Back to Table of Contents

Objectives

Once you have completed this section, you will be able to:

  • Apply custom branding to your SecurityIQ portal
  • Set the default education asset used in PhishSim Templates
  • Add custom domains to be used for sending PhishSim notifications
  • Enable the suppression of footers in PhishSim emails (Enterprise version only)
  • Customize PhishNotify Plugin messages
  • Select the default domain used for sending AwareEd learner notifications
  • Add additional administrators to your SecurityIQ portal
  • Download email logs

Overview

The SecurityIQ platform can be customized in many ways. This section describes how to manage the customizable options available to SecurityIQ administrators.

1

Figure: Account Setting Page

Branding

Many areas of SecurityIQ can be branded to include your organization’s logo, name, and color scheme.

To display a custom logo on SecurityIQ pages, education assets, and email notifications:

  • From the main menu, click your name at the right side of the screen
  • Click “Change Branding” in the branding section
  • Click “Use Custom Logo” in the Logo section
  • Click “Choose File”
  • Select a jpg image file with dimensions between 420×420 and 1280×1280 pixels
  • Click “Save”

To modify the background color of SecurityIQ pages:

  • From the main menu, click your name at the right side of the screen
  • Click “Change Branding” in the branding section
  • In the Background Color section, choose your desired color. The background of the Branding section will update in real-time so you can easily determine how the color will look.
  • Once you have chosen a color, click “Save”

To preview your branding changes:

  • From the main menu, click your name at the right side of the screen
  • Click “Change Branding” in the branding section
  • In the preview section, click the “Binocular” icon to the right of the item you wish to preview

To update the name which is displayed on SecurityIQ pages, education assets, and email notifications:

  • From the main menu, click your name at the right side of the screen
  • Update the “Customer Name” in the User Information section
  • Click “Save” at the bottom of the page

 

2

Figure: Change Branding Page

PhishSim Settings

PhishSim Email Templates will display a default education module if one isn’t specified when the template is created.

To change the default PhishSim Education Module:

  • From the main menu, click your name at the right side of the screen
  • Click the “Gear” icon to the right of Default Education in the PhishSim section
  • Select the desired education asset to be used as the default education for PhishSim templates
  • Click “Save”

To suppress the footer from being included in PhishSim emails (Enterprise version only):

  • From the main menu, click your name at the right side of the screen
  • Click the “Gear” icon to the right of My Domains in the PhishSim section
  • Click the “Suppress Footer” checkbox to the right of the domains you would like to enable this feature for
  • Click “Save”

PhishNotify Plugin Settings

To modify the configuration of the PhishNotify plugin:

  • From the main menu, click your name at the right side of the screen
  • Click the “Gear” icon to the right of Messages and Behavior in the PhishNotify section
  • To enable uploading of message contents when a user reports a suspicious message, click the checkbox to the right of “Upload Email Contents” in the Email Options section
  • To enable uploading of email attachments when a user reports a suspicious message, click the checkbox to the right of “Upload Email Attachments” in the Email Options section
  • If you wish to move an email after it has been reported, select the appropriate action from the dropdown box in the Email Actions section
  • To customize the messages displayed to the learner after they have reported a potentially suspicious email, update the text in the appropriate section
  • Click “Save”

AwareEd Settings

To add custom domains to be used for sending AwareEd notification emails:

  • From the main menu, click your name at the right side of the screen
  • Click the “Gear” icon to the right of My Domains in the PhishSim section
  • In the new window that appears, click the “Add Domain” button
  • Enter the domain you wish to use
  • Click “Save”

To select a default domain to send AwareEd notification email from:

  • From the main menu, click your name at the right side of the screen
  • Click the “Gear” icon to the right of “Send notifications from” in the AwareEd section
  • Select the desired domain and click “Save”

Add Additional Administrators

To invite a new administrator to manage your SecurityIQ portal:

  • From the main menu, click your name at the right side of the screen
  • Click “New Administrators” in the Account Administrators section
  • Enter the email address of the person you would like to share administrative access with
  • Click “Add”

Download Email Logs

To download a log of all email sent from SecurityIQ to your learners in the past seven days:

  • From the main menu, click your name at the right side of the screen
  • Click “Download Log” from the Email Log section

 

Dedicated Email Server

Your SecurityIQ platform comes with the ability to specify a dedicated email server. This enables you to whitelist IP Addresses/Hostnames associated with SecurityIQ. This can help prevent emails generated from SecurityIQ getting blocked by your organization security software and appliances.

