PHISHGUARD: A WEB-BASED PHISHING SIMULATION AND AWARENESS TRAINING PLATFORM FOR ORGANIZATIONAL CYBERSECURITY
Yamuna J, Subha M, Yogeshwari J, Vishwa Pooja V
Department of Information Technology, PSNA College of Engineering and Technology, Dindigul, India
Abstract
Phishing remains the leading vector of organizational data breaches globally, with over 36% of reported incidents attributable to deceptive email tactics targeting human behavior rather than technical system vulnerabilities. Existing countermeasures—firewalls, spam filters, and endpoint antivirus tools—are fundamentally ill-suited to address the social engineering dimension of phishing attacks. This paper presents PhishGuard, a web-based Phishing Simulation and Awareness Training Platform designed to systematically evaluate and enhance employee phishing resilience within organizations. PhishGuard enables administrators to orchestrate realistic, customizable phishing simulation campaigns spanning delivery notification scams, HR policy impersonation, password reset directives, and account verification lures. A token-based behavioral tracking engine captures three critical interaction events—email open, link click, and credential submission—and a weighted risk scoring model aggregates these signals into a per-employee composite susceptibility score. An administrative analytics dashboard delivers real-time visual reports, department-level vulnerability heat maps, and campaign effectiveness metrics, enabling precision-targeted training interventions. Upon credential submission, the platform triggers an immediate context-sensitive awareness feedback mechanism that presents phishing indicators and links the employee to a structured training module. A role-based difficulty assignment algorithm calibrates simulation complexity to organizational hierarchy, ensuring equitable and meaningful assessment across all staff tiers. Experimental evaluation across four campaign types and three difficulty levels demonstrates that PhishGuard accurately differentiates phishing susceptibility, measurably reduces click and submission rates following training, and provides actionable intelligence for organizational security posture improvement. The modular RESTful architecture ensures scalability and compatibility with enterprise security ecosystems.
Keywords: Phishing Simulation, Cybersecurity Awareness Training, Social Engineering, Behavioral Tracking, Risk Scoring, Security Analytics, Employee Vulnerability Assessment, Spear Phishing.
Journal Name :
VIEW PDF
EPRA International Journal of Multidisciplinary Research (IJMR)
VIEW PDF
Published on : 2026-05-12
| Vol | : | 12 |
| Issue | : | 5 |
| Month | : | May |
| Year | : | 2026 |