Skip to content
Avanet

Sophos Phish Threat: Create and Plan Campaign Series Safely

With a campaign series, Sophos Phish Threat runs attack simulations or security training repeatedly on a fixed schedule. A series is not simply one long-running campaign: Sophos creates separate campaigns whose content and participants depend on the series type and the selected settings.

Configure the series in Sophos Fusion (formerly Sophos Central) under My Products > Phish Threat > Campaigns by selecting New Series.

Requirements

The licence, administrative access, and verified recipient domains must be set up in advance. Sophos Phish Threat: Getting Started describes these basic requirements. A verified domain alone does not guarantee successful delivery: configure mail flow for your platform using Phish Threat for Microsoft 365 or Phish Threat for Google Workspace, and also check Phish Threat sender allowlisting.

Test delivery with a controlled internal mailbox before creating a series for the final target audience. Create a Sophos Phish Threat Campaign explains how to create a separate, standalone campaign.

Set series type before configuration

Under Get Started enter the campaign name and choose one of the two series types:

Series TypePurposeImportant Follow-up
Simulated attack seriesTest users repeatedly with simulated attacksAttack type, difficulty, and optional follow-up training are defined as series rules
Security training seriesEnrol users repeatedly in mandatory trainingOne or more training courses and their passing thresholds are scheduled

The series type determines the subsequent pages of the wizard. Therefore, decide in advance whether the primary goal is to measure user behaviour or to implement a mandatory training plan.

Then select the frequency and the language for emails and training materials, and click Next. The language must suit the attack template, training content, and target audience; the administrator account language is irrelevant.

Configure simulated attack series

Three types of attacks are available under Series preferences:

  • Phishing prompts users to click a link in an email.
  • Credential Harvesting leads to a fake website and requests the entry of login credentials. Sophos does not capture passwords in the process.
  • Attachment entices users to open a simulated malicious email attachment.

You can select multiple attack types. To keep the process predictable, however, use one attack type per series. If you select multiple types, Sophos randomly chooses one for each campaign generated from the series. For a quarterly series, for example, it makes a new random choice each quarter. This multiple selection does not create a fixed rotation.

Then set the difficulty level and decide whether users who fall for the simulation should be enrolled in training. By default, Sophos assigns training that matches the selected attacks. If you use follow-up training, also set the passing threshold; the default is 80 %.

Examine two different success metrics separately:

  1. The attack simulation measures whether the user responded to the simulation.
  2. The passing threshold determines whether the subsequent training was successfully completed.

After checking, click on Next.

Configure a security training series

Under Series selections, open a course to check its brief summary. With Choose this training, add it to the series. Multiple training courses can be selected.

If you select multiple courses, check that every course suits the target audience. Under Review & Schedule, set the passing threshold for each course. The default is also 80 %; click Next to move to the passing threshold for the next course.

Recipients and automatic enrolment

Under Enroll Users, select the desired Users or Groups. Activate Auto-enroll new users to this series only if users later created in Sophos Fusion should be added to the series without any further approval.

Automatic enrolment behaves differently depending on the series:

  • In a simulated attack series, new users are added to the next campaign generated by the series. They are not added retrospectively to campaigns that have already started.
  • In a Security training series, Sophos adds new users to every training campaign in the series; they start with the first campaign. If the training series contains a sequence of courses, each newly enrolled user begins with the first course.
  • Delivery continues to follow the series schedule and does not necessarily begin on the enrolment date. If a monthly training course begins on the 1st of a month and a user is enrolled on the 15th, they will not receive the first training email until the 1st of the following month. The subsequent courses shift accordingly for that user.

The differences from standalone campaigns and other series types are explained in Automatic Enrolment in Phish Threat.

Verified domains and administrative units

Simulated phishing emails may only be sent to addresses in domains that belong to the company and have been verified in Sophos Fusion.

  • If the user selection contains addresses from unverified domains, Enroll Users displays a warning.
  • If a group contains both verified and unverified addresses, Sophos only takes the addresses from verified domains and also displays a warning.
  • Use Verify domains in the warning to go to verification. After completion, return to campaign creation via Phish Threat.
  • In Sophos Central Enterprise, the domain must be added and verified separately in each affected sub-estate. Verification in another sub-estate is not sufficient.