To enable the sending of outbound email through a dedicated email server:

  1. Log into your SecurityIQ platform and click the gear icon (upper right) and navigate to Account Settings.
  2. On the bottom left side of the Account Settings page, you will find the “Dedicated Email Server” section.
  3. Enable this feature by clicking the “Enable” checkbox and use the provided IP Addresses/Hostnames for your whitelisting.
  4. Click “Save”
  5. If you are using the custom domains feature the following domain/hostname will need to be whitelisted: 67.217.44.158/mail.phish.io

 

  

 

 

Supplementary

Email Template Variables

 

Variable Description Subject Email Body
http://phish.io (or any URL) in a hyperlink All URLs used in hyperlinks (i.e., in an “<a href=’…’>” clause) will automatically be replaced by a “phish.io” link that allows the system to track your learners’ clicks and present them with a specific landing pages. (Some paid tiers of service allow you to customize these landing pages further.) Hyperlinks are only supported in the BODY of a message. No Yes
{{footer}} Provides a block of text that explains that this email is not spam, that it is a service of our system and that you specifically requested the test. Also provided in the text are links to report this message as phishing, unsubscribe and “report as spam”. This block of text looks similar to other legal “boilerplate” often appended to email messages by corporate email servers and usually ignored by end users. However, it is REQUIRED on all messages, both to keep our system legal, and to give eagle-eyed recipients a way to positively tell the system that they recognized your phishing message and were not fooled. This variable is only supported in the BODY of a message. No Yes
{{learner}} Provides the first and last name of the learner with a space in between the names. Example: “John Smith”. Note: this value may be blank if this value was not configured. This variable is supported in all message fields. Yes Yes
{{learner_first}} Provides the first and last name of the learner. Example: “John”. Note: this value may be blank if this value was not configured. This variable is supported in all message fields. Yes Yes
{{learner_last}} Provides the first and last name of the learner. Example: “Smith”. Note: this value may be blank if this value was not configured. This variable is supported in all message fields. Yes Yes
{{learner_email}} Provides the email address of the learner. Example: “jsmith@email.com”. This variable is supported in all message fields. Yes Yes
{{learner_title}} Provides the title of the learner. This variable is supported in all message fields. Yes Yes
{{learner_department}} Provides the department of the learner. This variable is supported in all message fields. Yes Yes
{{learner_phone}} Provides the phone number of the learner. This variable is supported in all message fields. Yes Yes
{{learner_address1}} Provides the address of the learner. This variable is supported in all message fields. Yes Yes
{{learner_address2}} Provides the address of the learner. This variable is supported in all message fields. Yes Yes
{{learner_city}} Provides the city of the learner. This variable is supported in all message fields. Yes Yes
{{learner_state}} Provides the state of the learner. This variable is supported in all message fields. Yes Yes
{{learner_zip}} Provides the zip code of the learner. This variable is supported in all message fields. Yes Yes
{{learner_country}} Provides the country of the learner. This variable is supported in all message fields. Yes Yes
{{learner_custom}} Provides the custom field of the learner. This variable is supported in all message fields. Yes Yes
{{customer}} Provides the name of your account (not the learner). Yes Yes
{{customer_email}} Provides the email associated with your account (not the learner). Yes Yes

 

 

PhishSim Education Template Variables

Variable Description
{{campaign}} Provides the name of the campaign. Example: “Customer Reps Training”.
{{learner}} Provides the first and last name of the learner with a space in between the names. Example: “John Smith”. Note: this value may be blank if this value was not configured. This variable is supported in all message fields.
{{learner_first}} Provides the first and last name of the learner. Example: “John”. Note: this value may be blank if this value was not configured. This variable is supported in all message fields.
{{learner_last}} Provides the first and last name of the learner. Example: “Smith”. Note: this value may be blank if this value was not configured. This variable is supported in all message fields.
{{learner_email}} Provides the email address of the learner. Example: “jsmith@email.com”. This variable is supported in all message fields.
{{learner_title}} Provides the title of the learner. This variable is supported in all message fields.
{{learner_department}} Provides the department of the learner. This variable is supported in all message fields.
{{learner_phone}} Provides the phone number of the learner. This variable is supported in all message fields.
{{learner_address1}} Provides the address of the learner. This variable is supported in all message fields.
{{learner_address2}} Provides the address of the learner. This variable is supported in all message fields.
{{learner_city}} Provides the city of the learner. This variable is supported in all message fields.
{{learner_state}} Provides the state of the learner. This variable is supported in all message fields.
{{learner_zip}} Provides the zip code of the learner. This variable is supported in all message fields.
{{learner_country}} Provides the country of the learner. This variable is supported in all message fields.
{{learner_custom}} Provides the custom field of the learner. This variable is supported in all message fields.
{{customer}} Provides the name of your account (not the learner).
{{customer_email}} Provides the email associated with your account (not the learner).
{{education_asset}} Provides an Education Asset. Place the variable in your custom content then select an Education Asset for the variable.

