As illustrated in FIG. 13, the network server device 210 can be part of or contained within the organization 260. This allows for internal simulated phishing campaigns to be launched from a phishing simulation module 230. Alternatively, as shown in FIG. 14, the system can be external to the organization 360. In this and other embodiments, there can be a connection to an internal or external database containing information regarding confirmed malicious messages. This can be a connection to another organization with which information is shared, or a database to which a single or multiple organizations forward information and can receive information to develop recipes or determine if a reported message has already been identified as a malicious message. In any of the above examples, the network server device may generate a simulated phishing message in a phishing simulation module 330 to send to any number of individuals in the organization a simulated phishing attack message.
As non-limiting examples, the systems and methods described herein can be used to raise the acuity of the individual in identifying phishing attack messages and provide a means for identifying and reporting those messages so that remedial action can be taken with reduced time between arrival of the attack message and the remedial action. As described below, this can be accomplished in part by providing a console at which reports of suspicious messages can be efficiently reviewed. Each user reporting a phishing attack message may be given a reputation score. The reputation score may be adjusted based on correctly or incorrectly reporting a message as a phishing attack message. A correct report may be indicated when a user reports a message which was originally generated by the phishing simulation module in the system.