For a mixed group, do not proceed with only the eligible addresses without checking them. Otherwise, the series may start without an error but fail to reach the intended audience.

Check and plan

After Next, open the step Review & Schedule. Check each section and use Edit before saving the series.

For a simulated attack series, specify under End Series either the number of months or When I cancel. User actions after the end date will no longer be considered in the campaign results. Therefore, plan enough time for reactions and any follow-up training. When I cancel is not an automatic end condition; the series continues until it is manually ended.

For a training series, set the series start and the passing threshold. For multiple trainings, each course is checked individually. Complete the wizard with Done only after confirming that the series type, frequency, language, content, recipients, and schedule are correct.

Phased delivery is not available during creation

A Sending Increment cannot be set while creating the campaign series. Phased delivery can only be configured after saving, by editing the series before it starts.

In the process, you determine:

  • the percentage of users per delivery phase,
  • the interval between phases,
  • and based on the displayed estimate, how many days the full delivery will take.

This sequence is important: first save the series with Done, then edit it again before launch and configure the delivery stages. Do not start the series manually until this second check is complete. For monthly series, also check the automatically generated campaign during the limited window under Upcoming Campaigns.

Validation before the first production launch

Use a documented checklist for approval:

  1. Series type: Does the series match the goal – attack simulation or mandatory training?
  2. Rhythm: Are frequency, first start, and desired series end correct?
  3. Language: Do the email and training language match the target audience?
  4. Attack: Is only the intended attack type selected, or is the random selection of multiple types explicitly desired?
  5. Training: Do course assignment and passing threshold match for each course?
  6. Recipients: Do the number of users and groups match the approved scope? Have warnings about omitted addresses been clarified?
  7. Domains: Are all recipient domains verified in the correct administrative unit?
  8. Automatic enrolment: Is the inclusion of users created in Sophos Fusion in the future intentional and approved by the organisation?
  9. Delivery stages: Was the saved series edited again before starting, and was the expected total duration checked?
  10. Upcoming Campaign: Do the content and recipients of the first campaign generated from the series match the plan?

Test new templates, recipient sources, or mail flow settings in a separate standalone campaign or pilot series with a small internal target audience. Check the delivered message, landing page, event tracking, and, if applicable, training assignment. Then recreate the production series with the final recipient selection after checking it again. Do not plan to switch the target audience of an already saved series from the pilot group to the production group.

Stop the series and limit the impact

Until you complete the wizard with Done, you can correct its pages. An incomplete entry appears under Campaign Drafts; continue it with Finish or remove it with Discard. After saving, phased delivery can be edited before launch; do not assume that other series options can be changed later. For monthly series, the generated individual campaign can be adjusted during the week under Upcoming Campaigns.

To end an active series, open the campaign series and select End this series. This does not automatically end campaigns already generated from it: they may remain under Upcoming Campaigns. Each such campaign can only be ended from one week before its scheduled date. Therefore, check this area even after ending the series.

If a single campaign is already running and further sending should only be temporarily stopped, use Pause. Then attack, training, and reminder emails will no longer be sent to the remaining users; messages already delivered will not be recalled. While paused, the campaign can be edited with Edit; Campaign Type and Campaign Start Date remain unchangeable, and a recipient with an email already sent can no longer be removed.

Once messages have been sent, there is no technical way to recall emails that have already been delivered. Changes after Resume apply to the remainder of the campaign and do not alter past events. If the series has a defined end date, later user actions are simply excluded from the campaign results.

In the event of a misconfiguration, the following applies:

  1. Do not manually start an upcoming campaign that has not yet started.
  2. For a series that has not yet started, if necessary, correct only the documented editable setting for phased delivery; do not assume that recipients and automatic enrolment can be changed later.
  3. Stop an ongoing individual campaign with Pause and correct the values that can still be changed.
  4. End an active series that is no longer needed via End this series and then separately check already generated upcoming campaigns.
  5. Document already sent messages and recorded events as the existing state.
  6. Validate corrections first with internal recipients and only then select Resume or reschedule.

The safe rollback limit is therefore before sending to the respective recipient. After that, Pause and End this series only limit future processes; simulations already delivered and past events are not undone. Further actions for checking status, editing, and ending campaigns are described in Managing Phish Threat Campaigns.