CYB-28 · Cyber security
Phishing simulations are the most effective way to measure and improve staff resilience against email-based attacks. Simulations must be conducted at minimum quarterly, with failure rates tracked over time and declining. Staff who fail must receive immediate targeted training — not disciplinary action.
Trigger
No phishing simulation programme; simulations conducted less than quarterly; failure rates not tracked or not declining over time
Applicability gate
This is a readiness rule mapped to JS2 themes. Its presence in the library does not establish that JS2 applies directly to the firm.
Citation
This control maps to the public instruments below. The mapping does not establish entity applicability.
Remediation
Implement a phishing simulation platform. Run monthly or quarterly simulations varying attack type (credential harvest, malware, BEC). Track click-through and report rates. Auto-enrol failures in targeted training.
Evidence required