Trois-Rivières, serving all of Quebec 450 231-3836 info@oktosolutions.ca
FR

Sorel-Tracy

IT services in Sorel-Tracy: drilling employees before the next fake email

The filter stops most phishing messages. The one that gets through lands in front of a person, on a busy morning, between two calls. What that person does in the next few seconds depends on no software at all. OKTO Solutions offers SMBs in Sorel-Tracy phishing simulations and awareness training, from Trois-Rivières, about 70 km away.

Advisor in front of a whiteboard with drawings of a shield, a padlock, computers and a team in a circle

OKTO Solutions offers SMBs in Sorel-Tracy employee awareness through four phishing simulations a year, included in its vCIO module. Each campaign tracks the click rate and the reporting rate, then awareness training is aimed where the results call for it. Nobody is named publicly. OKTO’s office is in Trois-Rivières, about 70 km away.

Who trains the staff of a Sorel-Tracy business to spot a phishing email?

In Sorel-Tracy, a small business can hand employee security awareness to OKTO Solutions, which offers its services from Trois-Rivières, about 70 km away. The method is the phishing simulation: a harmless fake phishing email sent to staff to see who clicks and who reports it. OKTO’s vCIO module includes four of them a year, one per quarter, at all three of its levels. Each campaign tracks two measures over time, the click rate and the reporting rate, with scenarios adapted to the company’s sector and its real ways of working. The results are used to aim awareness training where it is lacking, never to name a person publicly. They are recorded in the file, which helps in front of an insurer or a demanding customer. The module is taken with a managed IT services plan, and it needs at least ten workstations or servers. OKTO has neither an office nor a technician stationed in Sorel-Tracy.

The numbers

What does a phishing simulation measure?

Two things, and the second matters more than the first. The click rate says how many people opened the link in the fake message. The reporting rate says how many recognized it and flagged it. A team that does not click but says nothing leaves the co-worker at the next desk alone with the same email.

A stand-alone campaign measures a single day. That day, accounting was closing the month, or half the office was on vacation. Four campaigns spread over the year give you something else: a trend. Are people clicking less than at the start? Reporting more? Does one department need a hand?

A high first result is nothing to be ashamed of. It is a starting point, and it is often where management finds the gap between what it believed and what happens in front of the screens. What counts afterwards is which way the two curves head.

The scenario carries weight too. A fake delivery notice teaches nothing to a team that never receives parcels. So the messages are adapted to your sector and your processes.

A year of simulations, with sample figures. What we look for: clicks going down, reports going up, and nobody named.

The moves

Which habits is awareness training trying to build?

Not a list of twenty rules nobody will read twice. Three moves, simple enough for someone in a hurry to make anyway.

Report instead of delete

Binning the message protects you. Reporting it also protects the co-worker who got the same one and was about to click. A single report can spare someone else an incident.

Call when in doubt

A doubt is settled by calling the person or the organization, using a number you had before the message arrived. Never the one written in the suspicious email.

Check every new bank account

Wire fraud comes with no link and no attachment, so filters see it poorly. A house rule blocks it: no payment leaves for new banking details without a confirmation out loud.

These moves are learned by repeating them, not by reading them once. Our article on phishing simulation for small businesses explains the exercise in more depth.

How it runs

How does a simulation campaign unfold?

In five beats. No password is stolen and no computer is infected: the fake message is harmless from start to finish.

  1. Choosing the scenario. Invoicing, delivery, human resources, a Microsoft 365 notice. We pick what looks like the real mail the team gets.
  2. Sending. It is staggered, so the first person to smell the exercise does not tip off the whole office at once.
  3. Measuring. Clicks, credentials entered and reports are counted, anonymously or by name depending on company policy.
  4. Explaining on the spot. Whoever clicks lands on a page saying it was a test and pointing out the clues that could have been noticed.
  5. The debrief. Results are compared with earlier campaigns and added to the file.
What the tools already do. Filtering holds back most messages before they reach the mailboxes. The simulation is about the ones that get through. The technical side is described on the email protection for small businesses page.

The climate

Why never name the person who clicked?

Because it is the surest way to make everyone go quiet. An employee singled out in front of her colleagues learns a lesson, and not the intended one: next time she will say nothing. Yet the moment someone admits to clicking on a real message is the moment the password can still be reset and the sessions closed.

So the results are used to aim. A department that clicks more than the others gets a reminder of the right reflexes. People who clicked are followed up with, and no ranking goes up in the lunchroom.

Training delivered once fades within a few weeks. A reflex exercised from one quarter to the next stays. You can tell when the team talks about it on break, compares what each person noticed and ends up writing its own rule.

Awareness does not replace the tools. It rounds them out: they block most of the messages, and employees catch the rest.

A sample team cheat sheet, written together: when in doubt, we ask instead of trying.

The ground

Sorel-Tracy, about 70 km from our office

Sorel-Tracy is the seat of the Pierre-De Saurel regional county municipality, in Montérégie, where the Richelieu River meets the St. Lawrence. Autoroute 30 and Route 132 run through the city.

A simulation goes out by email and is read over the network. Whether the team sits in Sorel-Tracy or elsewhere makes no difference to the exercise. We have neither premises nor a technician stationed in the city, and we publish no on-site response time. A trip from Trois-Rivières is scheduled when the work calls for it.

The simulations are part of the vCIO module, which goes with any of our three plans, Base, Standard and Complet, from ten workstations or servers. On weekdays, regular support answers between 8 a.m. and 5 p.m. Complet includes the emergency line. The technical measures that surround awareness are on the managed cybersecurity page. The other cities we cover are named under service areas, and the contact page is there to tell us about your team.

Questions and answers

Your questions about security awareness in Sorel-Tracy

Do you have an office in Sorel-Tracy?
No, we have no office there. OKTO Solutions is based in Trois-Rivières, about 70 km away, and no technician is stationed in Sorel-Tracy. A phishing simulation is sent and measured remotely. A trip is scheduled when the work calls for it, and we publish no on-site response time.
Are phishing simulations part of a plan?
They are part of the vCIO module, which includes four a year at all three of its levels, Essentiel included. That module attaches to a managed IT services plan, starting at ten workstations or servers. It is never bundled in by default.
Will our employees feel trapped?
Not if the exercise is run to teach. The aim is never to trap or punish. The person who clicks learns right away that it was an exercise, and the results are not used to name publicly who got caught. Naming someone is the surest way to make the reports stop.
Is one simulation a year enough?
No. A single campaign measures one day, not a habit. Four simulations spread over the year, one per quarter, show a trend: are people clicking less, are they reporting more, does one department need a hand.
Our email filter is good. Why train people?
Because the filter stops most of the volume, not all of it. A wire transfer request typed by someone who read your website has no link and no attachment, and no filter can recognize it for certain. What stops it is a person who confirms by phone, at a number already on file.
Can the results be used with our insurer?
They are recorded in the file, which helps when an insurer or a demanding customer asks whether employees receive training. The results of the campaigns that were run can then be shown. We do not promise what the insurer will decide.

Would your team report a fake email?

Tell us how many people have a mailbox at your company and whether an exercise has ever been run. We will tell you what four simulations a year would change.

Reviewed by , president of OKTO Solutions · updated