Welcome to the Security Awareness Training Discussion Forum!
Recently active
One of our core commitments when we began developing Webroot® Security Awareness Training was to remain relevant. We pledged to continuously develop content that reflected the latest threats faced by businesses and users as they arose. One of the most significant challenges we’ve seen since the launch of our user training tool has been the shift to remote workforces forced by the novel coronavirus outbreak. It’s dealt a serious blow to the cyber resilience of many organizations and is something, we felt, needed to be addressed. We’re happy to announce that a course designed to do just that is now available. It’s a guide for organizations and their users to maintain their cyber resilience with dispersed workforces, and we hope you’ll enroll. Why bother developing a Cyber Resilience while Working from Home Course? Cybercriminals know many remote workforces are no longer always under the watchful eyes of IT teams. They know some are even working from their own devices, often outsid
Hello, I took over SAT at my company from another tech who no longer works for us. He had campaigns set up so that when you add a new user to a site, it would automatically send them the campaign. He also had campaigns set to “indefinite” duration and never got around to ending any of them. This seemed fine until recently when I added a user to a site and it triggered the automatic sending of not just the most recent campaign, but also the past ones. Going forward I will change the settings so this doesn’t happen again. However, I was wondering if there was a way to end multiple campaigns at once or do I have to go through them all one-by-one? Any help would be appreciated.Thank you
Hello, I am trying to add images to phishing campaigns for SAT. I want to do this so I can relate the material either to the client itself or to current security events. I have tried using the editor in both the Site List and the Management Console. I have browsed through the posts on here and have read the OpenText Admin Guide. I have tried hosting the image on imgur and Google Drive, as well as a simple Ctrl+C, Ctrl+V combo. Nothing has worked. Using the image addition window (see below) doesn’t work: If I insert a URL in the Image Info tab and press “OK,” the window closes and nothing happens (no image inserted). I I use the link tab, insert a URL and press “OK,” I get the following error: The only thing that DOES work is copying one of your images already available in your pre-built options and pasting it into a new campaign. This however limits me to only images currently available in pre-built OpenText campaigns, which in my opinion are fairly limited and doesn’t allow me to
Our WR SAT point of contact clients are wanting an interim report during a campaign to see the users yet to action or complete and therefore require follow up prompting. A report showing up to date progress is a common request. I understand this feature is not yet available.
Every time we push a phish test our help desk is inundated with tickets from clients “helpfully” informing us that they discovered a phishing email in their inbox.We’ve tried distributing the phish test over the course of a month to keep volume down, but that just spreads out the tickets.We have a few ideas we’re kicking around, but wondering if others have good strategies already in place. Thanks!
Hello, how are you?I'm sending this message because I would like you to help me clarify a few doubts.I've been testing the autopilot in order to automate the SAT tool.I have a couple of questions:1. Is it possible to create a monthly routine, meaning the campaign runs every month and sends a phishing email to users each month?2. Could you explain how SAT works?I look forward to your response.Best regards,António Correia
Hello all!I am a cybersecurity analyst for an MSP and I am in charge of the Security Awareness Training program. I have been getting this error when trying to access the Webroot SAT platform:{"statusCode":500,"error":"Internal Server Error","message":"An internal server error occurred"}Probably every other day I get this error. It is getting annoying as I have to delay training until this error is resolved. Do you guys have insight as to why this is happening? Your help is much appreciated. Thank you!
Hello. Our SAT module shows incomplete but I’ve completed it already and when I go back to the training link, the status is up to date and shows completed. Can you help me figure this out? Thanks! This is what shows in Individual User Logs This is what shows when I go back to the training link
how do I send an SAT training video to the an IT manager to review before a campaign goes out
I recall a while back Webroot had some sample curriculum or a training path for the SAT videos, but can’t for the life of me find that page now. It basically had a suggested order to watch the videos so people got a good overview of cybersecurity. Does anyone know where to find that? Thanks!
Hi there,I am wondering if anyone else has encountered this issue and has any advice:Every time we push a phish test, we have partners forward the phishing email to our help desk. What we discovered recently is that when someone forwards the email our outbound mail filter “clicks” the link.I have discussed this with our spam filter and there is no workaround. They have to protect their IPs from being blacklisted as a source of spam.I’m just curious if anyone else has encountered this and ask what you’ve done.Seems to me the only way to prevent this is to educate users NOT to forward the emails. But we also don’t want to discourage partners reporting security concerns.Open to suggestions. What do you guys do?
