What to Expect
GoPhish is 75 minutes. Your team leaves knowing how real phishing attacks are constructed — because they just played against thirteen of them.
Before the Room Fills
The WILDCARD facilitator arrives 30 minutes before the session. For in-person sessions, the opening trivia cards and props are laid out — the room looks normal when your team walks in.
As people arrive, they each pick up 3 trivia cards and 2 fish cards and start challenging each other immediately. Correct answers win cards. Wrong answers win a fish. The game is running before you call the room to order.
Thirteen Scenarios
The facilitator guides the group through 13 real attack scenarios, one at a time, using an illustrative slide deck (in-person and virtual run the same lean format). Each scenario presents a situation your team will recognize from their actual inbox:
- Display name spoofing — the From field doesn't verify who sent it
- Vendor fraud — an invoice from a domain that's off by one character
- Reply-chain phishing — a legitimate thread gets hijacked mid-conversation
- CEO impersonation — urgent wire transfer request from "the boss"
- And nine more scenarios from the GoPhish Level 1 deck
The group discusses, commits to an answer, and then finds out what attackers are counting on them to miss. No slides. No quiz score. Just the scenario and what actually happens.
Debrief
The final 10 minutes covers three questions:
- What surprised you most?
- Which scenario is most likely to hit your team?
- What's one thing you'll change this week?
Each participant leaves with an action sheet — three concrete things they can do before next week. Not awareness posters. Actual changes.
After the Session
- Within 3 business days: Completion certificates emailed to each attendee
- Within 24 hours: WILDCARD follow-up if anything from the session warrants a conversation
Filing CAPG? The application must be submitted before the session, and your payment receipt was issued at booking — you'll need both for your final claim. See the CAPG guide →