Skip to content
ISO 27001, SOC 2, the DPDP Act and manual VAPT.
Part of Managed Services7 services in this practice area

Practice Before the Real Thing

Phishing Simulations

Most breaches start with someone clicking a link. Our phishing simulations put realistic, safe lures in front of your people, then turn every click into a teachable moment rather than a real incident.

See the engagement path, 5 phasesSee the full Managed Services service index

Overview

Phishing simulations measure how your people respond to a convincing lure and help them get better over time. We design scenarios that match the threats you actually face, launch them safely, and track who clicks, who reports and who enters credentials. Nobody is named and shamed. Instead, the moment someone clicks, they get short, targeted training that sticks. Run regularly, these simulations turn your workforce into a genuine layer of defence.

Methodology

How the Engagement Runs

Every phase has a named output, so you always know what is being worked on and what lands on your side of the table.

The Engagement, End to End

5 Phases, 5 Named Handovers

Flow

Flow chart of the Phishing Simulations engagement, 5 phases in order, each one selectable. Phase 1, Baseline and Scenario Design. We measure your starting point and design lures that match real threats to your teams, from invoice fraud to fake internal notices, tuned to be believable without being cruel. Activities: Measure a baseline click and report rate; Design pretexts matched to real lures your staff receive; Rate each scenario with the NIST Phish Scale; Agree exclusions and tone limits with HR and leadership. Hands over Baseline Susceptibility Report. Phase 2, Launch. We send the campaign safely to the agreed audience, at a realistic pace, without touching live systems or exposing anyone's real credentials. Activities: Allowlist sending domains with your mail team; Stage delivery in waves so results stay clean; Brief the service desk so genuine reports are handled well; Monitor delivery for bounces and filtering issues. Hands over Campaign Launch Record. Phase 3, Tracking and Capture. We record who opens, clicks, reports or enters details on the landing page, giving you an honest, anonymous picture of behaviour. Activities: Track opens, clicks, submissions and reports per scenario; Measure how quickly the first report reaches the service desk; Discard real credentials at the point of capture; Aggregate results by team so no individual is named. Hands over Anonymised Behaviour Dataset. Phase 4, Reporting. We report the results by team and scenario, show trends over time, and highlight where the real risk sits so you can focus effort. Activities: Compare click and report rates against the baseline; Break results down by team, role and scenario difficulty; Show the trend across previous campaigns; Recommend where training effort will pay off most. Hands over Campaign Results Report. Phase 5, Targeted Follow-up Training. People who clicked receive short, relevant training straight away, and we repeat the simulation later to prove the lift is real. Activities: Deliver a short training module at the moment of the click; Explain the exact cues that gave the lure away; Run a repeat simulation for the same group later; Report the improvement between the two rounds. Hands over Improvement Trend Report. Each phase begins from the artefact the phase before it produced.

Phase 01 Baseline and Scenario Design

We measure your starting point and design lures that match real threats to your teams, from invoice fraud to fake internal notices, tuned to be believable without being cruel.

What Happens In This Phase

  • Measure a baseline click and report rate
  • Design pretexts matched to real lures your staff receive
  • Rate each scenario with the NIST Phish Scale
  • Agree exclusions and tone limits with HR and leadership

The Handover

Baseline Susceptibility Report

The next phase starts from this.

Read the handover cards on their own and you have the paper trail. Select a phase to see what happens inside it.
  1. 01

    Baseline and Scenario Design

    We measure your starting point and design lures that match real threats to your teams, from invoice fraud to fake internal notices, tuned to be believable without being cruel.

    OutputBaseline Susceptibility Report

    Activities

    • Measure a baseline click and report rate
    • Design pretexts matched to real lures your staff receive
    • Rate each scenario with the NIST Phish Scale
    • Agree exclusions and tone limits with HR and leadership
  2. 02

    Launch

    We send the campaign safely to the agreed audience, at a realistic pace, without touching live systems or exposing anyone's real credentials.

    OutputCampaign Launch Record

    Activities

    • Allowlist sending domains with your mail team
    • Stage delivery in waves so results stay clean
    • Brief the service desk so genuine reports are handled well
    • Monitor delivery for bounces and filtering issues
  3. 03

    Tracking and Capture

    We record who opens, clicks, reports or enters details on the landing page, giving you an honest, anonymous picture of behaviour.

    OutputAnonymised Behaviour Dataset

    Activities

    • Track opens, clicks, submissions and reports per scenario
    • Measure how quickly the first report reaches the service desk
    • Discard real credentials at the point of capture
    • Aggregate results by team so no individual is named
  4. 04

    Reporting

    We report the results by team and scenario, show trends over time, and highlight where the real risk sits so you can focus effort.

    OutputCampaign Results Report

    Activities

    • Compare click and report rates against the baseline
    • Break results down by team, role and scenario difficulty
    • Show the trend across previous campaigns
    • Recommend where training effort will pay off most
  5. 05

    Targeted Follow-up Training

    People who clicked receive short, relevant training straight away, and we repeat the simulation later to prove the lift is real.

    OutputImprovement Trend Report

    Activities

    • Deliver a short training module at the moment of the click
    • Explain the exact cues that gave the lure away
    • Run a repeat simulation for the same group later
    • Report the improvement between the two rounds

Specification

What We Run, and What We Measure You Against

The tooling our engineers use on this work, and the published standards the findings and evidence are mapped to.

Scope

What Is Examined, and What it Is Measured Against

Map

Map of the Phishing Simulations scope, running left to right in three stages. Stage one, what we run, 6 tools and techniques: GoPhish, KnowBe4, Microsoft Attack Simulator, evilginx, Mailtrap, custom landing pages. Stage two, findings from all of it are proven by hand and written up once. Stage three, measured against 4 published standards: NIST Phish Scale, NIST SP 800-50, MITRE ATT&CK, SANS Security Awareness Maturity Model.

What We Run

6 tools

  • GoPhish
  • KnowBe4
  • Microsoft Attack Simulator
  • evilginx
  • Mailtrap
  • custom landing pages

Converges On

One Set of Proven Findings

Every issue is reproduced by hand before it is written down, and it is written down once.

Measured Against

4 standards

  • NIST Phish Scale
  • NIST SP 800-50
  • MITRE ATT&CK
  • SANSAwareness Maturity Model
One pass of testing and analysis, one set of findings, then that single set is graded against every standard on the right. You are not paying for the same work once per framework.

Deliverables

What You Receive

  • Baseline phishing susceptibility report
  • Realistic simulation campaigns on an agreed schedule
  • Anonymous results by team and scenario
  • Just-in-time training for those who click
  • Trend report showing improvement over time

Scope This Engagement

Tell us about your environment, your timelines and any audit dates you are working to. We come back with scope, effort and a start date.

Questions

What Clients Ask Us

Something here not covered? Ask Us Directly.

Will this embarrass our staff?

No. Results are reported anonymously and framed as practice, not punishment. The goal is to build instincts, so the tone stays supportive and the training that follows is genuinely helpful.

How often should we run simulations?

Regularly beats rarely. A monthly or quarterly rhythm keeps instincts sharp and lets you measure real improvement, rather than a one-off snapshot that fades.

Are the simulations safe for our systems?

Yes. We never capture real passwords or touch live systems. The lures land in inboxes, the landing pages are ours, and everything is designed to teach without risk.

Keep Moving Through Managed Services

Service 5 of 7 in this practice area