Technology
Engineers are targeted differently
Nobody is sending your platform team an obvious invoice scam. They are getting OAuth consent screens, package-registry lures, CI token requests and push notifications at 02:00 — and a generic awareness course insults them without teaching anything.
- Tier 5
- OAuth and CI-token lures
- API
- campaign automation
- SCIM
- at any headcount
Credibility
Scenarios that respect the audience
Consent-screen abuse, a dependency that asks for a token, an MFA prompt storm, a recruiter with a take-home repository. If the lure is not plausible to an engineer, the result tells you nothing except that they can spot a bad one.
- MFA fatigue and push-bombing sequences
- OAuth consent and device-code flows
- Package-registry and CI-token pretexts
Operations
Programme as code
Create audiences, launch campaigns and read results over the API, so the awareness programme lives in the same automation as everything else your team runs rather than in a console somebody logs into monthly.
- REST + signed webhooks
- Terraform-friendly tenant configuration
- Events into your existing SIEM
Questions
Asked on every first call
The ones that decide whether a first call turns into a second one.
1 questions
Our engineers will spot every simulation. Is this pointless?
They spot tier one. Tier five is a thread hijack referencing a real internal project, or a consent screen for an app with a plausible name — and the results are consistently humbling. The interesting metric for engineering populations is report rate, not click rate.
Keep reading
Related
Try a tier-five scenario on your platform team
Pick a test group. We will build something they have not seen before.