Phishing Simulations — Guide
What it does
Records the results of phishing-simulation campaigns your organization runs (in-house or via providers like KnowBe4, Proofpoint, Microsoft Attack Simulator, Cofense, Hoxhunt). The rolling 90-day click rate feeds the Cyber Governance Maturity Index (CGMI) sub-metric Phishing Simulation Click Rate under the Workforce, Culture & Awareness dimension.
How the click rate is calculated
click_rate = sum(clicks) / sum(recipients) across every campaign whose conducted-on date falls in the last 90 days. Future-dated rows and campaigns with zero recipients are excluded. When no eligible rows exist the metric shows Insufficient data rather than a fabricated 0.
Who can edit
OrgAdmin and WorkflowAdmin can record, edit, and delete campaigns. Everyone in the organization (plus Super Admins) can view the register and the rolling KPIs.
Validation rules
- Recipients must be greater than 0.
- Clicks must be 0 or greater and cannot exceed recipients.
- Reported (optional) must be between 0 and recipients.
Audit trail
Every record/edit/delete writes a row to the Phishing Simulations audit log and is mirrored to the Platform Activity Log. Audit codes: PHISHING_SIMULATION_RECORDED, PHISHING_SIMULATION_UPDATED, PHISHING_SIMULATION_DELETED.
