Simulated Phishing Delivery Verification System
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current cybersecurity measures, such as email security systems, often intercept and modify simulated phishing communications, leading to inaccurate assessments of employee cybersecurity awareness and increased administrative workload due to ineffective whitelisting and post-delivery scanning, which can result in skewed perceptions of user risk and reliability issues in delivering simulated phishing campaigns.
Innovation Solution
A method and system for verifying whether simulated phishing communications can pass through email security systems to user accounts without being blocked or modified, involving a delivery verification campaign that identifies suitable email accounts, selects types of simulated phishing communications, configures the campaign, communicates them to test accounts, and determines their reception status, allowing reliable delivery and adaptation of phishing campaign configurations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Object-affected harmful factors
If email security systems intercept and scan simulated phishing communications, then security detection capability is improved, but delivery reliability deteriorates because the communications are blocked or modified
Solution Approach 1:
The system performs preliminary actions by sending test emails before the actual simulated phishing campaign to identify which email types are blocked by the security system. This advance testing allows the system to adapt and select only those communication types that will successfully deliver, ensuring both security detection capability and delivery reliability are maintained.
Solution Approach 2:
The system changes parameters by adapting the simulated phishing campaign configuration based on test results. When certain email types are blocked, the system modifies the campaign to use different email types or formats that successfully pass through the security system, thereby maintaining delivery reliability while preserving security detection capability.
2Reliability
If administrators manually update whitelisting configurations to ensure delivery, then delivery reliability is improved, but administrative workload increases
Solution Approach 1:
The system performs self-service by automatically conducting test emails and adapting the simulated phishing campaign configuration without requiring manual administrator intervention. The system independently identifies blocked email types and adjusts the campaign accordingly, eliminating the need for constant whitelisting updates while maintaining delivery reliability.
Solution Approach 2:
The system performs preliminary testing automatically before deployment to identify delivery issues. This advance automated testing prevents the need for manual whitelisting updates by proactively adapting the campaign configuration to bypass security blocks, thereby reducing administrative workload while ensuring reliable delivery.
3Ease of operation
If simulated phishing communications are sent through SMTP, then ease of operation is improved, but measurement precision deteriorates because delivery status cannot be reliably determined
Solution Approach 1:
The system implements feedback by monitoring whether test emails and simulated phishing communications actually reach user inboxes. This feedback mechanism allows the system to determine delivery status accurately by comparing expected delivery with actual reception, thereby maintaining ease of SMTP operation while improving measurement precision of delivery status.
Data Source
AI summary
Systems and methods are described for verifying whether simulated phishing communications are allowed to pass by a security system of an email system to email account of users. One or more email accounts of the email system with the security system may be identified to use for a delivery verification campaign. Further, one or more types of simulated phishing communications may be selected from a plurality of types of simulated phishing communications. The delivery verification campaign may be configured to include the selection of the one or more types of simulated phishing communications from the plurality of types of simulated phishing communications. The selected one or more types of simulated phishing communications of the delivery verification campaign may be communicated to the one or more email accounts. Further, whether or not each of the one or more types of simulated phishing communications was allowed by the security system to be received unchanged at the one or more email accounts.


