Monitoraggio periodico della consapevolezza anti-phishing per team di sicurezza distribuiti, tramite Slack.

Nessun articolo trovato.
Blog immagine in miniatura

For the IT or security lead running an awareness program across a team that is rarely, if ever, logged into the same tool at the same time.

Most security awareness programs still run on an annual cycle: a mandatory module in the LMS, a completion certificate, a box checked before an audit, then eleven months of silence before the cycle repeats. If you run security for a distributed team, spread across time zones and home offices with no shared physical space to post a warning poster in, that once-a-year format is weaker than it looks on paper. People forget material they were tested on within weeks. The actual attack surface, a convincing invoice email, a spoofed calendar invite, a fake Slack DM claiming to be from “IT support,” does not wait for the next training cycle to show up.

The fix is not a longer course or a stricter pass threshold. It is moving part of the program into the tool the team already has open all day. A two-question pulse check dropped into a Slack channel takes under a minute to answer, requires no separate login, and, run often enough, keeps the material fresh in a way a single annual session structurally cannot.

Why the annual model breaks down for a distributed team

A once-a-year training session works reasonably well when a team sits in one office and a security lead can walk the floor, catch a conversation at the coffee machine, and get a read on who is confused about the latest phishing trend. None of that works when the team is spread across a dozen home offices and three time zones. The security lead loses the informal feedback loop entirely, and the only signal left is a quiz score from a session that happened months ago.

Compliance frameworks make this worse in a specific way. Most require documented, recurring security awareness activity, not a single annual event, but the tooling most IT teams already have (an LMS module, a slide deck, a PDF policy attachment) is built around the single-event model. Building a genuinely recurring program on top of that tooling usually means asking a distributed team to log into yet another platform on a schedule nobody remembers, which is exactly the kind of friction that gets a program abandoned after two quarters.

What the research says about recurring training

The scale of the problem is not in doubt. Verizon’s 2025 Data Breach Investigations Report found that around 60 percent of breaches still involve a human element, someone clicking, replying, or handing over a credential, and that the median time for a person to click a phishing link is under a minute. The exposure is real, it is fast, and no filter catches all of it, so what your team does in the moment still matters.

The more useful question is whether training actually changes that behaviour, and here the largest real-world dataset is encouraging. KnowBe4’s 2025 Phishing by Industry Benchmarking Report tracked 14.5 million people across 62,400 organisations through 67.7 million simulated phishing tests. Before any training, an average of 33.1 percent of employees, one in three, fell for a simulated phish. Within 90 days of starting regular training that dropped by more than 40 percent, and after a full year of ongoing training it fell to 4.1 percent, an 86 percent reduction.

Bar chart showing the share of employees who fell for a phishing test falling from 33.1 percent before training to 4.1 percent after a year of ongoing training, an 86 percent drop. Source: KnowBe4 2025 Phishing by Industry Benchmarking Report.

The shape of that curve is the whole argument. The improvement is not a single step from one annual session; it accumulates over months of repeated, spaced exposure. A one-off module moves the number once; sustained, repeated training is what takes a third of your team down to roughly one in twenty-five. That is the case for making awareness a recurring habit rather than a yearly event, and for running it somewhere the team already is.

AhaSlides for Slack: pulse checks where the team already is

AhaSlides for Slack is rolling out on the AhaSlides marketplace as an integration that lets you post interactive slides directly into a Slack channel or DM, no separate meeting or login required. It is not yet on the main ahaslides.com integrations page; it is still in its rollout phase, and for now it supports two slide types: Pick Answer (a scored quiz slide) and Poll. Word Cloud, Q&A, and the other interactive slide types are not part of the Slack integration today, so keep those for your live sessions and standalone AhaSlides presentations, not the Slack workflow.

For a phishing pulse check, that two-slide-type scope is enough to do real work. A Pick Answer slide posted to a channel might read:

  • You get a Slack DM from someone claiming to be your IT admin, asking you to reset your password through a link they’ve shared. What’s the first thing you check before clicking?
  • An invoice email arrives from a vendor you work with, but the reply-to address is one character off from their real domain. Is this a legitimate, cautious, or clearly malicious email?
  • A calendar invite from “HR” asks you to confirm your direct deposit details through an embedded link. What’s the correct move?
A phishing-awareness Pick Answer quiz running as a live AhaSlides slide

Each option scores automatically, and the right answer can be revealed in the thread right after someone commits to a guess, which is the retrieval-then-correction pattern that makes a correction actually stick. A Poll slide works well for the lower-stakes, more diagnostic questions: “How confident are you that you’d catch a spoofed sender address in a rush?” or “Have you gotten a suspicious Slack DM in the last month?” Polls do not have a right answer, but they surface where confidence is low, which tells you exactly where to point the next Pick Answer round.

