Scope
Training is only one layer of phishing defense
This assessment is a planning screen, not a penetration test, compliance audit, breach-probability model or employee performance tool. Phishing resilience also depends on identity controls, email security, payment verification, reporting workflows and incident response. Use aggregate simulation data for program improvement rather than treating one test as a definitive measure of an individual employee.
Framework note: NIST small-business phishing guidance emphasizes teaching employees to recognize and report phishing. CISA guidance emphasizes MFA, including phishing-resistant MFA where available, and recommends user awareness and training that covers identifying and reporting suspicious activity. Neither source establishes the OfficeQ training-frequency bands used here; those bands are a model-based planning recommendation.