Sophos Phish Threat: Managing Campaigns
Sophos Fusion (formerly Sophos Central) provides a single place to manage draft, scheduled, active, and past Phish Threat campaigns. A campaign’s status determines which actions are possible: you can edit a scheduled campaign directly, but you should pause a running campaign before changing it, and you cannot modify a campaign once it has ended.
Go to Meine Produkte > Phish Threat > Kampagnen. From there, you can search and filter campaigns, manage them throughout their lifecycle, and export data from an open campaign.
Finding campaigns quickly
Use the search bar to find a campaign by name. You can also narrow the list by campaign type:
- Alle Kampagnen shows all campaigns.
- Phishing shows simulated phishing attack campaigns.
- Diebstahl von Zugangsdaten shows campaigns for harvesting credentials.
- Anhang shows campaigns with simulated malicious attachments.
- Training shows training-only campaigns.
Campaign type and campaign status are different. The page also groups campaigns by lifecycle stage:
| Section | Meaning | Typical next action |
|---|---|---|
| Aktive Kampagnen | The campaign is already running. | Pause, review, edit if necessary, or resume. |
| Bevorstehende Kampagnen | The campaign starts at the configured time. | Check configuration and schedule before starting. |
| Vergangene Kampagnen | The campaign has ended or been completed. | Export, clone, or delete it; it can no longer be edited. |
| Kampagnenentwürfe | The creation has not yet been completed. | Fertigstellen or Verwerfen. |
A paused campaign has the label Pausiert next to its name. This distinguishes a deliberately suspended send from a campaign that is merely scheduled or has already ended.
Complete or discard drafts
An unfinished setup wizard appears under Kampagnenentwürfe. Select Fertigstellen to continue configuring it or Verwerfen to remove the draft.
Before discarding a draft, check whether it contains custom template changes, a substantial recipient selection, or an agreed schedule. Discarding is not the same as pausing: it removes the draft, which cannot then be resumed as a running campaign. To preserve its configuration, either complete the draft or document it first.
Remind administrators seven days before the start
Sophos can notify selected administrators seven days before a Phish Threat campaign starts. Configure the recipients of this administrative reminder globally:
- Open the Globale Einstellungen icon.
- Go to Produkte & Services > Sophos Phishing Threat > Kampagnenerinnerungen.
- Select the administrators who should receive a reminder seven days before a campaign starts.
This setting reminds administrators before the campaign start. It does not control training reminders to participants or the messages configured to users in a campaign.
After making a change, verify the selected administrator accounts and their current email addresses. Do not assume that Sophos will send a reminder retroactively for a campaign that starts in fewer than seven days.
Open a campaign and review the available actions
Open the desired campaign under Meine Produkte > Phish Threat > Kampagnen. Depending on the status, Bearbeiten, Löschen, Klonen, Anhalten, Fortsetzen, and Exportieren are available.
Edit campaign
You can edit an upcoming campaign before it starts. For a campaign that is already running, use this safer procedure:
- Open the active campaign and select Anhalten.
- Check that the campaign is marked as Pausiert.
- Select Bearbeiten. The setup wizard opens in edit mode.
- Adjust the required values in the wizard.
- Check the new configuration before selecting Fortsetzen.
You can change the settings of a paused campaign with two exceptions: Kampagnentyp and Kampagnen-Startdatum cannot be changed. You can add or remove recipients, but you cannot remove a recipient who has already been sent the campaign email.
Vergangene Kampagnen cannot be edited. Even a completed campaign cannot be extended with a new end date. If the same setup is needed again, the campaign is cloned and scheduled as a new campaign.
Clone campaign
Klonen copies the campaign details to a new entry under Kampagnenentwürfe. The clone’s name includes its creation date. Before activating the draft, review at least its name, recipients, templates, training, and start and end dates.
A clone is a new campaign, not a retroactive continuation of the original, so it does not include events that have already occurred. Cloning is the appropriate way to run a completed campaign again with a different schedule or recipient group.
Delete campaign
Open the campaign and select Löschen in the top right. Sophos also allows deletion for a completed campaign.
