A security awareness test should answer whether employees, technical controls, and responders can interrupt a realistic attack path. Sending an easy template and counting clicks does not show whether users can report a convincing message, whether an unexpected MFA prompt reaches support, or whether the security team can find and contain affected accounts. The exercise needs a defined risk question and a safe operating plan.
Different scenarios test different defenses. A shared-document lure examines identity and file-sharing behavior. An MFA fatigue scenario tests prompt recognition, authentication settings, reporting, and session response. A caller impersonating support tests identity verification and remote-access policy. A bank-change request tests business approval. These should be planned separately, with appropriate authorization and safeguards.
ALLMSP plans and runs security awareness exercises in house for Lawrenceville, Suwanee, Gwinnett County, Metro Atlanta, and Georgia organizations. We can design scenarios, configure safe delivery, monitor results, respond to reports, correct technical gaps, coach employees, and verify improvement.
Test a complete attack path without creating unnecessary risk
- Ask a question: Define the behavior, technical control, reporting path, and response outcome the exercise will test.
- Authorize: Set sponsor, scope, participants, privacy, safety limits, stop conditions, support contacts, and data retention.
- Match context: Choose realistic but responsible scenarios for employee roles, systems, channels, and current business work.
- Observe: Record delivery, interaction, verification, reporting, control behavior, triage, containment, and feedback.
- Correct: Address learning, email, identity, device, payment, support, workflow, and incident-response weaknesses.
- Retest: Use a comparable exercise or operating evidence to confirm that corrections changed the intended outcome.
Define the scenario, safeguards, and success criteria before launch
Choose one risk question for each exercise. Examples include whether finance verifies new payment instructions, remote staff report an unexpected shared-file login, employees deny and report repeated MFA prompts, or help desk staff authenticate a caller before resetting access. Identify the legitimate business workflow, likely attacker path, affected systems, expected employee action, technical detection, responder action, and business consequence. Do not combine so many behaviors that a result cannot explain what failed.
Obtain written authorization and establish who knows about the exercise. Define target population, exclusions, delivery window, privacy rules, data access, retention, support handling, stop conditions, and procedures for an actual incident discovered during testing. Avoid collecting real passwords or exposing sensitive information. Consider employees on leave, accessibility needs, high-stress roles, recent incidents, and personal circumstances. Prepare the help desk and security team to respond without revealing the exercise unnecessarily.
- Risk question: State exactly which human behavior, control, report path, and response action will be evaluated.
- Authorization: Name the sponsor, operator, reviewers, escalation authority, privacy owner, and emergency stop contact.
- Safety: Prevent credential collection, financial impact, sensitive disclosure, harmful files, and unnecessary employee distress.
- Population: Use a representative audience and document exclusions, role groups, delivery conditions, and sample limitations.
- Success: Define correct employee action, expected technical behavior, response timing, and evidence before results exist.
A responsible exercise is designed to improve a known risk outcome, not surprise employees for entertainment or produce a dramatic score.
Exercise phishing, MFA, support, and payment scenarios as separate controls
For phishing, vary message difficulty deliberately and record both cues and recipient context. Test ordinary email, shared documents, QR codes, mobile display, or messaging channels only when they reflect real exposure. Observe reporting as well as interaction. For MFA fatigue, use a safe method that tests whether a user denies and reports an unexpected prompt without risking account access. Review whether the identity platform uses phishing-resistant authentication or number matching, whether repeated denials create alerts, and whether responders can revoke sessions and investigate the source.
For help desk and voice scenarios, test identity-verification procedures without seeking real secrets or bypassing approved limits. For payment and vendor-change scenarios, verify that staff use an independent known contact route and required approval. Measure whether technical controls support the expected behavior. A well-trained user can still fail when a display hides the sender, the report button is unavailable, the approval process rewards urgency, or support procedures permit identity resets from weak evidence.
- Phishing: Test relevant cues, role context, safe interaction, verification, reporting, email controls, and response.
- MFA fatigue: Verify denial, reporting, number matching or resistant methods, alerting, session review, and account containment.
- Support impersonation: Exercise known contact routes, caller verification, reset authority, remote-control policy, and escalation.
- Payment fraud: Test callback verification, separation of duties, approval evidence, bank-change procedure, and urgent exceptions.
- Data requests: Check identity, purpose, sharing controls, sensitivity, authorization, expiration, and reporting of mistakes.
Separate scenarios produce clearer evidence and let the organization improve the exact combination of human, technical, and process controls involved.
