Client Security Awareness Overview
Training
0
Enrolled Employees
0%
Training Completion Rate
0%
Average Quiz Score
0
Active Training Campaigns
Phishing Simulation
0
Simulation Campaigns Run
0
Simulated Emails Sent
0%
Click Rate
0%
Training Acknowledged Rate
Phishing Simulation Funnel
Sent → Opened → Clicked → Acknowledged, across all simulation campaigns to date.
Recent Activity
My Training
Here's your personal training status.
📧 Phishing Results
🎓 Training Assignments
0
Assigned Trainings
0
Completed
0
Pending
—
Average Score
Completed Trainings
| Training | Type | Completed | Score |
|---|
Employee Training Status
Uses the group/enabled/licensed filters set on the M365 Integration tab.
| Name | Department | Status | Score | Source | Action |
|---|
Training Campaigns
| Campaign | Type | Target | Progress | Avg Score | Actions |
|---|
Phishing Simulation — M365
New Simulation Campaign
A realistic-looking lure document (e.g. "Invoice.pdf") sent alongside the email. Allowed types: PDF, Word, Excel, PowerPoint, images, text/CSV — max 5MB. Executable/script files are not allowed.
Recipients are pulled from the Employees tab (anyone with an email on file). Add employees manually or sync them from M365 there first. Use the department filter for role-based targeting (e.g. send the "Invoice Approval" template only to Finance), or check individuals directly below.
| Name | Department |
|---|
Campaign Results
| Campaign | Category | Sent | Click Rate | Ack. Rate | Launched | Actions |
|---|
Consent & Engagement Tracker
| Client | Authorized By | Date Signed | Scope | Status |
|---|
Reports
Filterable, exportable reporting across training and phishing simulation — pulled live from the database.
Overview
0
Enrolled Employees
0%
Training Completion Rate
0%
Average Quiz Score
0
Simulation Campaigns
0%
Phish-Prone Percentage
0%
Training Acknowledged Rate
Phish-Prone Percentage Trend
Click rate per simulation campaign, in chronological order — the key metric for tracking whether awareness is improving over time.
By Department
| Department | Employees | Training Completion | Avg Score | Phishing Sent | Phish-Prone % |
|---|
Repeat Clickers — clicked a simulated phishing link in 2+ campaigns
| Name | Department | Times Clicked | Most Recent |
|---|
Campaign Detail
Training Campaigns
| Campaign | Type | Target | Enrolled | Completed | Avg Score |
|---|
Phishing Campaigns
| Campaign | Category | Sent | Opened | Clicked | Acknowledged |
|---|
Exports
Microsoft 365 Integration
Connect to Microsoft 365 / Entra ID via Microsoft Graph to import users and (optionally) sync the Employees tab. This connection is also used if you choose "Microsoft 365" as the send method on the Email Sending tab.
These filters apply both to "Import Users" below and to "Sync from M365" on the Employees tab. Picking a group requires the app registration to have Group.Read.All permission.
| Name |
|---|
Imported users become available as recipients on the Phishing Simulation tab, where campaigns are built and launched.
Email Sending
Choose how simulation emails go out. You can configure both and pick which one to use each time you launch a campaign.
Option A — Microsoft 365 (Graph API)
Uses the connection configured on the M365 Integration tab. The sender mailbox's domain must already be added and verified in your M365 tenant (Admin Center → Domains) — Graph will reject sending from domains the tenant doesn't own.
Option B — SMTP (e.g. Hostinger email)
Sends directly through a mailbox's SMTP server instead of M365.
For Hostinger email, this is usually
smtp.hostinger.com, port 465 (SSL) with an
existing mailbox on your domain (e.g.
security-training@ciqur.com) created in hPanel → Emails.
Option C — Resend (HTTP email API)
Sends over plain HTTPS instead of SMTP — useful if your host (e.g. Render's free tier) blocks outbound SMTP ports. Sign up at resend.com, verify a sending domain there, and paste the API key below.
Option D — Amazon SES
Also sends over plain HTTPS via AWS's API (not SES's SMTP
interface, which would hit the same port block). You'll need an
IAM user with ses:SendEmail permission, a verified
sending identity in SES, and — for a brand new AWS account —
production access approved (new accounts start in "sandbox
mode" and can only send to addresses you've individually
verified).
External Training
Connect third-party training content two ways: live-launched via LTI 1.3 (grades sync back automatically, content stays hosted by the provider), or by uploading a SCORM 1.2 package they've exported for you. Both show up together on each employee's My Training dashboard, alongside your regular campaigns.
Option A — LTI 1.3 (live-launched)
1. Register a Tool
You'll need three URLs from the provider's own LTI 1.3 platform registration instructions (for RansomLeak, this is in their admin console under "LTI Integration" or similar).
| Tool | Client ID (give to provider) | Deployment ID |
|---|
3. Add specific exercises
Each "resource link" is one launchable exercise or course from the provider — get the exact launch URL from their content catalog or deep-linking flow.
| Exercise | Tool | Target |
|---|
Option B — SCORM 1.2 package upload
Upload a course package
Export the course as a SCORM 1.2 zip from the provider's own platform, then upload it here. Some packages (like RansomLeak's) stream the actual content live from the provider's servers even after upload — you're just hosting the launch shell and receiving completion/score reports here.
| Course | Target | Uploaded |
|---|
Admin Control Panel
Manage who can log into this dashboard, what they can do, and how they sign in. This is separate from Employees (the people being trained/tested).
Portal Users
| Username | Display Name | Role | Groups | Sign-in | Effective Role | Actions |
|---|
Permission Groups
Groups grant their assigned role to every member — useful for bulk permission changes (e.g. give an entire team Manager access at once).
| Group | Grants Role | Members | Actions |
|---|
Single Sign-On
Microsoft (Entra ID)
Reuses the Tenant ID / Client ID / Client Secret already configured on the M365 Integration tab. In your Entra ID app registration, add this as a Web redirect URI: (loads once page is open)
Generic SSO (SAML/OIDC provider — e.g. Okta, Google Workspace, Auth0)
Enter the OIDC endpoints from your identity provider's app configuration. Redirect URI to register with your provider: (loads once page is open)