diff --git a/documentation/email-reporting.md b/documentation/email-reporting.md index 5a2125b..852205c 100644 --- a/documentation/email-reporting.md +++ b/documentation/email-reporting.md @@ -13,7 +13,7 @@ Consider a simple scenario where we send out 100 simulated phishing emails. Let' * **Outcome 1** - In this outcome, only 1 user clicks the link and submits credentials. That's great! However, no one reports the email. In this case, as an administrator our users were targeted by phishing and an attacker has a valid set of credentials, yet we don't know anything has happened. * **Outcome 2** - In this outcome, 50 users click the link and only 1 user reports it. In this case sure, more users clicked the link, but as an administrator we now know that a phishing campaign is in progress and we can start the incident response process. -Reporting suspicious emails can help prevent the impact of a phishing campaign. It's recommended to build a culture that **rewards the users who report emails**. Even something small like an email to that employee and their manager thanking them for their vigilance can go a long ways. This gives positive feedback that will encourage users to report more emails in the future. +Reporting suspicious emails can help prevent the impact of a phishing campaign. It's recommended to build a culture that **rewards the users who report emails**. Even something small like an email to that employee and their manager thanking them for their vigilance can go a long way. This gives positive feedback that will encourage users to report more emails in the future. ## Reporting via IMAP