Who Should be Included in ePHISHiency?
When thinking about a phishing simulation program, you may thinking about what groups, departments or people to include. Use our handy guide below to generate your list:
First
Identify everyone with an active @yourorganization.com email address. Think about contractors, vendors, and even interns. As long as they have an official organization provided email address, they are at risk.
Second
Identify who actually has access to their email. Do you assign email addresses for HR purposes, but that person never actually gets access to use it? You can eliminate them from the list because phishing is not a risk for them.
Third
Finally, you may be thinking about eliminating some specific people at your organization for various reasons. However, every role at your organization is a target for phishing. And on the right day, with the right subject, anyone can get caught. So even if someone is “too busy to be bothered” or “too senior,” that person is probably a perfect target for phishing and should be included in the simulations.
Having trouble?
More KB Articles
Our IP addresses or hostnames, and header information for the purposes of allow listing ePHISHiency.
The allow list decision guide will help lead you to the relevant allow list instructions for your organization.
Why is allow listing required to make ePHISHiency work? We break down the reasoning for you in an approachable way!
Trying to figure out who should be included in your phishing simulations? We’ve got the answers.
How do you manage your organization when it comes to a phishing simulation program? How will you handle how people react, or what to do for those who are most susceptible?
How do you communicate out about a new phishing simulation program? We have some sample language you can use to get the conversation started.
How to allow list by IP Address in Google Workspace to ensure our phishing simulation emails arrive to your inboxes
How to allow list by email header in Google Workspace to ensure our phishing simulation emails arrive to your inboxes
How to Bypass Safe Link/Attachment Processing of Advanced Threat Protection (ATP) in Microsoft 365 to ensure our phishing simulation emails arrive to your inboxes
How to exclude ePHISHiency’s domains from URL rewriting in Microsoft 365 Defender to ensure our phishing simulation emails arrive to your inboxes
How to allow list by header in Exchange 2016 or Microsoft 365 to ensure our phishing simulation emails arrive to your inboxes
How to allow list by IP Address in Exchange 2016 or Microsoft 365 to ensure our phishing simulation emails arrive to your inboxes