Phishing Simulation Record
Purpose
Use this record to document phishing or social engineering simulations and the lessons identified.
The objective is to improve recognition and reporting, not simply to record how many employees clicked.
Exercise Information
Exercise ID: ____________________
Date: ____________________
Exercise owner: ____________________
Audience: ____________________
Number of participants: ____________________
Scenario
Simulation type:
- Email phishing
- Credential phishing
- QR phishing
- Attachment
- Executive impersonation
- Supplier impersonation
- IT support impersonation
- MFA/social engineering
Other: ____________________
Scenario description:
Learning Objective
What behavior was the exercise intended to test or reinforce?
Examples:
- Recognizing suspicious login requests
- Reporting suspicious messages
- Identifying supplier impersonation
- Rejecting unexpected MFA prompts
- Avoiding malicious QR codes
Objective:
Results
Messages delivered: ____________________
Messages reported: ____________________
Links clicked: ____________________
Credentials attempted/submitted in simulation: ____________________
Attachments opened: ____________________
Other relevant actions: ____________________
Average time to first report: ____________________
Positive Findings
What worked well?
Examples:
- High reporting rate
- Fast employee reporting
- Employees independently verified the request
- Managers escalated correctly
Weaknesses Identified
Examples:
- Employees clicked but did not report
- Employees reported only after colleagues warned them
- Finance staff did not verify unusual instructions
- Reporting method was unclear
- Mobile users could not easily report messages
Follow-Up
Is additional training required?
- Yes / No
Audience: ____________________
Training required:
Owner: ____________________
Due date: ____________________
Process or Control Improvements
Did the simulation reveal a technical or process problem rather than only a training issue?
- Yes / No
Examples:
- Weak email filtering
- Missing report button
- Confusing reporting instructions
- Poor external email warning
- MFA weakness
Finding:
Action:
Owner: ____________________
Due date: ____________________
Management of Results
Results should be handled proportionately.
Avoid using simulation results as the sole measure of employee cybersecurity performance.
Where possible, focus on:
- Improving reporting
- Identifying repeated weaknesses
- Improving technical controls
- Providing additional training
- Recognizing positive reporting behavior
Exercise Closure
Reviewed by: ____________________
-
Lessons communicated: Yes / No
-
Actions transferred to Improvement Action Tracker: Yes / No
Evidence location: ____________________
Next exercise: ____________________
Practical Rule
A successful phishing exercise is one that improves real-world recognition and reporting, not one that simply catches employees making mistakes.