 

 

Training Notification Variables

The following variables may be used in AwareEd notification messages.

Variable Description Subject Email Body
{{training_link}} Provides a link to a page where the learner may take his/her training and view his/her progress against the entire course. This variable is REQUIRED in Enrollment and Reminder notifications. Note that links are uniquely generated for each learner and cannot be shared between learners. No Yes
{{days_since_start}} Provides the number of days since the campaign started. Example: “13”. No Yes
{{days_until_end}} Provides the number of days until the campaign ends. Example: “10”. No Yes
{{campaign}} Provides the name of the campaign. Example: “Customer Reps Training”. No Yes
{{course}} Provides the name of the course associated with the campaign. Example: “Popular Modules” No Yes
{{module_count}} Provides the number of modules in the course associated with the campaign. Example: “4” No Yes
{{learner}} Provides the first and last name of the learner with a space in between the names. Example: “John Smith”. Note: this value may be blank if this value was not configured. This variable is supported in all message fields. Yes
{{learner_first}} Provides the first and last name of the learner. Example: “John”. Note: this value may be blank if this value was not configured. This variable is supported in all message fields. Yes
{{learner_last}} Provides the first and last name of the learner. Example: “Smith”. Note: this value may be blank if this value was not configured. This variable is supported in all message fields. Yes
{{learner_email}} Provides the email address of the learner. Example: “jsmith@email.com”. This variable is supported in all message fields. Yes
{{learner_title}} Provides the title of the learner. This variable is supported in all message fields. Yes
{{learner_department}} Provides the department of the learner. This variable is supported in all message fields. Yes
{{learner_phone}} Provides the phone number of the learner. This variable is supported in all message fields. Yes
{{learner_address1}} Provides the address of the learner. This variable is supported in all message fields. Yes
{{learner_address2}} Provides the address of the learner. This variable is supported in all message fields. Yes
{{learner_city}} Provides the city of the learner. This variable is supported in all message fields. Yes
{{learner_state}} Provides the state of the learner. This variable is supported in all message fields. Yes
{{learner_zip}} Provides the zip code of the learner. This variable is supported in all message fields. Yes
{{learner_country}} Provides the country of the learner. This variable is supported in all message fields. Yes
{{learner_custom}} Provides the custom field of the learner. This variable is supported in all message fields. Yes
{{customer}} Provides the name of your account (not the learner). Yes
{{customer_email}} Provides the email associated with your account (not the learner). Yes

 

Sample Enrollment Email

Hello {{learner}} ({{learner_email}}),

You have been enrolled in computer-based Security Awareness Training!

To access your training, please follow this link: {{training_link}} Note that NO username and password is required. The course you are taking is called “{{course}}”, is being directed at “{{campaign}}”, and includes {{module_count}} interactive training modules. You have {{days_until_end}} to complete your training and you will be reminded to complete it every few days. For the best possible experience, you should plan on taking your training at a computer with audio, but closed captions are also provided if audio is not an option.

Thank you!

 

Sample Reminder to Start Notification

Hello {{learner}} ({{learner_email}}),

It’s time to start your computer-based Security Awareness Training! To begin your training, follow this link: {{training_link}}

(You have {{days_until_end}} to complete your training. For the best possible experience, you should plan on taking your training at a computer with audio, but closed captions are also provided if audio is not an option.)

 

Sample Reminder to Finish

Hello {{learner}} ({{learner_email}}),

This is just a reminder to complete your computer-based Security Awareness Training! To complete your training, follow this link: {{training_link}}

(You have {{days_until_end}} to complete your training. For the best possible experience, you should plan on taking your training at a computer with audio, but closed captions are also provided if audio is not an option.)

 

Sample Completion Notification

Congratulations {{learner}} ({{learner_email}})!

You have successfully completed your computer-based Security Awareness Training!

For your information, it took you {{days_since_start}} to complete all {{module_count}} modules in the “{{course}}” training course.

Please save or print a copy of this email for your records.