Skip to content

Resource

Security awareness when your org lives in Google Workspace

Practical steps for your security and IT team — and how PhishGuard supports each one.

Use your OUs as the targeting model

Your Organizational Units already map to who should receive which campaign. Include production employee OUs; exclude service accounts, test users, and break-glass aliases. PhishGuard is built to include and exclude OUs cleanly.

Measure report rate — not only clicks

A healthy program increases reporting of suspicious mail. Pair simulations with a clear report-phish path and celebrate people who report — including those who flag real threats. PhishGuard tracks reports alongside clicks so you see the full picture.

Coach high-risk users without shame

Define high risk as repeated interactions across recent campaigns (for example, 3 of the last 6). Offer targeted follow-up — not public call-outs. PhishGuard’s high-risk views help you find those people quickly.

Keep simulations ethical

Do not harvest passwords. Prefer training landings. Align with IT before your first live campaign so delivery and support are ready. PhishGuard is designed with dry-run and no credential capture as defaults.

Related: Running phishing simulations in your Canadian organization