Changes to Security Awareness Service Publication on January 18, 2024

Improvements

  • Under “Security Awareness Service > Statistics > Phishing”, an error that resulted in the display of mismatched numbers has been fixed.
  • An error leading to empty strings instead of the sender’s name in simulated phishing emails has been fixed.
  • An error that resulted in simulated phishing emails being sent in the wrong language to several users has been fixed.

Release of New Phishing Scenarios

The following new phishing scenarios have been released:
  • Third-party OAuth application
    • Description: The user is notified that a third-party OAuth application has been granted access to their email account.
    • Email subject: Security Notification: A Third-party OAuth application has been connected to your account
    • Languages: DE, EN, ES, FR
  • Doudle account activation
    • Description: The user has been invited by a colleague to join a Doudle team.
    • Email subject: You have been invited to a Doudle team
    • Languages: DE, EN, ES, FR
  • Feedback request email
    • Decription: An email requesting urgent feedback on a project draft. Includes a link to the draft document.
    • Email subject: Request for Feedback
    • Languages: DE, EN, ES, FR
  • Happy greeting card
    • Description: A special greeting card to wish you a wonderful week filled with joy and success.
    • Email subject: Happy Greeting Card
    • Languages: DE, EN, ES, FR
  • Cybersecurity incident report
    • Description: The email is about a recent cybersecurity incident that has affected the company’s systems, and includes a link to preliminary findings and actions, as well as a reminder for the recipient to secure their own systems and report suspicious activities.
    • Email subject: Cybersecurity Incident Report
    • Languages: DE, EN, ES, FR
  • Weekly project report
    • Description: The user is asked to click on a link to view the weekly project report.
    • Email subject: Weekly Project Report
    • Languages: DE, EN, ES, FR
  • Security alert
    • Description: The user is informed about a security incident and asked to change their access credentials.
    • Email subject: Security Alert
    • Languages: DE, EN
  • Employee gym membership initiative
    • Description: The email is about a new initiative by the company to subsidize employee gym memberships in partnership with local gyms, encouraging employees to register soon as spots are limited.
    • Email subject: Employee Gym Membership Initiative
    • Languages: DE, EN, ES, FR
  • Project Tracker notification: mentioned in report
    • Description: The user is informed about being mentioned in a colleague’s report.
    • Email subject: Project Tracker: You’ve Been Mentioned in a Report
    • Languages: DE, EN, ES, FR
  • Company newsletter
    • Description: The email is a company newsletter informing about some updates HR policies and other news.
    • Email subject: Company Newsletter
    • Languages: DE, EN, ES, FR
  • Project Tracker account creation
    • Description: The user is informed about registration in Project Tracker.
    • Email subject: Project Tracker Account Creation
    • Languages: DE, EN, ES, FR
  • Incomplete cloud storage payment
    • Description: Warning from a cloud storage service regarding an incomplete payment.
    • Email subject: Action Required: Incomplete Payment
    • Languages: EN, DE, FR, ES

Changes to Security Awareness Service in Control Panel Version 6.35.0.0

Enhancements

  • All functionalities of the Security Hub have been enhanced and are now part of the User Panel.
  • Users can now give feedback in the User Panel.
  • In the user settings, it is now possible to disable or enable the sending of simulated phishing emails in the name of the user (identity spoofing).
  • Administrators can now disable the identity spoofing for specific users in the “Customer Settings” module under “Mailboxes”.
  • The training schedule for planning e-trainings manually in the “Security Awareness Service” module under “Configuration > E-Training” has been reworked.
  • The groups and user tables in the statistics under “E-Trainings” in the “Security Awareness Service” module have been redesigned.
  • In the configuration of e-trainings in the “Security Awareness Service” module, it is now possible to make all e-trainings available for users in the User Panel.
  • In the configuration of e-trainings in the “Security Awareness Service” module, it is now possible to deactivate e-training reminders via email for the whole organization.

Changes to Security Awareness Service in Control Panel Version 6.34.6.3

Enhancements

  • The Control Panel now displays a banner for all customers with a customized Security Hub, to set up the customization in the Control Panel by December 14.

Improvements

  • Customers of the Security Awareness Service who have deactivated the privacy mode can now see the results of individual users again in the “Groups” tab of the “Security Awareness Service > Statistics” module.
  • An error during the creation of an allowed domain list for the phishing simulation in the Security Awareness Service has been fixed.

Changes to Security Awareness Service in Control Panel Version 6.34.6.0

Enhancements

  • The “Dashboard” submodule of the Security Awareness Service has been removed. All relevant information has been included in the “Statistics” submodule, which has also been redesigned.

Improvements

  • The following improvements have been made to the Security Awareness Service.
    • Users who existed in the Control Panel before version 6.34.4.0 and who are added later to a group to which e-trainings had been assigned manually will now also receive these e-trainings.
    • When a user who had been removed from a group is successfully added again to that same group under “Customer Settings > Groups”, no error message will be shown anymore.
    • The API for the Security Awareness Service has been improved.