A phishing-awareness Pick Answer pulse check posted into a Slack channel by the AhaSlides for Slack app, with a tap-to-answer button beside each option.

Because the integration lives inside Slack, a pulse check does not compete with a separate LMS login for anyone’s attention. It shows up in the channel someone is already reading, gets answered in the time it takes to read the question, and does not require scheduling a session across three time zones. You can add it to your workspace from the AhaSlides Slack app page.

Pick Answer: rehearsing judgment in a live session

The Slack pulse check catches people in the flow of their normal day, but it is deliberately short and asynchronous: one question, answered alone, with no discussion. A live monthly security review is a different setting. The team is on a call together, so a Pick Answer round can run as a short sequence of scenario questions back to back, with the group’s answer distribution shown after each one and a minute spent talking through why the wrong options were tempting.

That group visibility is what the Slack version cannot do on its own. When two-thirds of the room picks the same wrong answer, the security lead running the session sees it immediately and can dig into why on the spot, instead of finding out from a report three days later. Scenario-based questions get more out of this format than plain definition-style ones:

  • Marketing gets an email from a lookalike domain asking to expedite an invoice payment before end of day, using the CFO’s actual name. What should the person who received it check first, before replying?
  • A contractor calls IT support asking for a password reset instead of filing the usual ticket, and gives a plausible reason for the urgency. Is this normal, worth verifying, or a red flag?
  • A colleague forwards a Slack DM that looks like it came from internal IT support, asking them to confirm their login through an external link. What is the fastest way to check if it is real?

Space these questions out through the session rather than running them back to back, and use the pause after each one for discussion, not just the correct answer. That conversation, tied to a scenario the group just answered together, is what a live Pick Answer round adds on top of the async Slack version instead of repeating it.

Analytics and Reports: the evidence a CISO or auditor wants

At some point, someone on the compliance or leadership side is going to ask how you know the program is working, and “people completed the annual module” is not a satisfying answer. AhaSlides records individual responses to quiz and poll slides and produces reports on how each person and the group performed, which does two things worth building a program around.

First, it is documentation: a report showing who was asked what, and how they answered, holds up to an audit question about recurring, documented security awareness activity in a way a spreadsheet of completion dates does not. Second, it is a diagnostic. If a third of the team misses the same scenario in a Pick Answer pulse check, that is not a result to file away. It is the exact topic for next week’s follow-up, and it is the kind of department-level or team-level pattern that a single annual test, run once and forgotten, would never catch.

A practical flow for a distributed security org

  1. Post a short Pick Answer or Poll pulse check in Slack every one to two weeks, built from real (redacted) attempts your team has seen, not generic textbook scenarios.
  2. Run a monthly live session with a scenario-based Pick Answer sequence, showing the group’s answer distribution after each question so the team can talk through why the wrong options were tempting.
  3. Pull the Analytics report after each round and look for a shared miss, a pattern across a team or region, not just an individual score.
  4. Build the next Slack pulse check directly from that miss, so the second touchpoint lands within two to three weeks of the gap showing up, matching the sustained, spaced reinforcement that KnowBe4’s data links to an 86 percent drop over a year.
  5. Keep a short record of each round’s report for whoever owns the compliance relationship, so “documented, recurring security awareness training” is a folder of real data, not a single certificate from January.

What to change this quarter

A single annual training module is not wrong so much as incomplete. It teaches the material once, tests it once, and then trusts that the lesson holds for a year on a team that is never in the same room to reinforce it informally. The largest real-world dataset says the opposite: susceptibility falls steadily with repeated, spaced training, more than 40 percent in the first 90 days and 86 percent over a year, not with a single annual session. Move part of the program into Slack, where the team already spends its day, keep the questions built from real incidents instead of generic examples, and use the reports to decide what to ask next. That is a smaller, more frequent program than most teams are running today, and the research suggests it is also a more effective one.

Iscriviti per ricevere suggerimenti, approfondimenti e strategie per aumentare il coinvolgimento del pubblico.
Grazie! La tua richiesta è stata ricevuta!
Oops! Si è verificato un errore durante l'invio del modulo.

Dai un'occhiata agli altri post

AhaSlides è utilizzato dalle 500 migliori aziende americane secondo Forbes. Scopri oggi stesso il potere dell'engagement.

Inizia gratuitamente
© 2026 AhaSlides Pte Ltd