Simulated Self-Phishing System for Security Awareness Training

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Despite investments in cybersecurity tools and awareness training, organizations continue to face successful phishing attacks due to employee lack of understanding and engagement issues in security awareness training programs.

Innovation Solution

A simulated self-phishing system that allows users to enroll in a dynamic training program, receiving personalized and contextually relevant simulated phishing communications, with scoring and feedback mechanisms to enhance engagement and awareness.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional security awareness training programs are implemented, then employees are educated on phishing recognition, but employee engagement is low and training effectiveness is insufficient

Engineering Contradiction:
Improvetraining effectivenessVSAvoidemployee engagement
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system enables employees to self-enroll in simulated self-phishing campaigns at their own convenience, eliminating mandatory training constraints. Employees initiate training requests through their email interfaces, receive personalized simulated phishing emails, and complete training at their own pace, transforming passive compliance training into active self-directed learning.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The training system dynamically adapts to individual employees by generating personalized simulated phishing campaigns based on their role, department, and risk profile. The system adjusts campaign parameters, timing, and content in real-time based on employee responses and risk assessments, creating a flexible, adaptive training experience rather than a static one-size-fits-all approach.

Inventive Principle:
Principle #15Dynamics

2Reliability

If cybersecurity tools such as antivirus and anti-phishing platforms are deployed, then known attacks are detected and intercepted, but social engineering attacks and new threats remain undetectable

Engineering Contradiction:
Improveattack detection capabilityVSAvoiddetection of new and social engineering attacks
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system performs preliminary training and education before actual attacks occur by sending simulated phishing campaigns to employees in advance. This prepares employees to recognize and report real phishing attempts, creating a human-layer of defense that complements technical security tools and enables detection of sophisticated social engineering attacks that automated systems cannot identify.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The simulated self-phishing system acts as an intermediary between technical security tools and human employees. It bridges the gap by providing continuous, personalized security education that enhances employee awareness without replacing technical defenses, creating a hybrid security model where both automated tools and human judgment work together.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If employees are required to attend security awareness training for compliance, then organizational security policy is enforced, but employees are not focused on security implications and engagement is minimal

Engineering Contradiction:
Improvesecurity policy complianceVSAvoidemployee focus and engagement
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system replaces mandatory compliance training with voluntary self-service training requests. Employees initiate training campaigns through their own email interfaces, indicating genuine interest in improving their security awareness. This self-driven approach maintains compliance spirit while eliminating the disengagement caused by forced training requirements.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system changes key parameters of training delivery by moving from centralized mandatory scheduling to individualized on-demand access. Employees can request training at any time, receive personalized campaigns tailored to their risk profile, and complete training at their own pace, fundamentally altering the compliance-enforcement dynamic into a risk-based voluntary participation model.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20220377101A1System and methods to incentivize engagement in security awareness training
Publication Date: 2022.11.24 KNOWBE4 INC
  • US20220377101A1 patent drawing
  • US20220377101A1 patent drawing
  • US20220377101A1 patent drawing

AI summary

Systems and methods to incentivize engagement in security awareness training are disclosed. The systems and methods include a user enrolling in a simulated self-phishing system that enables the user to receive simulated self-phishing communications and be scored on the user's interactions with the simulated self-phishing communications. The method includes identifying organizational information of the user, and communicating simulated self-phishing communications based at least on the organizational information of the user. The method includes receiving interaction data of the user with the simulated self-phishing communications. The method may generate a score of the user based at least on the interaction data.