Skip to content

Target Groups: Dynamic Workforce Segmentation & Smart Groups

Platform Feature: Target Groups (Divisions)
UI Location: Main Navigation > Human Attack Surface > Target Groups (/target-groups)
Grouping Models: Static Departmental Groups, Dynamic Behavioral Smart Groups, Multi-Attribute Criteria
Associated Modules: Full Roster (/full-roster), Ecosystem Bridge (/connect-sync)


1. Executive Summary & Value Proposition

Treating an entire enterprise as a monolithic group for cybersecurity awareness is ineffective and counter-productive. Sending a software developer the same generic password hygiene test as a frontline warehouse technician or an accounts payable manager fails to assess actual job-specific threat exposure.

Target Groups (/target-groups) empowers organizations to divide their workforce into precise, logical segments. By combining directory-based department groups with Dynamic Smart Groups—which automatically populate based on real-time employee behavioral risk—SimuPhish enables tailored simulation difficulty and targeted learning pathways.


2. The Strategic Problem Solved

  • Generic Training Inefficiency: Finance staff face wire fraud; software engineers face GitHub token theft and package poisoning; executive assistants face voice deepfakes. Target Groups ensures employees only receive threats relevant to their daily workflows.
  • Static Group Maintenance Overhead: Manually tracking which employees failed recent phishing tests to assign extra training is virtually impossible at enterprise scale.
  • Dynamic Risk Segmentation: SimuPhish’s Dynamic Smart Groups automatically add or remove employees based on behavioral triggers (e.g. failing 2+ simulations in 60 days).

3. How It Works (The User Journey)

Core Segmentation Models

  1. Departmental & Divisional Groups: Automatically synchronized from Active Directory / Okta (e.g., Legal, Finance, Engineering, Marketing, Human Resources).
  2. Behavioral Smart Groups (Rule-Based):
  3. Repeat Clickers: Automatically collects any user who clicked links or submitted mock credentials in recent campaigns.
  4. Security Champions: Groups users with high reporting velocity and zero simulation failures for advanced testing and recognition.
  5. New Hires Onboarding: Captures users created within the last 30–90 days for mandatory initial security baselining.
  6. VIP / Executive Protection: High-value targets (C-Suite, board members, senior treasury staff) receiving bespoke spear-phishing drills.

The Administrator Experience

  1. Navigate to Human Attack Surface > Target Groups (/target-groups).
  2. Click Create Target Group and choose between static assignment or dynamic rule criteria.
  3. Attach target groups directly to PhishStrike, QuishFire, or Resilience Academy training missions.
  4. Monitor aggregated risk scores and susceptibility metrics on a group-by-group basis.
graph TD
    Directory["Enterprise Identity Directory (Entra ID, Okta)"] --> Sync["Automated SCIM / Group Sync"]
    Sync --> StaticGroups["Department Groups<br/>(Finance, Legal, Engineering, HR)"]

    BehavioralEngine["Behavioral Telemetry Engine<br/>(Simulation clicks, credential inputs, course scores)"] --> DynamicSmart["Dynamic Smart Groups"]

    DynamicSmart --> RepeatClickers["Repeat Clickers Group<br/>(Automatic Remedial Drills)"]
    DynamicSmart --> Champions["Security Champions Group<br/>(Advanced Recon Drills)"]
    DynamicSmart --> NewHires["New Hires Group<br/>(30-Day Onboarding Pathway)"]

4. Key Business Benefits & Measurable ROI

  • Maximum Relevance & Engagement: Increases employee training engagement by 60%+ through contextual, job-relevant scenarios.
  • Hands-Off Automation: Eliminates manual roster updates; employees transition between risk groups dynamically based on behavior.
  • Precision Remediation: Focuses educational resources where risk is concentrated rather than subjecting resilient employees to repetitive remedial courses.

5. Target Buyer & Operational Roles

  • Primary Users: CISO, Security Awareness Director, Identity & Access Management (IAM) Team, HR Business Partners.
  • Compliance Standards: ISO 27001:2022 Control 5.14, NIST CSF 2.0 PR.AT-01, SOC 2 Type II CC2.2.