Independent security assurance and editable documentation to keep organizations secure, compliant and resilient Questions? contact@rootguardsecurity.com

Exercise · Buy on its own or inside an assessment

Everyone clicks eventually. The question is what happens next

A controlled simulation that measures whether somebody who notices can get that to a person who can act, and how quickly. We report the reporting rate first, the click rate second, and no individual by name at all.

Measures
Reporting rate, time to first report
Population
All staff, or an agreed group
Ends with
Report, findings, recommendations
Fee basis
Fixed on agreed scope

The measure

Reporting rate, not click rate

A click rate measures whether people can be fooled. Everyone can be, given a good enough pretext and a bad enough morning, and a low number mostly means the lure was obvious. The control is not that nobody clicks. It is that when somebody notices, you find out fast enough to act.

Reporting rate

How many people got it to somebody who could act. This is the control, and it is the number the report leads with.

Time to first report

Compared against what containment would have needed. If the first report arrives at 47 minutes and an attacker needs 20, that sentence is the finding.

Clicked, then reported

The most encouraging result available. Admitting a mistake immediately is harder than avoiding it, and it is the behaviour that contains a real incident.

Conditions

Two things we agree before anything is sent

Nobody faces a consequence for clicking

Signed before we send. Not a moral position, a technical one: if people believe there is a penalty they stop reporting, including when it is real, and the exercise would be degrading the control it measures. If that cannot be agreed, we would rather not run it.

No individual is ever named

Not in the report, not in the briefing, not afterwards. Departments only where the department is large enough that nobody is identifiable.

Authorization comes from somebody with authority over staff rather than from IT, because this tests people. The pretext excludes bereavement, redundancy, medical information and disciplinary process: a simulation that upsets people damages the control it was measuring.

What you end up with

A baseline you can repeat

What we produce

  • The numbers, with the stated difficulty of the lure, so the next run is comparable to this one.
  • Where the pipeline worked or did not. Whether reports reached a person, whether anyone triaged them, how long it took.
  • Findings with owners and criteria, usually about the reporting route rather than about people.
  • What would move the number, ordered by effort.

What one run cannot tell you

  • It is a baseline, not a trend. The second run is where the value is.
  • It does not predict behaviour against something targeted at you specifically.
  • A good number on an obvious lure means less than a poor one on a subtle lure, which is why the difficulty is stated.

Before you book one

Check the reporting route works first

Send one suspicious email through your own process and watch where it goes. If it reaches somebody who acts on it, a simulation will tell you how many people would do the same. If it reaches a mailbox nobody watches, you have the finding already and it costs nothing to fix.