G DATA Phishing Simulation
The G DATA Awareness Manager
With the help of our online platform—the G DATA Awareness Manager—you can conveniently manage your phishing simulation campaigns. |
|
The home page of the G DATA Awareness Manager provides a clear overview of all completed and still-open campaigns. You can create campaigns using the Weitere Kampagne hinzufügen button. How many campaigns you can run depends on how many campaigns you have purchased.
To run a campaign, first open the campaign by clicking the corresponding row.
|
Using the yellow G DATA Academy logo in the upper-left corner of your browser window, you can return to the home page with an overview of your campaigns at any time.
|
You can now complete all necessary steps within your campaign:
Dashboard
The Dashboard of the G DATA Awareness Manager provides a clear overview of the status of preparations for your campaign. A green border indicates that this preparation step is complete; a yellow border indicates that something still needs to be completed.
You can access the individual areas via the menu on the left edge of the screen.
General settings
In the settings area, you can define two items:
-
By clicking the pencil next to the campaign name, you can freely assign a custom name for the campaign.
-
If campaign preparations are to be carried out by additional people, you have the option to add users to your campaign. These can be additional members of your company or external service providers.
To do so, click Benutzer hinzufügen.
An input form opens where you can enter the first name, last name, and email address of the person who is to receive access to your campaign.
After you complete the entry using the Benutzer anlegen button, the added person receives the following email:
By clicking the link provided in the email, the newly added user can set their own password and log in to the G DATA Awareness Manager.
| The invitation is valid only in the context of the phishing campaign in which you created the user. If additional campaigns exist, the user entry is not included there and may need to be added again. Third parties can also be invited to phishing campaigns that have already been completed, for example to accompany the evaluation. |
| If a service provider has received a user account in the G DATA Awareness Manager but does not have access to the network, responsibility for correct whitelisting lies with the Customer. |
Define the campaign objective
What objective would you like to pursue with the phishing campaign?
Select whether your participants should receive feedback when they click our links.
Do your employees receive phishing emails that reach the inbox despite all security measures? Is your IT team informed so that it can then take action to block these emails in the future?
And: despite all caution, it can happen to anyone to accidentally click a phishing link. Such mistakes often happen in a hectic day-to-day routine. Usually, you quickly realize that you should not have clicked that link. Often it is only an unpleasant feeling that something about this link was not right. If the employee reports this mistake to IT quickly, damage can often still be prevented (for example, by promptly changing disclosed passwords). If this mistake is concealed, however, the attacker has achieved their goal.
Do your employees report to IT after such a mistake has happened?
This internal reporting process is an essential factor in assessing your own IT security.
If the internal reporting process is the focus of your planned G DATA Phishing Simulation, participants should not receive feedback. By comparing the "total number of links clicked in your simulation campaign" and the "total number of Alerts about accidental clicks to your IT team," you can see how well your participants’ sense of responsibility with regard to IT security in your company is developed.
These insights help you assess whether training your participants with regard to the correct handling of data leaks is the main priority.
In this case, select Interne Meldeprozesse bewerten: Melden Mitarbeiter mögliche Gefahren der IT?
Good knowledge of phishing emails and how to recognize them helps to avoid such mistakes in advance. Even under stress, there are criteria that can help you quickly identify a phishing email.
If you want to sensitize your participants to Detection of phishing emails, participants will be shown an appropriate information page after clicking one of our links and after entering data on the landing page that opens. In this way, a campaign can help you assess whether phishing training is necessary for your company or whether completed training has sustainably improved your participants’ Detection rate.
In this case, select Sensibilisierung für Phishing-Mails steigern: Durch unmittelbares Feedback die Security Awareness fördern.
|
If you want, you can alternatively design your own web page to provide feedback to your participants. By entering the URL for this page, the G DATA standard page will not be displayed; instead, the page you specified will be shown. Please note that when using your own page, it is not possible to display dynamically how the specific phishing attempt could have been recognized.
|
Optional addition: Reporting function for phishing emails
You have the option to install an add-in for Microsoft Outlook for participants in your phishing simulation campaign.
With this add-in, participants in your campaign can report any email they consider suspicious via the report button.
The participant receives immediate feedback on whether their suspicion was correct and the email was actually part of the campaign.
The analysis of these Alerts is included in your final report.
There you will find
-
the number of participants who correctly reported at least one phishing email,
-
as well as a chronological overview of the phishing emails that were reported correctly.
Select reports
At this point, active check marks indicate whether you
-
receive only the standard report included in every campaign about all participants after completion of the campaign, or
-
additionally receive the optional group report with key metrics related to specific groups (e.g., grouped by departments or by employees/managers).
| Group analysis is an optional additional service that you can obtain through our sales team. You define groups individually. It is possible to assign participants to multiple groups. |
On this page, enter the name of the report recipient, the language in which the reports are to be written, and the recipient’s email address.
Enter participants
On this page, you enter the participants for the G DATA Phishing Simulation. This can be done via direct entry on the page or via importing a previously created CSV file.
| Changes to the recorded or edited list are applied only after you have saved them. This can lead to problems if you are inactive for a long time while entering participants. The input form then loses connection to the server and entries are lost. If you have long lists or if you need to interrupt the entry, be sure to save in between. |
Select/manage email templates
Each campaign sends four different emails to your participants. G DATA has already compiled four templates for you. These templates are suitable for an initial introduction to the topic and reflect common scenarios.
You can create your own template from a range of email templates.
You can copy and/or edit templates you have already created, as needed, via the pencil icon
copy and/or edit.
You select these templates via the tab Templates.
Perform whitelisting
Whitelisting depends on the security software you use. In this article, you will find helpful information on this topic.
Submit data/enable campaign
When everything is prepared and all areas in the Dashboard are green, you can enter the start week under Daten absenden and start the campaign. Before starting, it is necessary that you confirm once again that the whitelisting was performed and tested correctly.