Retest
A new simulation of the same attack category, weeks after a failure and with a different template, to verify the person actually changed their behavior.
Full definition
A retest is a new phishing simulation sent weeks after a person fell for a simulated attack and completed their training, using the same category and sophistication as the original lure but a different template. Its purpose is to verify that the person learned the lesson, not that they memorized an email.
It is the direct answer to the central problem of awareness: peer-reviewed evidence shows that completing courses does not by itself predict fewer real failures. What demonstrates change is testing the behavior again under equivalent conditions. Passing the retest is the proof; failing it means the risk is still active and should be reflected in the person's profile.
In a mature program, the retest closes the cycle of simulation, training and validation, turning the question of whether training worked into a verifiable data point instead of a hope.
Related terms
Phishing simulation
A controlled phishing attack a company sends to its own employees to measure who falls, for which kind of lure, and how often.
Microlearning
Training in short, specific doses delivered at the moment of the mistake. It uses the instant when a person is most receptive to learning.
Security awareness
Programs that teach employees to recognize and report threats. Completing courses does not equal changed behavior: that is validated with a retest.
Human risk score
An indicator that summarizes the security risk of a person or team based on observed behavior: simulations, exposed credentials, retests.
From definition to data: measure your company's human risk
Fensivo detects leaked credentials, simulates real attacks and validates with retests that behavior changed.