I have been running quarterly phishing simulations to keep our users on their toes. I noticed that a handful of users are flagged as deferred in the Campaign Phishing Line Data. Do you often have deferred emails to your users? Do you care about them? Should we do anything about this? Thanks!
Hi there, I’m not seeing this in the documentation, but figured I’d ask here just in case I missed something. We would like to be able to send SAT reports directly to our partner point of contact after a phishing/training campaign ends. As far as I can tell this is not possible if we are using the centrally managed portal or Autopilot.Right now all I can do is have them delivered to me in an email. Just had a meeting this week with our account management team, and this is a big source of frustration for them. The phishing and training modules are fantastic, we are just looking for a better way to communicate results with our partners. Thanks!
Hi all, wondering if an ‘open’ in SAT is an actual open if the client is using Outlook’s preview pane. Research shows some say yes, some say only if images are allowed, some say no, one says to ignore it because only clicked links should count. But specifically within Webroot’s Security Awareness Training, if a client is using Outlook, does ‘open’ in a campaign include people who see it in preview pane only? ThanksFranco
Is it possible to disable the training modules and only send out phishing simulations? I don’t want to annoy customers with a bunch of training when all they want is to test if their employees are clicking through phishing emails.
Hi there!We’ve been testing Autopilot internally and really like it so far!The only complaint I’ve gotten so far is the training email looks a lot like a phish. Sketchy looking domain, long link of gobbblygook, unsolicited email asking to click something…This is basically the email we’re training our clients not to click.Is there any way to customize this email template? Or are there plans to make it look more official?We are pretty excited about Autopilot, but are hesitant to push the training piece as is. It’s sure to generate a lot of questions from our clients. Thanks!Matt
HelloI am setting up the course ‘Security Awareness Training’ for a company we provide IT support for. According to this guide https://answers.webroot.com/Webroot/ukp.aspx?pid=4&app=vw&vw=1&solutionid=2938 I need to add ‘Secops Mailbox’ in order for the training to work. It is my understanding that flagging a mailbox as ‘Secops’ just opens the mailbox up to any rules I then put into Phishing simulation. I just wanted to confirm this is the case and that there will be no adverse affects from flagging the mailbox as a ‘Secops’ mailbox. I am changing 30 or so mailboxes so wanted to double check before finalising the settings Thanks in advance :) H
I saw a Whats New post that talked about the WSAT Autopilot being released. I can’t find it in my console. IS it available yet?
Hi,I have many part-time employees that do not have a company AD account and email address as their job functions do not require it. What is the best way to get them into a Campaign since public emails are not supported? I’m not going to create 100+ email accounts (and train those employees on how to use/access company email) simply for training modules.Thanks in advance for any ideas.
We have a couple of thousand people registered across our client base for phishing tests and really like being able to distribute the phish emails over the course of a couple weeks. They just all deliver at once. I contacted support, but wasn’t able to get a clear answer as to why this happened aside from a potential lack of available resources to handle the campaign. I’ve been told this is resolved now, but haven’t tested beyond a small subset of people. I’m not saying support is wrong. We just get a lot of support calls when all of these go out at once, so I’m a little gun shy. Before I shoot out another campaign, I’m just curious if anyone else has seen this behavior. Thanks!Matt
Hi, Has anyone had any success in adding their own logo to the SAT Training Invite emails please? Is there a maximum size for the logo?Thanks
We are an MSP and we sell a lot of SAT. We are desperate to get some decent reporting for individual organisations. Is this something that is imminent? I believe that our tech team have been chasing this up for a very long time.
Is anyone having issues loading targets into the phishing campaigns? I can load targets into the training, but not the phishing campaign. When I set up the phishing campaign it just does a continuous load on the targets page. Any advice would be helpful. Thanks.
When a user that has already been synced as a target to SAT uses the registration URL for a training campaign, if they do not use the exact uppercase/lowercase spelling of their email address, it registers them as another target within the SAT portal. Could this be updated to NOT be case-sensitive? This is causing issues for the statistics on training campaigns and on the training campaign reminders.
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.