Skip to content
Avanet

Sophos Phish Threat: Data protection and governance

Sophos Phish Threat processes data about identifiable people during simulations and training, including recipient and campaign assignments, delivery and response events, and training status. This data is useful for an awareness program, but it must not be evaluated without a defined purpose, authorized access, and a managed lifecycle.

This runbook describes a controlled internal process; it does not provide legal advice. The appropriate internal teams determine which legal basis, consultation rights, information obligations, and retention periods apply to their organization. A campaign being technically possible does not mean it has received operational or legal approval.

Define the governance objective

Before the first campaign, the responsible owner approves a brief operating plan. It answers at least the following questions:

  • What specific awareness or training goal does the program pursue?
  • Which employees, external persons or organizational units are in the scope and which are expressly not?
  • Which responses and training statuses are needed, and which data will deliberately not be used?
  • Who can create and approve campaigns, or view, export or delete person-level results?
  • How will participants be informed and who can they contact if they have questions?
  • How long are local exports, tickets and other copies required?
  • What happens if messages are sent to the wrong recipients, complaints are received, real secrets are entered, or a genuine security incident is suspected?
  • How are entry, role changes, extended absences and departures taken into account?

The approved purpose is formulated so narrowly that every campaign and every evaluation can be checked against it. “Improve security” alone is too vague. A verifiable goal would be to train the secure reporting of suspicious emails in a defined target group without using individual results as isolated proof of performance.

Clarify responsibilities and provider role

The organization decides on the purpose, target group, campaign content, evaluation and internal reuse. These decisions may not be delegated to Sophos Fusion. The Sophos contractual documents also distinguish between processing on behalf of the customer and Sophos’ own processing activities. Therefore, the Data Processing Addendum applicable to the tenant, the current Sophos Group Privacy Notice and the product-specific data protection information are checked together with the contract and License Schedule.

The teams responsible for contracts and data protection document in particular:

  • which parties and services are covered by the contract;
  • which instructions, types of data, groups of people affected and purposes of processing apply;
  • which technical and organizational measures are promised and how they will be checked;
  • how sub-processors and international transfers are treated;
  • what support is provided for inquiries, security incidents and audits;
  • which rules apply for return or deletion after the end of the contract.

The review does not replace the organization’s own legal assessment. Contract version, tenant, data region and products used are documented together; a general Sophos website does not prove which agreement applies to a specific customer.

Plan roles with separation of duties

A practical model separates program ownership, technical implementation, and analysis of person-level results:

roleTaskNot automatically included
Program ownerResponsible for purpose, target group, metrics, budget and reviewSophos Fusion administration or access to individual results
Responsible data protection, legal, HR, or employee-representation teamsConduct the review and consultation process required by internal rulesTechnical campaign configuration
Campaign operatorConfigure, test, start, and stop an approved campaignUnilateral changes to purpose, scope, or escalation rules
Results reviewerEvaluate reports for the approved purpose and document follow-up actionsGeneral distribution of raw data or rankings
Sophos Fusion AdministratorManage identities, roles and technical accesssubstantive decision about personal consequences
Helpdesk or incident ownerHandle delivery errors, misdirected messages, and security reportsRoutine behavioral assessment of all participants

In Sophos Fusion, the predefined roles Help Desk and Read-only with a Phish Threat license see users, campaigns, series, results and reports. Read-only therefore does not mean “without access to personal results”. Help Desk is also not automatically suitable minimum access. Roles are assigned according to Assign Sophos Fusion administrator roles correctly and checked with a test account.

For particularly sensitive results, the review covers not only whether an account can make changes, but also whether it can see campaigns, reports, sensitive logs and exports. At least two responsible people provide a route for administrative recovery; shared administrator accounts are avoided.

Minimize data

A data matrix is created in advance for each campaign:

Data areaTypical purposeMinimization
Name, work email address, groupDelivery and target group mappingUse only approved business identities and necessary groups
Campaign and training assignmentImplementation of the approved scenarioassign only appropriate language, content and required training
Delivery statusDistinguish errors from behaviorPending, Failed and Blocklisted should not be considered a user response
Open, report, click, simulated credential entry, or attachment actionAssess the effect of awareness trainingEvaluate only the event types needed; record context and measurement limitations
Start and end of trainingtrack required traininguse only for the specified period and purpose
PDF/CSV Exportapproved evidence or limited analysisExport only the view you need, store it safely and delete copies

Templates contain no real secrets, real customer cases, or unnecessary personal details. Campaign names and internal notes are also chosen so as not to reveal health information, human resources procedures, or other unnecessarily sensitive information. Productive passwords, tokens and full tracking links do not belong in tickets or in normal evaluations.

