Skip to main content

What the click list may and may not be used for

A simulation produces a list of names. CERT-In's guidelines require anonymised or statistical results with no individual identified or penalised, and a programme that ignores that rule destroys its own report rate.

By Chintan Joshi
August 31, 20267 min read

A phishing simulation produces a list of names as a by-product of its own mechanics. The message went to individual mailboxes, and the tracking distinguishes who opened it, who clicked, and who submitted credentials. Someone will ask for that list, and the request is usually well meant: to retest the people who fell for it, or to find out whether the problem sits in one function.

What may be done with it is settled twice over, on two grounds that do not depend on each other. The first is a rule. CERT-In's audit policy guidelines require that testing of general staff use anonymised or statistical techniques, that no individual be personally identified or penalised, and they state the purpose of the testing in the same breath. The second is a matter of measurement: a programme whose results reach line managers as a list of names stops producing usable numbers, and it stops producing them exactly where the programme's value sits.

The clause, and the three things it requires at once

CERT-In's Comprehensive Cyber Security Audit Policy Guidelines, CISG-2025-02, Version 1.0, 25 July 2025. §4 applies the guidelines to two audiences, the first of which is CERT-In empanelled auditing organisations. §15.2.2(iii), pp. 55–56, governs how social engineering and process testing are conducted:

"Social engineering and process testing should be conducted in a controlled and ethical manner. When targeting general staff (e.g., untrained or non-security personnel), such testing must utilize anonymized or statistical techniques—ensuring no individual is personally identified or penalized. The purpose is to evaluate overall awareness and the effectiveness of security processes, not to single out individuals."

Three requirements sit in that passage and they are usually read as one. The first is a technique: anonymised or statistical. The second is the outcome that technique has to ensure, and it has two halves — no individual personally identified, and no individual penalised. The third is a purpose, which the guideline states rather than leaving to the parties: to evaluate overall awareness and the effectiveness of security processes.

The purpose sentence is the operative one here. A use of the results sits inside the clause when it evaluates the awareness of an organisation, and outside it when it singles out a person. Identification and penalty are named separately, so a list that names clickers to their managers meets the first condition on its own, whatever is or is not then done to anyone on it.

The clause binds the empanelled auditing organisation conducting the test: a condition the work is performed under, whatever a statement of work says about deliverables. The argument that follows is independent of it and applies to any programme, however it is staffed.

What the per-recipient record is legitimately for

The individual-level record has work to do before it is reduced. Population statistics are computed from individual events. Exclusions and escalation contacts have to be honoured. Cohorts for the next round in the cadence are assigned from the results of the last one. None of that requires the identified list to travel beyond the people running the exercise, and all of it is finished once the report exists.

The Digital Personal Data Protection Act, 2023 governs the same dataset. Section 8(5) requires reasonable security safeguards over it. Section 8(7)(a) requires erasure "as soon as it is reasonable to assume that the specified purpose is no longer being served".

Look at what that erasure trigger is keyed to: not a fixed number of days, but the specified purpose. The purpose here is the one the processing was grounded on — measuring the awareness of a workforce, under s.7(i)'s employment ground and s.4(1)'s lawful-purpose requirement. Once the population report is produced and the next cohorts are assigned, the identified list has done what it was collected to do. The two instruments interlock: the guideline governs the technique, and the Act governs how long what the technique leaves behind may be kept.

Why the punitive version stops measuring anything

Now set the clause aside entirely and consider only the numbers.

A programme is not judged on one campaign. It is judged on a series — a baseline, then a figure each period against a comparable population — because that is what a standing obligation to evaluate awareness periodically is discharged with. The RBI Directions, 2026 put it in those terms for banks: "The bank shall evaluate the awareness level of employees periodically" (Commercial Banks ¶202; ¶201 Payments Banks and Small Finance Banks; ¶197 Credit Information Companies; all 31 July 2026). The series is the deliverable, and a single quarter's click rate is an input to it.

