Phishing Defense is Ethena's new phishing category, made up of Simulator, Reporter, and Phishing Training. This update introduces Reporter and makes Simulator's click detection more reliable.
- Simulator - sends realistic phishing tests to employees to see who's prepared.
- Reporter - lets employees flag and report suspicious emails, real or simulated, in one click.
- Phishing Training - Training that explains common phishing scams and what to watch out for.
Overview
Until now, phishing simulations could only measure one kind of behavior: clicking. Employees who fell for a simulated phishing email were flagged for remediation training, but employees who did the right thing, spotting the email and reporting it, got no credit at all. This update changes that, while also improving accuracy issue affecting organizations that run certain email security tools.
Reporter lets employees get credit for reporting simulated phishing emails, using the report-phishing buttons already built into Gmail and Outlook. There's nothing new to install or learn, since employees use the same buttons they already have. When an employee reports a simulated phishing email, it shows up in your dashboard with a new Flagged status, alongside the existing Delivered, Opened, and Clicked statuses. This status is visible both at the campaign level and for individual employees, and an employee can hold more than one status at once (for example, Opened and Flagged).
On the backend, Reporter requires a one-time setup step from your IT team: a Google Workspace or Microsoft 365 integration, similar in spirit to setting up SSO. A step-by-step setup guide is available to walk your team through it.
Improved click detection addresses a separate, longstanding issue: some security tools automatically pre-load links inside emails before a person ever opens them (Mimecast is a common example). Previously, this pre-loading could be misread as an employee click, inflating click rates and making results unreliable for affected organizations. This update screens out those false positives, so click rates and materially more reliable.
FAQ
Do my employees need to install anything? No. Reporter uses the report-phishing buttons already built into Gmail and Outlook, the same buttons your employees already have. There's nothing new for them to install or learn.
Does my IT team need to do anything? Yes, a one-time setup step. To detect when an employee has reported a simulated phishing email, your IT team will need to complete a Google Workspace or Microsoft 365 integration. A step-by-step setup guide is available at launch.
What changes in my campaign dashboard? A new Flagged status appears alongside Delivered, Opened, and Clicked, both at the campaign level and for individual employees. An employee can hold more than one status at a time.
Will my click rates change? They might, and that's the fix working as intended. If your organization uses a tool that pre-loads links before a person opens the email, some of those pre-loads were previously counted as employee clicks. This update screens those out, so click rates should better reflect real human behavior going forward.
What happens when an employee reports a real (non-simulated) phishing email? The report-phishing buttons in Gmail and Outlook work exactly as they always have. Reports of real phishing emails go to your email provider and your internal security team, same as today. Ethena credit and the Flagged status currently apply to simulated phishing campaigns sent through Ethena.
Does this change how I build or run campaigns? No. Campaign setup is unchanged. What's new is the Flagged status showing up in results, plus more reliable click detection behind the scenes.
Where can I get help? If you have questions about your specific rollout, setup steps, or existing campaigns, reach out to your Customer Success Manager or our support team at support@goethena.com.
For more information about Phishing please check out our help center articles below
How to set up a Phishing Campaign
What is the Phishing Simulator?
How to view Phishing Campaign results and reports
Comments
0 comments
Article is closed for comments.