Phishing Simulation and User Awareness Platform for Enterprise Environment
Tender ID: 618937
Tender Details
Tender Description
Key problem/s
National Library of Australia is seeking a phishing simulation solution to strengthen our cyber security awareness program. While we currently have a phishing simulation solution in operation, several gaps limit its effectiveness in preparing staff for real-world phishing threats.
1. Lack of Realistic Phishing Simulations
Current solution relies on generic or predictable phishing emails, which do not adequately reflect modern, sophisticated attack techniques. We need the capability to deliver highly targeted, context-aware phishing campaigns that simulate real-world attack scenarios (e.g., spear phishing, business email compromise, credential harvesting etc.)
2. Limited Flexibility in Campaign Design
Existing tools do not offer sufficient flexibility in crafting and managing campaigns e.g., limited phishing templates, no capability to distribute
We require:
- Access to a comprehensive library of phishing templates
- Ability to easily customise templates to align with our organisational context.
- Support for multiple phishing payload variations within a single campaign.
- Capability to distribute different phishing email variants across user groups or individuals, rather than sending the same payload to all staff on the same day.
- Support for varying difficulty levels and attack types to better simulate real-world adversary tactics.
- Ability to select specific user or users of a branch in campaign design.
3. Predictable Campaign Execution
The current solution does not randomise phishing simulation payloads across the user base, reducing the effectiveness of campaigns and potentially creating artificial user behaviour.
We require:
- Randomised and staggered phishing delivery across users and time periods.
- Ability to simulate “always-on” threat conditions rather than point-in-time testing.
4. Limited Visibility into User Risk
We lack detailed insight into how individuals and groups respond to phishing attempts.
The solution should provide:
- Granular visibility at individual, team, and enterprise levels
- Tracking of user actions (click, credential submission, email reply, reporting, etc.)
- Clear identification of high-risk users and behavioural trends over time
5. Inability to Effectively Manage Repeat Offenders
Repeat offenders present a higher organisational risk but are not currently systematically addressed.
We require:
- Identification and flagging of repeat offenders.
- Ability to target high-risk users with more frequent or advanced simulations.
- Risk scoring to prioritise remediation efforts.
6. Need for Continuous Improvement and Metrics
There is currently no strong feedback loop to measure program effectiveness.
We require:
- Metrics such as phish-prone percentage, reporting rates, and resilience scores.
- Benchmarking and trend analysis over time
- Support for continuous improvement of the cyber awareness program
The users and their needs
1. Executive and Operational Visibility
We require:
- Intuitive dashboards for quick assessment of organisational risk posture
- Executive-level reporting with trends and key metrics
- Ability to export data for governance, audit, and reporting purposes.
2. Reporting Capability
The solution should include:
- A “Phish Alert” button integrated into enterprise email clients so that employees can report phishing email.
- Capability to capture, analyse, and triage reported emails
- feedback loop to reinforce correct reporting behaviour.
3. Usability and Administrative Efficiency
We require:
- A user-friendly administration interface
- Streamlined campaign creation, reporting, and user management.
- Minimal administrative overhead for ongoing operations
Location
Similar Tenders
Active opportunities matching this tender's categories and regions.