Simulating a spam campaign would allow the Chief Security Officer (CSO) to evaluate whether the training has been successful in reducing the number of successful ransomware attacks that have hit the company, because it would: Test the employees' ability to recognize and avoid clicking on fake or malicious emails, which is one of the main vectors for ransomware infection. Measure the effectiveness of the training by comparing the click-through rate and the infection rate before and after the training. Provide feedback and reinforcement to the employees by informing them of their performance and reminding them of the best practices for email security.