How to Build a Phishing Risk Model at Work

TL;DR
Build phishing simulations around three factors: employee susceptibility, the value and privileges of accessible assets, and the strength of technical defenses. Grade each simulated email by sophistication, establish a baseline through campaigns, inventory business applications and account privileges, then use consistent metrics to estimate the phishing risk introduced across the organization.
Transcript
All right. Who can finish the next line of our talk? Title. Go right ahead. One fish, two fish, right? So think about that, right? Red fish, blue fish, an attack fish, a defense fish. One fish, two fish, right? So one fish allows you to phish some more, right? So we really took that and embodied that a little bit. It was really a creative stroke of... Read More
Key Insights
- Phishing risk cannot be measured well through inconsistent simulations because irregular testing does not produce the metrics an organization needs to assess exposure from the phishing attack vector. A repeatable classification and measurement process makes campaign results more useful for risk analysis.
- A phishing sophistication model grades each simulated message according to how difficult it is for an employee to recognize. Blue-level messages contain many clues, while red-level messages may contain only one or two clues, or no recipient-visible indicators at all.
- Phishing indicators include spelling mistakes, grammatical errors, suspicious sender addresses, inappropriate salutations, unexpected link destinations, risky attachments, and inconsistencies in the message body. These clues help determine the sophistication level of a simulated email and the knowledge demonstrated by its recipient.
- Red-level phishing can involve a state-sponsored attack or a message sent through a compromised employee account. Such messages are especially difficult to identify because the recipient may see none of the usual signs that distinguish a malicious message from legitimate internal communication.
- A credible phishing lure depends on relevance, correct targeting, and timing. Content should fit the recipient's work or interests, reach the intended person, and arrive when the requested action appears plausible, otherwise the exercise may measure poor scenario design instead of susceptibility.
- An attack's practical success depends on more than persuading a recipient to click. Payload quality, the usefulness of harvested credentials, the ability to bypass filters and antivirus protection, and the amount of attention generated all affect whether the attacker receives a meaningful payoff.
- Baseline campaigns establish where employees stand in phishing susceptibility and knowledge. Those results become more valuable when combined with an inventory of business applications, user accounts, and administrative privileges, because identical behavior can create different consequences depending on accessible assets.
- Security awareness is broader than periodic phishing emails. Snap's program combines orientation, training, employee-to-employee phishing education, attack simulations, extensive metrics, editorial content, product and process improvements, usable defenses, and elements of gamification across four main program pillars.
Install to Summarize YouTube Videos and Get Transcripts
Explore YouTube Video Summarizer or Get YouTube Transcript Extractor
Questions & Answers
Q: How do you build a phishing risk model for an organization?
Begin by deciding whether to operate simulations internally or use a vendor. Create a model that grades every phishing email by sophistication, establish the necessary infrastructure, and run initial campaigns to measure employee susceptibility and knowledge. Then inventory business applications, accounts, and administrative privileges. Combine those findings with information about technical defenses so phishing results reflect organizational risk rather than click behavior alone.
Q: What is a phishing sophistication model?
A phishing sophistication model is a classification system for grading how difficult each simulated message is to identify. At the blue end are obvious scams with many clues, such as spelling errors or implausible sender details. At the red end are advanced or compromised-account messages with few or no visible indicators. Applying the same schema across campaigns supports more consistent measurement of employee knowledge.
Q: What clues can employees use to identify phishing emails?
Useful clues include spelling mistakes, grammatical errors, a sender address that does not match the claimed identity, an inappropriate salutation, and a link destination that differs from what the message suggests. Suspicious attachments, including executable, ZIP, or PDF files, can also matter. Employees should also examine the body for content that seems inconsistent with the sender, request, or surrounding context.
Q: Why are advanced phishing emails difficult to detect?
Advanced phishing messages may provide only one or two warning signs, and some may provide no recipient-visible indicators at all. One example is an attacker using a compromised employee account to send a message on that employee's behalf. Because the sender identity can appear legitimate, training focused only on obvious spelling, address, or formatting mistakes cannot fully prepare employees for these attacks.
Q: How should a company establish a phishing baseline?
A company can establish a baseline by deploying supporting infrastructure and running its first campaigns across the employee population. Each simulated message should be assigned a sophistication level so results account for difficulty. The organization can then assess where employees stand in susceptibility and phishing knowledge. Consistent campaign design is necessary if the baseline will support later comparisons and meaningful risk metrics.
Q: Which factors affect the quality of a phishing simulation?
Simulation quality depends on whether the message is relevant to the recipient, reaches the correct target, uses a plausible lure, and contains an appropriate payload. It also depends on payoff, detectability, noise generation, timing, and simplicity. These factors mirror concerns an attacker would consider, helping the security team test realistic scenarios instead of relying only on generic, easily recognized messages.
Q: Why should application access and account privileges be included in phishing risk?
Application access and account privileges help show the potential consequences of a successful phish. After measuring employee susceptibility, Snap inventoried its business applications and accounts, including which users held administrative privileges. Connecting behavioral results with accessible assets distinguishes users whose compromise may have different effects and supports a risk model that extends beyond counting clicks or collecting isolated campaign statistics.
Q: How can security teams run phishing simulations with internal resources?
Security teams can use open source technologies to assemble the infrastructure needed for phishing campaigns without assuming that the program requires many complex moving parts. Snap chose an internal approach after considering vendors and determining that its combined team could operate the simulations. The infrastructure supported initial baseline campaigns, a consistent sophistication model, and the collection of metrics for broader phishing risk assessment.
Summary & Key Takeaways
-
Snap chose to operate its own phishing simulations after assessing whether a vendor or an internal approach would better meet its needs. The security team then created a sophistication model, established supporting infrastructure with open source technologies, and ran initial campaigns to measure employee susceptibility and knowledge across the organization.
-
The sophistication model classifies phishing messages from obvious blue-level scams with many recognizable clues to red-level attacks with few or no visible indicators. Classification considers spelling, grammar, sender addresses, salutations, link destinations, attachments, message content, recipient relevance, targeting, lures, payloads, payoff, detectability, noise, timing, and simplicity.
-
The broader phishing risk model combines simulation results with an inventory of business applications, accounts, and administrative privileges. Snap embeds this work within an awareness program that includes training, attack simulations, metrics, employee content, defensive product and process improvements, and gamification to strengthen both human judgment and organizational protections.
Read in Other Languages (beta)
Share This Summary π
Summarize YouTube Videos and Get Video Transcripts with 1-Click
Try YouTube Summary with ChatGPT & Claude or YouTube Transcript Generator
Explore More Summaries from RSAC Cybersecurity π






Summarize YouTube Videos and Get Video Transcripts with 1-Click
Try YouTube Summary with ChatGPT & Claude or YouTube Transcript Generator