Human Risk Scoring Weights, Scanner Defense & Landing Site Expiry¶
1. Executive Summary & Value Proposition¶
Effective human risk management requires precise mathematical scoring, robust defense against automated mail scanners, and strict control over simulated landing page lifecycles. If security platforms mistake automated email gateway scanners for human clicks, risk scores become distorted and credibility is lost. SimuPhish provides granular operational governance through Human Risk Scoring Weights, Scanner Defense & Landing Site Expiry (Main Navigation > Settings > Platform > Risk Information, False Positive Prevention, and Phishing Site Expiry). Organizations fine-tune risk weighting formulas, eliminate false positives caused by security scanners, and govern landing page expiration to guarantee data accuracy.
2. The Threat Landscape & The Real-World Problem Solved¶
- Automated Security Scanner Distortion: Enterprise email gateways (Microsoft Defender Safe Links, Proofpoint URL Defense, Google Workspace) automatically crawl and click every link in incoming emails. Unfiltered platforms record these as human failures, falsely accusing innocent employees.
- One-Size-Fits-All Risk Formulas: Different industries prioritize risks differently; a healthcare organization may penalize credential disclosure more heavily than an initial link click.
- Lurking Simulated Landing Pages: If simulated phishing websites remain online indefinitely, search engine bots, third-party threat feeds, or former employees may access them weeks later, skewing analytics.
3. How It Works (The User Journey)¶
graph TD
A[Simulated Email Delivered to Employee Inbox] --> B{False Positive Prevention Filter}
B -->|Known Mail Scanner IP / User-Agent Bot| C[Filter Out & Silently Drop: No False Failure]
B -->|Legitimate Human Interaction| D[Log Open, Click, or Credential Submission]
D --> E{Human Risk Score HRS Formula}
E -->|Click: +Weight| F[Update Employee & Department Risk Score]
E -->|Credential: ++Weight| F
E -->|Threat Report: -Bonus| F
D --> G{Phishing Landing Site Expiry Engine}
G -->|Within 1-30 Minute Window| H[Display Teachable Moment / Oops Page]
G -->|Expired Window| I[Display Inactive / Safe Decommission Screen]
The Administrator Experience¶
- Configuring Human Risk Scoring Weights (
Settings > Platform > Risk Information): - Click Penalty Weight: Configure points added to an employee's Human Risk Score (HRS) when they click a simulated phishing link.
- Credential Submission Penalty: Assign elevated penalty weighting when an employee inputs credentials into a simulated landing page.
- Attachment / Payload Execution Penalty: Configure heavy penalty points for executing simulated malicious attachments (LockChain, DriveDrop).
- Threat Reporting Bonus (Vigilance Credit): Define positive credit subtracted from an employee's risk score when they report drills using the Phish Detect button, actively incentivizing reporting.
- False Positive Prevention & Scanner Defense (
Settings > Platform > False Positive Prevention): - Automated Bot Filtering: SimuPhish maintains an active heuristic database of automated mail protection scanner IP ranges and user-agent signatures (Microsoft Defender, Proofpoint, Mimecast, Cisco IronPort, Google Workspace link preview bots).
- Sub-Second Click Filtering: Discard clicks occurring within milliseconds of delivery (a hallmark of automated bot crawlers).
- Guaranteed Metric Integrity: Ensures that only genuine human interactions affect employee performance records and risk metrics.
- Phishing Site Expiry Duration (
Settings > Platform > Phishing Site Expiry): - Active Expiry Window: Configure how many minutes a simulated phishing landing site remains accessible after an email is opened (
1 to 30 minutes, default is10 minutes). - Automatic Deactivation: Once the timer expires, subsequent visits to the link show a safe, inactive placeholder screen rather than an active credential form.
- Security Benefit: Prevents third-party threat intelligence web crawlers or search engines from indexing the simulated landing page.
- Phish Reply Monitoring & Results Visibility:
- Reply Tracking: Toggle whether to capture and analyze direct email replies sent by employees to simulated phishing messages.
- Results Visibility Controls: Choose whether simulation test results are visible to direct line managers or restricted strictly to central platform administrators.
4. Key Business Benefits & Measurable ROI¶
- 100% Defensible Risk Metrics: False positive filtering ensures that risk scores reflect genuine human behavior, preserving trust with employees and managers.
- Customized Risk Alignment: Tailor scoring formulas to mirror your organization's specific risk tolerance and operational priorities.
- Controlled Landing Site Lifecycles: Time-limited landing sites protect corporate domain reputation and prevent external threat crawler noise.
- Incentivize Desired Security Behavior: Reward employees for reporting threats, fostering a positive culture of vigilance.
5. Real-World Attack Scenario & Case Study¶
Scenario: The Microsoft Defender Link Storm¶
- The Situation: A 5,000-employee enterprise launched a phishing simulation. Within 90 seconds of dispatch, Microsoft Defender's Safe Links engine pre-scanned and clicked the simulation link across 4,200 mailboxes.
- SimuPhish Action: SimuPhish’s False Positive Prevention engine instantly identified the Microsoft scanner IP subnets and User-Agent signatures. It recorded the delivery but filtered out all 4,200 scanner clicks.
- The Human Truth: Over the next 2 hours, 187 actual employees clicked the link, and 84 reported it.
- Outcome: The security manager presented accurate, untainted metrics to the executive team, avoiding widespread organizational panic and employee disputes.