Highlighted wordsare glossary terms — tap one for a plain-language definition.
A PhishingWhat it means: A deceptive email or message designed to make you click, share information, send money, or give account access.Example: An “unpaid delivery fee” text with a link to a page that looks like the post office.What to do: Don't tap links in unexpected messages — open the company's app or type its address yourself.Important: Real companies never ask for your password or a login code by message.What does this mean? simulation is meant to measure and improve real-world resilience — not to trap or embarrass people. NIST and CISA guidance supports a scoped, non-punitive, well-documented exercise that strengthens reporting and response. [1, 2, 3, 4]
Scope it before you send anything
CISA's own Phishing Campaign Assessment is a defined, opt-in service: it targets a specific group of users, runs for a set period, and is set up through signed paperwork with the organization before a single email goes out. Treat any internal simulation the same way — written authorization, a defined target list, a fixed time window, and an agreed stop condition. [3, 4]
- Get written sign-off from leadership, legal, and IT/security before launch.
- Define exactly who is in scope, for how long, and who can pause the exercise.
- Confirm a stop condition in advance if the simulation causes unexpected disruption.
Simulate the click, not the harm
NIST's Phish Scale exists to rate how difficult a simulated email is to detect — it is a measurement tool for training design, not a method for extracting real passwords or delivering working MalwareWhat it means: Software designed to damage, spy on, disrupt, or gain unauthorized access to a device.Example: A “free video player” download that quietly installs something else.What to do: Install apps only from official stores and keep automatic updates switched on.Important: Pop-ups warning that your device is infected are usually the scam itself.What does this mean?. Keep simulations to lookalike lures that log an action (click, report) rather than pages that store real credentials or payloads that actually execute. [1]
- Never collect real passwords, Multifactor authenticationWhat it means: Using more than one type of authentication evidence before an account grants access.Example: Entering your password and then approving the login through an authenticator app.What to do: Turn it on first for your email, financial, social-media, and cloud accounts.Important: Never give an unexpected login code to someone who contacts you.What does this mean? codes, or other sensitive data through a simulated page.
- Use a harmless landing page and disable any real malicious functionality.
- Minimize what's logged about each person to what's needed for training metrics.
- Avoid lures built around trauma, health, layoffs, immigration, or personal emergencies, and make the teaching page accessible.
Teach the moment it happens — don't punish it
NIST's guidance frames click rate and report rate as metrics to interpret in context — how hard the BaitingWhat it means: A social engineering tactic that lures you with something tempting — a free download, a prize, a lost USB drive — to deliver malware or steal information.Example: A USB stick labeled “Layoffs” left in a parking lot, plugged in out of curiosity.What to do: Never plug in drives you didn't buy, and get software only from official stores or the maker's site.Important: Curiosity and greed are the hooks; if it's too good or too juicy, assume it's bait.What does this mean? actually was — so results can drive better just-in-time coaching rather than blame. CISA's phishing guidance likewise treats reporting as the goal to reinforce, with a clear, easy channel for anyone to flag a suspicious message. [1, 2]
- Deliver a short, friendly teaching moment immediately after a click, not a punishment.
- Track and reward reporting behavior, not just avoiding a click.
- Interpret results against the lure's difficulty, not as a simple pass/fail on each person.
Keep it separate from real incidents, and repeat it
A simulation must never weaken the response to a genuine threat: keep the real reporting channel active, brief the small response team that needs to know, and stop the exercise if it causes unexpected risk. Run assessments repeatedly (CISA's own service spans six weeks) so you can track improvement over time instead of judging from a single snapshot. [2, 3, 4]
- Make sure responders can distinguish the simulation platform from real attacker infrastructure.
- Give staff one unambiguous way to report anything that might be a real phishing attempt.
- Re-run assessments on a regular cadence and compare trends, not one-off scores.
Why Hygi. recommends this — the guidance above follows these published sources:
NIST
NIST Phish Scale User Guide (NIST TN 2276)(opens in a new tab)Rating simulated-email difficulty and reading click/report metrics in context, not as pass/fail judgments.
CISA, NSA, FBI, MS-ISAC
Phishing Guidance: Stopping the Attack Cycle at Phase One(opens in a new tab)Reporting and incident-response guidance that keeps simulations distinct from real phishing incidents.
CISA
Capacity Enhancement Guide: Counter-Phishing Recommendations for Non-Federal Organizations(opens in a new tab)Describes CISA's free, scoped, repeated six-week Phishing Campaign Assessment to measure susceptibility.
CISA
Phishing Vulnerability Scanning(opens in a new tab)A mock phishing email sent to a defined, agreed group of users, with results reported for training — not exploitation.
Brought to you by NorthBridge
Unfamiliar term? Open the Digital Safety Glossary