Pause and resume campaign
Anhalten interrupts the sending of still pending attack, training, and reminder emails. Emails that have already been delivered remain with the recipients. According to Sophos Help, actions taken on delivered emails continue to be recorded and updated in the campaign report. However, the Sophos FAQ gives conflicting information for campaigns that sent all emails immediately: it says that user actions and behavior are no longer updated after the campaign is paused. If this data is relevant to your decision, test the behavior with a test campaign in your own tenant first.
Pausing is particularly suitable when:
- Campaign emails are not delivered correctly and the mail server must be corrected first,
- a mistake in a template must be corrected,
- a different training lesson should be used,
- recipients must be added to the pending send.
If the campaign sent all emails immediately, pausing it afterward cannot recall those messages. With interval-based delivery, emails that have not yet been scheduled are not sent. For immediate delivery, also note the documentation conflict described above about subsequent event updates.
Before selecting Fortsetzen, check both the campaign and, if applicable, the corrected mail server. The campaign then becomes active again: remaining attack emails follow the established schedule, and the associated training and reminder emails are sent to the affected recipients.
Changes apply only where they still can
Changes to a paused campaign apply to the remainder of the campaign. They do not rewrite events that have already occurred.
- If user A has already received the old attack email, a new template does not replace this message. Only recipients who have not yet received an email receive the new version.
- If user A has already been assigned to training and the administrator subsequently replaces the training course, a training link opened later leads to the new course.
- Already sent emails and existing user events are not undone by pausing, editing, or resuming. Whether Sophos still records new actions on emails that have already been delivered after pausing is not consistently documented in the case of immediate sending.
This limitation should be included in every change plan. Before making a major change, document which recipients have already been contacted and which are still pending. Otherwise, the same campaign will contain an intentional mixture of old and new settings.
A separate administrative action is Kampagnen-Ereignisse löschen in the campaign results. This allows the events of a user to be removed from the results. E-Mail gesendet events remain; Sophos logs the deletion in Audit-Protokoll. This function does not change any sent message and is independent of pausing, editing, or resuming a campaign.
End campaign series
An active campaign series is opened and stopped with Diese Serie beenden. However, this does not necessarily prevent any already visible future campaign: In the Bevorstehende Kampagnen section, campaigns from the series may still appear if Sophos had already generated them before ending the series.
Therefore, always check Bevorstehende Kampagnen after ending a series. Such a single campaign can only be ended within the week before its scheduled date. Ending the series and ending already created individual campaigns are therefore two separate steps.
Export campaign data as PDF or CSV
Open the relevant campaign and select Exportieren. Sophos provides the campaign data as PDF or CSV.
For change documentation, the export is created before an irreversible deletion and saved with the campaign name, export date, and purpose. The CSV file is suitable for structured processing, while the PDF file provides an easily readable snapshot. Interpreting the campaign results themselves is outside the scope of this guide.
Validate the change and understand the rollback options
After each administrative action, check both the confirmation message and the campaign’s visible status:
- Return to Meine Produkte > Phish Threat > Kampagnen.
- Search for the campaign by its exact name.
- Check the correct section: draft, upcoming, active, or past.
- If the campaign was paused, check that it is marked Pausiert.
- Open the campaign and compare its schedule, recipients, template, and training with the approved change specification.
- Before Fortsetzen, check which recipients have already received an email and which change only applies to the remaining recipients.
- Also check Bevorstehende Kampagnen after ending a series.
- Open a generated PDF or CSV export as a test before the campaign is deleted.
The available rollback depends on the action:
- A paused campaign can be resumed after successful review.
- An active campaign can be paused again and corrected for the remaining duration.
- An incorrect change to content that has not yet been sent can be corrected by editing again.
- Pausing, editing, and resuming do not change already logged events. Through Kampagnen-Ereignisse löschen, user events can be deleted separately; E-Mail gesendet events remain and the process is logged in Audit-Protokoll.
- Deleted campaigns cannot be restored. An export serves as documentation but is not an importable backup.
- Completed campaigns cannot be extended or edited. As a replacement, a clone is created as a new campaign.
- A completed series is not reactivated as a rollback. Already generated upcoming individual campaigns must be checked separately and, if necessary, ended within the permissible time window.