NIST SP 800-50PCI-DSS Req 12.6KnowBe4 + Hoxhunt benchmarksCISA Stop RansomwareDeep Prototype

PhishingSimResults — Quarterly Phishing-Sim Results per Team

8 teams × 4 quarters of phishing-sim results. Per team: click-rate (target <5%), report-rate (target >50%), repeat-clicker count, supplemental training assigned. Surfaces 2 teams with chronic high click-rate (Sales + Marketing) + 1 team with declining report-rate (Marketing Q4).

PhishingSimResults — Quarterly Phishing-Sim Results per Team preview
Open live →

What it is

The temporal companion to TrainingTracker. Training tracks completion; PhishingSim tracks effectiveness — and surfaces the team-level patterns where chronic click-rate persists despite training.

What’s in it

  • 8 teams × 4 quarters click-rate matrix
  • Per team: 4-quarter trend, headcount, repeat-clickers, supplemental training assigned
  • Findings: Engineering trends down (1.2% Q4); Sales chronic 8-12% (sales-velocity vs vigilance trade-off); Marketing chronic 12-18% + DECLINING report-rate Q4 — investigate

Why this shape

NIST SP 800-50 + PCI-DSS Req 12.6 require security-awareness training. The right metric isn’t completion — it’s behavior change. KnowBe4 + Hoxhunt benchmark click-rates < 5% as best-in-class; report-rate > 50% indicates the team understands what to do.

How it ships

Single HTML file, ~12KB. Zero dependencies. 8 teams × 4 quarters matrix + per-team drilldown in 100 lines of vanilla JavaScript.

Open the tool →