Skip to content

Phishing Simulation

What is Phishing Simulation?

Controlled tests that send simulated phishing emails to employees to measure susceptibility and reinforce security awareness training.

Information Security

Each of these is named in at least one of the same controls as phishing simulation. The number is how many controls name both.

What the standards actually require on phishing simulation

Requirements naming phishing simulation across 6 standards, quoted from the control text.

Lloyds MS11.7 Threat Detection and Security Monitoring - 24/7/365 Security Operations Centre (SOC) capability internal or via Managed Security Service Provider (MSSP) + Security Information and Event Management (SIEM) covering identity + network + endpoint + c...

LLOYDS-MS11-Threat-Detection-Security-Monitoring-Email-Phishing-Defences-MS11-7-12-SOC-EDR-XDR-SIEM · Lloyds MS11 Threat Detection + Security Monitoring + Email + Phishing + MS11.7-12

Operate IAM + workforce security + training across the retail enterprise per NRF framework. IAM must (a) implement multi-factor authentication for all employees + contractors + service accounts where feasible + with priority for privileged access + remote acce...

NRFCS-6 · Identity and Access Management, Workforce Security, Training and Awareness
OSFI B-132 controls

Operate cyber hygiene + security awareness per OSFI B-13 Domain 5. Cyber hygiene must (a) maintain patch management with risk-based prioritisation + KEV-driven remediation + (b) configuration management with hardened baselines + drift detection + (c) vulnerabi...

OSFIB13-5 · Cyber Hygiene and Security Awareness

Conduct random testing (e.g. phishing simulations) to measure the effectiveness of the awareness programme.

ASIC-CR-AT-3 · Random staff testing

All personnel complete annual security awareness training with role-based content and phishing simulations.

IS-X.A.1 · Security Awareness Training

FIRST CSIRT Services Framework v2.1 Service Area 5 - Knowledge Transfer. SCOPE: building cybersecurity capacity in the constituency + the broader community through awareness + training + exercises + advisory.

FIRST-CSIRTF-SA5-KnowledgeTransfer · Service Area 5 - Knowledge Transfer (Awareness, Training, Exercises, Advisory)

Questions people ask about phishing simulation

What is Phishing Simulation?
Controlled tests that send simulated phishing emails to employees to measure susceptibility and reinforce security awareness training.
Why is Phishing Simulation important for compliance?
Phishing Simulation is a key concept in Information Security. Understanding phishing simulation helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Phishing Simulation?
Phishing Simulation appears in the requirement text of Lloyd's Minimum Standards - Cyber Security, NRF Cybersecurity and Data Privacy Framework (National Retail Federation), OSFI B-13, ASIC Cyber Resilience Good Practices, FFIEC IT Examination Handbook. Across these standards we have identified 9 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Phishing Simulation?
Explore our compliance framework pages to see how phishing simulation applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Phishing Simulation applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.