Ransomware rarely starts with the ransom note - it starts with a single click on a phishing attachment or malicious link days or weeks earlier. This update adds a dedicated simulation track that mirrors how real ransomware campaigns actually reach employees.
What's New
Multi-Stage Attack Chains
Instead of a single test email, ransomware simulations now model the full delivery chain security teams see in real incidents: an initial phishing email, a follow-up "invoice" attachment, and a fake software update prompt - each stage only triggering if the previous one was missed.
Safe Payload Simulation
If an employee would have triggered the payload, they see an immediate, clearly-marked simulation notice explaining exactly what happened and what to do differently, with zero risk to any real device or file.
Attachment & Macro-Based Lures
Templates cover the delivery methods most associated with real ransomware incidents, including malicious document attachments, disguised executables, and "enable macros to view" prompts.
Incident-Ready Reporting Practice
Each simulation reinforces the same reporting habit that matters most in a real ransomware event: report immediately, don't try to fix it yourself, and don't open anything else from that sender.
Why It Matters
Ransomware remains one of the costliest and most disruptive attack types organizations face. Training employees on the actual multi-step way these attacks unfold - not just a generic "don't click suspicious links" warning - measurably improves early detection and reporting.
