Programa Continuo de Phishing SimuladoContinuous Simulated Phishing Programme
Campañas periódicas con métricas por área y refuerzo dirigido.Recurring campaigns with metrics by business unit and targeted reinforcement.
¿Qué es este servicio?What is this service?
Es un programa de campañas periódicas de correo simulado a lo largo del año, con dificultad creciente, segmentado por área y con formación inmediata para quien cae. No es una campaña suelta para asustar a la gente: es una serie con línea base, medición y refuerzo dirigido.
A programme of periodic simulated email campaigns across the year, with rising difficulty, segmented by area and with immediate training for whoever falls for it. It is not a one-off campaign to scare people: it is a series with a baseline, measurement and targeted reinforcement.
¿Para qué se usa?What is it used for?
Sirve para medir y entrenar la reacción real ante un correo fraudulento, no la que la gente declara en una encuesta. Y conviene señalar la parte que casi nadie dice: la métrica que importa es la tasa de reporte, no la de clic. Que el clic baje del veinte al diez por ciento significa poco si nadie avisa; una plantilla que reporta rápido le da al equipo de seguridad los minutos que deciden el incidente.
It measures and trains the real reaction to a fraudulent email, not the one people declare in a survey. And here is the part almost nobody says: the metric that matters is the reporting rate, not the click rate. Clicks dropping from twenty to ten per cent means little if nobody speaks up; a workforce that reports quickly gives the security team the minutes that decide the incident.
Qué beneficios traeBenefits it delivers
- Da una medición objetiva y repetible de un riesgo que de otra forma solo se estima.
- La formación en el momento del clic se recuerda mucho más que un curso desconectado del error.
- La segmentación revela qué áreas y qué roles concentran el riesgo, que casi nunca son los que la dirección supone.
- Sube la tasa de reporte, que es lo que acorta el tiempo de detección de una campaña real.
- Gives an objective, repeatable measurement of a risk that is otherwise only estimated.
- Training delivered at the moment of the click is remembered far better than a course disconnected from the mistake.
- Segmentation reveals which areas and roles concentrate the risk, rarely the ones management assumes.
- Raises the reporting rate, which is what shortens detection time in a real campaign.
¿En qué momentos es obligatorio?When is it mandatory?
Costa RicaCosta Rica
- No hay obligación legal de hacer simulacros de phishing en Costa Rica.
- Conviene atender el otro lado: la campaña trata datos de empleados identificados, así que entra en el ámbito de la Ley 8968 y de la vigilancia de PRODHAB. Hay reforma en trámite, el proyecto 23097, pero no está aprobada.
- Por eso el programa se define con recursos humanos y con legal antes de lanzar la primera campaña, y los resultados individuales no se usan para sancionar ni para evaluación de desempeño.
- There is no legal obligation to run phishing simulations in Costa Rica.
- The other side deserves attention: the campaign processes data on identified employees, so it falls under Law 8968 and PRODHAB oversight. A reform is in progress, bill 23097, but it has not been approved.
- That is why the programme is defined with HR and legal before the first campaign goes out, and individual results are not used for sanctions or performance reviews.
InternacionalInternational
- Ni PCI-DSS ni ISO 27001 exigen simulacros de phishing. Lo que exigen es un programa de concienciación; el simulacro es una forma de darlo y de medirlo, no un requisito en sí.
- PCI-DSS sí pide que la concienciación cubra específicamente la ingeniería social y las amenazas emergentes.
- En Europa, tratar resultados individuales de empleados obliga a base legal, información previa y minimización bajo el reglamento de protección de datos.
- Neither PCI-DSS nor ISO 27001 requires phishing simulations. What they require is an awareness programme; the simulation is one way of delivering and measuring it, not a requirement in itself.
- PCI-DSS does ask that awareness specifically covers social engineering and emerging threats.
- In Europe, processing individual employee results demands a legal basis, prior information and data minimisation under data protection law.
Requisitos mínimosMinimum requirements
- Aprobación formal de dirección, recursos humanos y legal, con acuerdo escrito sobre qué se mide y qué no.
- Comunicación previa a la plantilla de que el programa existe, sin decir cuándo llega cada campaña.
- Permitir el correo simulado en las plataformas de filtrado y tener un botón de reporte funcionando, porque sin él no hay tasa de reporte que medir.
- Un compromiso explícito de no punición: en cuanto la gente cree que el resultado la perjudica, deja de reportar y el programa se vuelve inútil.
- Formal approval from management, HR and legal, with written agreement on what is measured and what is not.
- Prior communication to staff that the programme exists, without disclosing when each campaign lands.
- Allow-listing the simulated mail in the filtering platforms and a working report button, because without it there is no reporting rate to measure.
- An explicit no-punishment commitment: the moment people believe results can harm them, they stop reporting and the programme becomes useless.
Plazo típico de entregaTypical delivery time
Se contrata por doce meses con una cadencia habitual de una campaña mensual o trimestral. La preparación inicial toma de dos a cuatro semanas: acuerdo con recursos humanos y legal, segmentación, plantillas y ajustes técnicos en el correo. La primera campaña es solo línea base; la tendencia útil aparece a partir de la tercera o cuarta.
It is contracted for twelve months with a usual cadence of one campaign per month or per quarter. Initial preparation takes two to four weeks: agreement with HR and legal, segmentation, templates and technical adjustments to the mail platform. The first campaign is only a baseline; the useful trend appears from the third or fourth onward.
NomenclaturaTerminology
Las siglas y estándares que aparecen en esta ficha, explicados. The acronyms and standards used on this page, explained.