After a phishing campaign has been completed, it is time to give the obtained data to the customer. Furthermore, most customers need a grade in order to explain to their superiors how bad the results have been.
Thus, you must provide your customers with an objective result based on a comprehensive analysis of the phishing campaign's outcomes.
First, let's assign some values to the actions appearing on GoPhis.
Then, obtain the highest value achieved in a phishing campaign and obtain a set of intervals in which the grades will be divided.
The highest can be achieved with the following formula.
After that, assign the percentages of victims required to obtain a certain grade, as can be seen in this table:
Each value represents the maximum number of employees who must complete every action that makes up the phishing campaign to obtain the security level.
For example, a company with between 1,000 and 10,000 employees must have a maximum of 1% of employees completing all actions to be considered to have an excellent level of security.
After that, the intervals are determined using the following formula:
The value of the phishing campaign is calculated with the following formula:
Finally, you only have to relate the score to the interval to obtain the grade.
Because this explanation may have been a bit complicated to implement, I have prepared a spreadsheet for you to play around with.