA CyberDefense is expanding its phishing simulation with customizable templates, allowing phishing training to better reflect real company situations. This enables companies to design training emails more realistically and make risks visible. As a result, they gain important information about the state of security awareness within their workforce. Phishing emails today still look deceptively genuine. They pick up on familiar processes, imitate internal communication, and pressure employees using urgency, authority, or curiosity.
Given the continuing high risk posed by fraudulent messages, G DATA CyberDefense is providing customers with a template editor for the phishing simulation. Four out of five employees in Germany are unsure whether they can recognize fraudulent emails. This finding from the current study “Cybersecurity in Numbers” by G DATA, Statista, and brand eins shows how great the need is to raise employee awareness in dealing with phishing emails. With the new template editor, messages in the G DATA phishing simulation can be individually edited. Those responsible can adjust language, tone, and company context without having to build their own scenarios completely from scratch. The offering is now available to all companies that already use G DATA’s phishing simulation.
“Phishing emails remain one of the biggest risk factors for IT security. The danger is increasing because such messages are becoming linguistically better, more credible, and harder to recognize thanks to AI,” says Nikolas Schran, Vice President Sales and Marketing at G DATA CyberDefense.
“With the customizable templates, exercises become more realistic and vulnerabilities more visible, so those responsible can better manage their awareness measures.”In total, the simulation comprises 90 templates across three difficulty levels. The templates cover typical scenarios, including shipping notifications from parcel delivery services, messages about blocked accounts, as well as requests to reset passwords or vouchers from online shops. The templates are available in numerous languages and can, in principle, be translated into additional languages. This means that internationally active companies in particular can now also serve locations whose language was not yet part of their security awareness training.
Boosting security awareness with hands-on trainingAs part of a phishing simulation, employees can engage intensively with dangerous emails and thereby build knowledge. A wide variety of psychological triggers are used in the process. Cybercriminals entice recipients with curiosity, urgency, authority, or willingness to help in order to get them to click a link or disclose personal data. It’s not just individual employees who benefit from the phishing simulation: with a management report, those responsible get all the important metrics at a glance. They learn how often the simulated phishing emails were reported and which triggers were “most successful” among employees. In addition, the report includes an analysis of opened emails. It shows the proportion of clicked links, the critical data that was disclosed, and the attachments that were opened. The reports can also be compared with one another, making the differences between standardized and individually customized messages visible.
Interested parties can find more information on phishing simulation here