The key figure Entered Credentials describes an event in a simulated Credential Harvesting campaign. It cannot be presented as evidence that a real account has been compromised. Likewise, Email opened is not the same as a click, and incomplete training does not prove refusal.

Control target groups and exclusions

The target group is not checked only at the final wizard step. The business owner provides an approved target list or clearly defined group; the operator matches it with the actual selection under Enroll Users.

Before each start, at least these cases are checked:

  • people who have left, whose accounts are blocked, or who have not yet joined;
  • longer absences, if they are to be excluded or postponed according to the internal process;
  • shared mailboxes, distribution lists, service and technical accounts;
  • external people, suppliers and partners outside the approved scope;
  • specially supervised groups where the content or timing needs to be adjusted;
  • test, duplicate, and outdated directory objects;
  • Individuals who do not participate due to a documented exception process.

Exclusions are justified, time-limited and assigned to an owner. They may not be kept as a permanently unchecked shadow list. The authoritative identity source and group membership are checked before sending; manually maintained parallel records are avoided. The Sophos Fusion user lifecycle is described in Manage users and groups in Sophos Fusion.

Auto-enroll new users to this campaign or Auto-enroll new users to this series extends the scope to users newly added to Sophos Fusion. The option is not a department filter. It is only used if continuous enrollment is expressly approved and the onboarding process excludes ineligible accounts in time. For details, see Automatically enroll new users.

Communication and fair implementation

A communication plan is approved before regular operation. It explains in an appropriate form the purpose, those responsible, the categories of data generally processed, the intended evaluation, contact points and the handling of results. Whether an organization announces specific dates or scenarios in advance is an internal decision; a surprise effect does not justify conducting the entire process secretly or without a contact person.

The following guidelines also apply to each campaign:

  • Content and language suit the target group and avoid unnecessary fear, embarrassment or reference to particularly stressful personal situations.
  • The simulation never asks for real payments, the sharing of real secrets or dangerous actions.
  • Helpdesk and Security Operations know the campaign windows and escalation path without receiving broader access to results than necessary.
  • A resolution or training communication explains the desired safe behavior and a real reporting path.
  • Complaints and requests for information, corrections or deletion are not improvised, but rather passed on to the internally defined process.

Approval before launch

A campaign may go live only after a documented two-person review. The approval covers:

  1. Check the correct tenant and a valid Phish Threat license;
  2. confirm the purpose, owner, internal approval, and any required consultation;
  3. check the target group, exclusions, language, template, training, and start and end dates;
  4. test verified domains and delivery route with a small approved pilot group;
  5. test access to results and export permissions with the intended roles;
  6. confirm the helpdesk, incident, and communication channels;
  7. establish local retention and deletion rules for exports and accompanying documentation;
  8. only then complete Review and Schedule in the wizard.

License planning belongs to the same control: Phish Threat counts unique recipients as soon as a campaign or training email is sent. Deleting or terminating does not retroactively remove such use. The counting model is described in How is Sophos Fusion licensed?.

Limit and correctly interpret results

The evaluation is started via My Products > Phish Threat. Individual campaigns are opened under My Products > Phish Threat > Campaigns; cross-campaign views are under My Products > Phish Threat > Reports > User Behavior and Reports > Training.

The result owner determines in advance which level is intended for which recipients:

  • aggregate trends for program control and management;
  • personal detail events only for explicitly authorized reviewers;
  • technical delivery information for operations or help desk;
  • limited follow-up training and security awareness;
  • HR or managers only according to the approved internal procedure, not automatically with every hit.

Individual results are never interpreted without considering delivery status, time window, campaign type, and technical measurement limits. Email security features can preload images or check links; absences and delivery problems can distort training statuses. The detailed data record is therefore checked before any personal follow-up measures are taken. The complete procedure is available at Sophos Phish Threat Evaluate results and reports.

Export to CSV, Export to PDF and campaign-related Export create additional data copies outside the portal view. Before exporting, the purpose, filter, period and recipient group are confirmed. The file, storage location, owner, access and deletion date are then registered. Exports are not distributed unprotected via email and are not copied to personal cloud storage or uncontrolled tickets.

Control retention and deletion without asserting an undocumented period

The Sophos features documented here do not specify a general retention period for all phish threat campaign, event and reporting data. Therefore, no product deadline is invented and an internal deadline is not presented as an automatic Sophos deletion.

The organization instead maintains a data registry with separate rules for:

  • Data still visible in the Sophos Fusion tenant;
  • downloaded CSV and PDF files;
  • Approvals, evaluations, presentations and tickets;
  • audit and incident documents;
  • Backups or downstream systems, if such copies actually exist.

