Phishing Simulation Record

Purpose

Use this record to document phishing or social engineering simulations and the lessons identified.

The objective is to improve recognition and reporting, not simply to record how many employees clicked.

Exercise Information

Exercise ID: ____________________

Date: ____________________

Exercise owner: ____________________

Audience: ____________________

Number of participants: ____________________

Scenario

Simulation type:

  • Email phishing
  • Credential phishing
  • QR phishing
  • Attachment
  • Executive impersonation
  • Supplier impersonation
  • IT support impersonation
  • MFA/social engineering

Other: ____________________

Scenario description:


Learning Objective

What behavior was the exercise intended to test or reinforce?

Examples:

  • Recognizing suspicious login requests
  • Reporting suspicious messages
  • Identifying supplier impersonation
  • Rejecting unexpected MFA prompts
  • Avoiding malicious QR codes

Objective:


Results

Messages delivered: ____________________

Messages reported: ____________________

Links clicked: ____________________

Credentials attempted/submitted in simulation: ____________________

Attachments opened: ____________________

Other relevant actions: ____________________

Average time to first report: ____________________

Positive Findings

What worked well?


Examples:

  • High reporting rate
  • Fast employee reporting
  • Employees independently verified the request
  • Managers escalated correctly

Weaknesses Identified


Examples:

  • Employees clicked but did not report
  • Employees reported only after colleagues warned them
  • Finance staff did not verify unusual instructions
  • Reporting method was unclear
  • Mobile users could not easily report messages

Follow-Up

Is additional training required?

  • Yes / No

Audience: ____________________

Training required:


Owner: ____________________

Due date: ____________________

Process or Control Improvements

Did the simulation reveal a technical or process problem rather than only a training issue?

  • Yes / No

Examples:

  • Weak email filtering
  • Missing report button
  • Confusing reporting instructions
  • Poor external email warning
  • MFA weakness

Finding:


Action:


Owner: ____________________

Due date: ____________________

Management of Results

Results should be handled proportionately.

Avoid using simulation results as the sole measure of employee cybersecurity performance.

Where possible, focus on:

  • Improving reporting
  • Identifying repeated weaknesses
  • Improving technical controls
  • Providing additional training
  • Recognizing positive reporting behavior

Exercise Closure

Reviewed by: ____________________

  • Lessons communicated: Yes / No

  • Actions transferred to Improvement Action Tracker: Yes / No

Evidence location: ____________________

Next exercise: ____________________

Practical Rule

A successful phishing exercise is one that improves real-world recognition and reporting, not one that simply catches employees making mistakes.