Overview
Phishing simulations show how your organisation would respond to a real attack: who clicks, who submits credentials, and — most importantly — who reports the email. Run regularly, they measurably reduce risk and build a reporting culture.
We design campaigns based on real lures our SOC sees — credential harvesting, fake invoices, delivery notifications, MFA prompts and executive impersonation — tailored to your industry and difficulty level. Users who fall for a simulation receive short, immediate training; users who report it are reinforced.
Campaigns are run ethically and transparently: no public shaming, sensible lure choices and clear communication with leadership and HR.
What's included
Our approach
- BaselineInitial campaign to measure current risk.
- PlanAnnual calendar of varied campaigns.
- RunSafe, controlled simulations.
- TeachInstant training and targeted follow-up.
- ReportTrends in click, submit and report rates.
What you receive
- Campaign calendar
- Per-campaign results
- Department-level risk insights
- Training follow-up for repeat clickers
- Quarterly human-risk report
Standards & frameworks
- NIST SP 800-50
- ISO/IEC 27001 A.6.3
- MITRE ATT&CK T1566
- SOC 2 CC2.2
Frequently asked questions
Is phishing simulation ethical?
Yes, when run transparently with leadership approval, sensible lures and a focus on learning rather than punishment.
How often should we run simulations?
Monthly or quarterly campaigns of varying difficulty work well for most organisations.
What metric matters most?
The report rate — how many users report the phish — is often more meaningful than the click rate.