A retention period is set by the responsible owner based on the approved purpose and the applicable requirements. At the end of that period, every controllable copy is deleted in the intended system and completion is documented. If an expected portal deletion or contractual return cannot be independently verified, it is not claimed but is clarified with Sophos or the contractual partner.

Clear campaign events can delete a user’s events from campaign results. Email sent is retained and the action is logged in Audit Log. The feature is therefore neither a complete user deletion nor evidence that all copies have been removed from Sophos or local exports. Before the action, authorization, scope, required preservation of evidence and remaining copies are checked.

Handle incidents and misdirected messages

A governance incident occurs, for example, when an unapproved target group is contacted, inappropriate content is sent, results are disclosed without authorization, or a recipient enters a real secret into a simulation flow. Then the following applies:

  1. Open the campaign under My Products > Phish Threat > Campaigns and stop the pending delivery with Pause if the action is available.
  2. Minimally document the time, campaign ID, recipient group, messages already sent and known exports.
  3. Inform program, security, data protection and, if necessary, other internally designated incident owners.
  4. limit access and sharing; do not copy real passwords or tokens into case documentation.
  5. If real credentials could be affected, trigger the normal account and security incident process. A phish threat event is not a substitute for real account investigation.
  6. Have the responsible teams decide on any required notification, preservation of evidence, and further measures.
  7. Only then can you specifically correct or delete data and take every remaining copy into account.
  8. Correct the cause, repeat the pilot, and obtain fresh approval before continuing.

Pause does not recall messages that have already been delivered. Events and license usage that have already been recorded do not disappear as a result. After pausing, check any remaining send intervals and any upcoming campaigns that may already have been created.

Offboarding and the data-subject request process

When someone leaves, first disable the account in the authoritative directory source or remove it from the synchronization scope. Running campaigns, series, groups, result access, local exports and administrative roles are then checked. Simply removing a person from a campaign is not a complete offboarding.

If a user was enrolled in a phish threat campaign within the last 30 days, they may appear again under Users & Groups after deletion. Before permanent deletion from Sophos Fusion, Last Targeted and Last Enrolled are checked and the 30-day window is allowed to elapse. The process then follows Safely delete and offboard Sophos Fusion users. Deleting a Sophos Fusion user does not prove that previously exported reports, tickets or other local copies have been deleted; these are tracked separately.

Requests from data subjects are coordinated through the internally designated data protection or HR process. The campaign operator does not decide alone which data is disclosed, corrected, restricted or deleted. Instead, the operator provides the responsible team with a traceable account of the tenant, campaign, period, visible events, exports and changes already made.

Validate operations and check regularly

After each campaign, at least the following points are validated:

  • The target and actual recipient lists, including exclusions, match;
  • Delivery Status distinguishes delivered messages from Pending, Failed and Blocklisted messages;
  • a sample in By User agrees with aggregate statements;
  • Results access works for authorized test accounts and is denied to unauthorized accounts;
  • Every CSV/PDF export has an owner, purpose, storage location and deletion date;
  • Incidents, complaints and exceptions have status and responsibility;
  • Follow-up actions correspond to the approved purpose and do not produce unfounded rankings;
  • Campaign end, ongoing series and automatic registration are in the expected state.

As an operational recommendation, not as a schedule prescribed by Sophos, the scope is approved before each campaign, ongoing campaigns, series, exports and open incidents are checked monthly, roles and personal result access are recertified quarterly and the operating concept, contract, data protection information, data region, sub-processors, deletion rules and communication documents are checked at least annually. An unscheduled inspection is carried out after product, contract, organizational or legal changes as well as after every incident.

The review does not end with a checklist. Deviations receive the owner, deadline and success criterion. If a statement regarding storage, deletion, transmission or role impact cannot be verified in your own tenant, it remains documented as an open question and will be clarified before the next affected campaign.

Frequently asked questions

Can Read-only see personal phish threat results?

Yes. The predefined Sophos Fusion role Read-only can see users, campaigns, series, results and reports with a Phish Threat license. The role name alone is therefore not a sufficient access restriction.

What general retention period does Sophos Phish Threat have?

The product features evaluated do not demonstrate a consistent deadline for all campaign, event and reporting data. Internal exports receive an approved deadline of their own; contractual or product-related deletions are clarified using the documents applicable to the tenant or directly with Sophos.

Does Clear campaign events delete all of a user's data?

No. Email sent remains in the campaign results and the action appears in Audit Log. The user object, local exports and other copies must be handled separately.