When setting up campaigns in software like KnowBe4, you must make sure the existing protections don’t flag emails you send in your campaigns. These are usually defined in something like defender for cloud as a policy, and so additional policies for knowB4 mail campaigns have to be set so you don’t prevent them from being caught.
However, this is mostly just to ensure you get targeted content for a campaign to end users, and most every email we send would pass through anyway. We set the defender for cloud exceptions because we do not want to falsely impact measures on targeted cohort performance with defender policies.
The above email for example would not be flagged as phishing by any current policies in place in our organization.
While it is easy to be cynical about the phishing email campaigns, they do exist to try and get to a more mindful state of your users. We have research that supports their efficacy, and while you won’t ever get end users to universally “good” levels of behaviors around phishing, we can’t make that perfection be the enemy of trying to be more mindful.
Still, it is humorous when you define a campaign and make it more specifically targeted for C suite cohorts only to get told to tone it down. They missed the point indeed.
So… not entirely accurate.
When setting up campaigns in software like KnowBe4, you must make sure the existing protections don’t flag emails you send in your campaigns. These are usually defined in something like defender for cloud as a policy, and so additional policies for knowB4 mail campaigns have to be set so you don’t prevent them from being caught.
However, this is mostly just to ensure you get targeted content for a campaign to end users, and most every email we send would pass through anyway. We set the defender for cloud exceptions because we do not want to falsely impact measures on targeted cohort performance with defender policies.
The above email for example would not be flagged as phishing by any current policies in place in our organization.
While it is easy to be cynical about the phishing email campaigns, they do exist to try and get to a more mindful state of your users. We have research that supports their efficacy, and while you won’t ever get end users to universally “good” levels of behaviors around phishing, we can’t make that perfection be the enemy of trying to be more mindful.
Still, it is humorous when you define a campaign and make it more specifically targeted for C suite cohorts only to get told to tone it down. They missed the point indeed.