The Simulation module sends your employees fake attacks, by email, SMS or phone call, to train their instinct for vigilance in real conditions. Every attack that gets through immediately becomes a chance to learn.
1️⃣ Training, not trapping
A simulation is not there to single out the "bad students". It is there to build an instinct: in a real attack, an employee has only a few seconds to act. That instinct is not acquired by reading a procedure, it is acquired by being tested in a real setting.
This is also why a one-off annual campaign achieves little: it measures a moment. It is repetition that changes behaviour.
2️⃣ What a campaign is made of
👉 An audience
Your whole workspace, specific groups, employees picked one by one, or your entire organisation. Smart Groups let you target by behaviour. For example, people who have already submitted their credentials.
👉 Templates
The template defines what the employee receives: the tool being imitated, the message and the landing page. Each one carries a difficulty rating and Smart Variables that personalise it for each recipient.
👉 A pace
A campaign can be one-off or recurring (daily, weekly, monthly, quarterly or yearly). On a recurring campaign, the audience is reassessed at each cycle: new joiners come in automatically, leavers drop out.
3️⃣ When attacks go out
You do not choose the send time of each attack: Riot spreads them across the cycle, so that employees do not all receive them at once.
Two rules worth knowing:
Attacks go out during working hours, from 9am to 6pm in each employee's time zone, Monday to Friday. A setting lets you open sending to any time, including weekends.
Riot starts with employees who have never been attacked, then with those whose most recent attack is the oldest.
👍 Good to know: the language of the attack is determined at send time, based on the language recorded for the employee. Someone who changes language mid-campaign will receive the attack in their new language.
4️⃣ Three types of attack
Phishing by email, the most common.
Smishing by SMS. See Understanding Smishing.
Callback by phone: the attack contains no link, the employee is invited to call a number. See Callback phishing attacks.
5️⃣ What you measure
👉 The distinction that matters
Clicking a link and submitting credentials are not the same mistake. The first had a doubt and checked; the second went all the way. Both are measured and targeted separately.
👉 The main metrics
The coverage rate: the share of employees you have attacked over a given period.
The vulnerability rate: the share of attacks where the employee went all the way. This is your reference metric.
The report rate: the share of attacks reported through the report button. It is the only metric that goes up as your teams improve.
The click rate.
The share of training completed by employees who were caught out.
⚠️ The open rate is not a reliable metric. Security tools that scan emails automatically push it up artificially, and mail clients that block images pull it down. Do not present it as a result to your leadership: use the vulnerability rate and the report rate.
6️⃣ What happens next
An employee who is caught out does not get a reprimand: they get remediation, immediately. That is where awareness training starts. A few seconds after the mistake, not three weeks later.
7️⃣ Simulation and Cyber Mission
If your workspace runs on Cyber Missions, Simulation feeds into them in two ways: phishing resilience is one of the signals that make up each employee's Cyber Posture, and the remediation course lands in their monthly mission as a priority.
8️⃣ Where to start
Do not start with a high sensitivity level or difficult templates. A population that is just starting out needs to spot the obvious signals before facing sophisticated templates.
Aim for 100 % coverage. An easy campaign that reaches everyone beats a difficult one on a sample.
Establish a rhythm. A recurring campaign is worth more than an annual test, even with fewer attacks per cycle.
Key takeaways
Favour recurring campaigns: a simulation trains an instinct, and it is repetition that changes behaviour.
A campaign combines an audience, templates and a pace; Riot spreads the sends across working hours.
Clicking and submitting credentials are two different mistakes, to be measured separately.
The open rate is not reliable: rely on the vulnerability rate and the report rate.