Suppose the click list is circulated to line managers, or a clicker's name reaches an appraisal conversation. Nothing about the mechanics of the exercise changes. What changes is what the workforce understands the exercise to be for, and they will not be wrong.

Once staff learn that an exercise produces a list managers see, the rational response is to stop reporting anything ambiguous. Reporting a message that turns out to be legitimate, or reporting late after having already clicked, becomes an act of self-identification into a process with consequences attached. Silence costs nothing. The population is not behaving irrationally; it is responding correctly to the incentive the programme has created.

So the report rate falls, and it is worth being exact about why that costs more than the click rate it was traded for. A click rate tells you what proportion of a population was deceived by one pretext, of one difficulty, on one day. The report rate tells you whether the organisation finds out that something is happening while it is still happening. Detection of a live phishing campaign begins with a person who says something to someone. A programme that has taught its population to stay quiet has suppressed the one behaviour that shortens a real incident. The figure also presupposes somewhere to report to: where no route exists, a low report rate measures the absence of a mailbox rather than the presence of vigilance.

The comparison breaks with it. Next period's figures will differ from this period's, and the difference will be read as a change in awareness. It will in fact be a change in what the population believes the measurement is used for. The instrument is now responding to itself, and the programme can no longer answer the question it was commissioned to answer — is this organisation more aware than it was a year ago — because the two ends of that comparison were taken under different conditions.

What the reporting contains instead, and the cohort floor

Anonymised or statistical is a property of the aggregate. It is not achieved by deleting a column.

The population view is the reportable one: click rate, credential submission rate, time-to-click, report rate and time-to-first-report, and heatmaps by department and by role. Each of those is a statement about a group, and each can be trended across the cadence.

Cohort size is where this is most often missed. A departmental heatmap in which a cell covers four people is not anonymised in any useful sense: the manager of those four can name the clicker by subtraction. Role cohorts fail the same way and faster, because a role is often one person. A statistical technique therefore has to carry a floor — a minimum cell size below which a cohort is merged upward or not reported separately.

Where the common requests land

The requests that arrive after a campaign sort cleanly against the two instruments.

The requestWhat governs it
Population and cohort statistics, trended across the cadence§15.2.2(iii): anonymised or statistical technique, for the stated purpose of evaluating overall awareness and the effectiveness of security processes
A named list of clickers sent to line managers§15.2.2(iii) requires the technique to ensure no individual is personally identified
A disciplinary consequence attached to a click§15.2.2(iii): no individual personally identified or penalised, and the stated purpose is not to single out individuals
Per-user risk scores or a departmental leaderboardThe same requirement — a score or a rank attached to a person identifies the person
Automatic enrolment keyed to a named clickerIdentifies the individual to the process that acts on them; the clause requires the technique to prevent that for general staff
Retention of the identified dataset after the report is issuedDPDP s.8(5) safeguards while it is held; s.8(7)(a) erasure once the specified purpose is no longer being served

What to settle before the first campaign

Each of these is cheaper to decide in the scoping document than in the week the first report lands:

  • Who receives identified data during the exercise, and who does not. Named roles, not departments.
  • The minimum cohort size for any cell that appears in a report, and the rule for merging upward beneath it.
  • The erasure point for the identified dataset, expressed against the purpose it was collected for rather than as an arbitrary period.
  • A stated position on disciplinary use, written before the first number exists. The question is otherwise answered for the first time on the day a senior person clicks, and the workforce will hear which way it went.

The programme's most valuable output is not this quarter's click rate. It is the ability to set this quarter beside last year's and have the difference mean something, and that rests on a population that still reports. A click list used the wrong way spends it once, and no later campaign gets it back.

About the author

Chintan Joshi

CISO & Director — Security Advisory

Oversees Security Brigade's cybersecurity advisory practice, helping regulated enterprises meet RBI, SEBI, CERT-In, and IRDAI compliance mandates. Previously held senior security leadership roles across BFSI.