Skip to main content

Targeting your employees with Smart Groups

The ‘smart groups’ feature allows you to target your employees based on one or more dynamic attributes.

1️⃣ What is a smart group?

A smart group automatically brings together the employees who meet one or more criteria. Unlike a manual group, you don't maintain its list of members: it updates by itself as synchronisations run and as your employees act.

That is what lets you target a specific population without spending time on it every month: a phishing campaign for employees who have already been caught, a course for those falling behind, an SMS simulation for those whose number you have.

👉 To create a smart group: Team > Groups > Create group. Some groups also exist by default on your workspace.

2️⃣ The available criteria

Criteria can be combined with each other. They fall into four families.

👉 Training

  • Employees who have - or have not - completed a given course.

  • Employees overdue on more or fewer than X courses, with the option to restrict this to a specific programme year.

👉 Behaviour when faced with attacks

Clicking a link and handing over a password are not the same mistake. The two behaviours are targeted separately.

  • Employees who clicked a link, or who submitted data during a simulation. For each, you specify how many times and over which period: the last X simulations, a date range, or since the beginning.

  • Employees who reported — or did not report — an email over the last X days. A report counts whether it was a real attack or a simulation.

👍 Good to know: these criteria work across all three attack types: email, SMS and phone. See Understanding Smishing and 'Callback attacks'.

Three common targets:

  • Repeat clickers: clicked at least twice across their last 4 simulations.

  • Those who hand over their credentials: submitted data at least twice across their last 4 simulations.

  • Those who click but never go further: clicked at least once, and never submitted data.

💡 Why the distinction matters: an employee who clicks out of curiosity but stops at the form does not have the same training need as one who types in their password. The first has a checking reflex, the second does not. Handling them separately lets you send a light reminder to one group and deeper support to the other.

👉 Employee profile

  • Language: the group gathers the employees whose language matches the one you pick. For an employee with no language set, the workspace's default language applies.

  • Valid phone number: useful for building the audience of a Smishing campaign without checking numbers by hand. A group with no country restriction automatically includes every supported country.

  • Cyber Posture: available on workspaces running Cyber Missions. You can target an exact level, or an "at most" / "at least" level — for example employees whose posture is critical, at most weak, or at least good.

👉 Devices

3️⃣ Two targeting examples

👉 Catching up with your most exposed employees

Employees who were caught in the last 90 days + who have not completed the Phishing course. You end up with a population you can address with a targeted course rather than a general announcement.

👉 Launching an SMS campaign with no preparation

Employees with a valid phone number. The group maintains itself as your directory evolves.

4️⃣ Best practices

  • Two to three criteria maximum. Beyond that, the audience shrinks very quickly and the campaign loses its point.

  • Check the headcount before launching. The number of employees in the group is shown as you create it: that is the best indicator of whether your targeting is too narrow.

  • A group evolves. An employee who completes their course leaves the "overdue" group. That is the expected behaviour: your recurring campaigns stay relevant without any intervention.

Key takeaways

  • A smart group updates itself: you define a rule, not a list.

  • Criteria cover training, behaviour when faced with attacks, the employee profile and their devices.

  • Cyber Posture is only available on workspaces running Cyber Missions.

  • Stick to two or three criteria to keep a usable audience.

Did this answer your question?