Debrief without blame and retest the control that actually failed
Analyze delivery, message difficulty, interaction sequence, verification, reporting, report timing, technical detection, responder acknowledgment, containment, and employee feedback. Interview a small sample to understand why people acted. Determine whether the primary cause was knowledge, message context, interface, workload, authority, process design, technical configuration, or culture. Report patterns and business consequences, while limiting unnecessary exposure of individual results.
Create corrective actions with named owners and dates. Provide focused coaching for the relevant behavior. Improve reporting tools, email authentication, filtering, MFA, alerting, access recovery, payment approval, support verification, or data-sharing controls as evidence requires. Tell participants what the organization learned and what changed. Retest with a comparable scenario after corrections have had time to operate. A lower click rate is not enough if reports remain slow or responders still cannot contain the account.
- Debrief evidence: Combine scenario difficulty, actions, timing, reports, controls, response, interviews, and business context.
- Root cause: Separate knowledge gaps from usability, workload, policy, authority, technology, and management incentives.
- Coaching: Explain the relevant cue and safe action privately, promptly, and without discouraging future reporting.
- Control correction: Change the technical or business process that allowed the simulated attack path to progress.
- Comparable retest: Preserve enough scenario context to judge whether behavior and response improved meaningfully.
Testing creates value when the organization learns why the attack path progressed, corrects that cause, and verifies a better outcome.
Security awareness exercises and remediation from ALLMSP
ALLMSP can design authorized phishing, MFA, help desk, payment, and data-handling exercises around the organization’s real systems and workflows. We configure safe delivery, monitor technical and user behavior, support reports, protect privacy, and stop the exercise if actual risk appears.
Our in-house team can then coach employees, strengthen email and identity controls, improve support and approval procedures, correct alert routing, and run a comparable retest. Lawrenceville, Suwanee, Metro Atlanta, and Georgia businesses receive one path from exercise design through verified remediation.
- Exercise: Define a risk question, authorize safeguards, select context, and run a controlled scenario.
- Diagnose: Interpret employee behavior, technical controls, reporting, response, and root cause together.
- Remediate: Improve learning, technology, workflow, authority, and response, then verify the result.
Primary guidance for responsible phishing and MFA exercises
Use human-centered and technical guidance to plan safe, interpretable exercises, then correct the whole attack path rather than placing the result only on employees.
- NIST Phish Scale User Guide. Provides a structured method for rating human phishing detection difficulty based on message cues and recipient context.
- CISA phishing guidance. Addresses phishing-resistant MFA, email and identity controls, prompt reporting, investigation, and response across the attack cycle.
- CISA multifactor authentication guidance. Explains phishing-resistant MFA and number matching as a mitigation for push-notification fatigue.
- Microsoft attack simulation documentation. Documents safe simulation setup and reporting for delivery, user actions, reports, training, and activity timelines.
Security awareness testing FAQs
What should a phishing simulation test?
It should test a defined employee decision, relevant technical controls, the reporting path, responder action, and a business-risk outcome.
Should a simulation collect employee passwords?
No. Use safe indicators that show interaction without collecting real credentials, exposing sensitive data, or creating unnecessary account risk.
How realistic should a phishing test be?
It should reflect credible work context while remaining authorized, proportionate, respectful, and within documented safety and privacy limits.
What is MFA fatigue?
An attacker sends repeated push prompts hoping the user approves one through confusion, habit, or frustration. Phishing-resistant MFA is preferred, with number matching as an interim improvement.
What should an employee do after an unexpected MFA prompt?
Deny the prompt, report it immediately through the approved channel, and follow instructions for session review and account protection.
Can voice or help desk impersonation be tested?
Yes, with explicit authorization, strict limits, no collection of real secrets, prepared escalation, and a focus on identity-verification procedure.
How should simulation difficulty be considered?
Record message cues, sophistication, premise alignment, role relevance, timing, recipient context, and technical display before comparing observed behavior.
Should employees who fail be publicly identified?
No. Use private coaching and restricted data. Leadership reporting should emphasize group trends, root causes, business processes, and corrective action.
Can ALLMSP run and remediate awareness exercises?
Yes. ALLMSP can plan, authorize, deliver, monitor, analyze, coach, correct technical and process gaps, and retest with its in-house team.
Where does ALLMSP provide phishing simulation services?
ALLMSP delivers security awareness testing and follow-up for organizations in Lawrenceville, Suwanee, Gwinnett County, Metro Atlanta, and across Georgia.
























































