Practice Before the Real Thing
Phishing Simulations
Most breaches start with someone clicking a link. Our phishing simulations put realistic, safe lures in front of your people, then turn every click into a teachable moment rather than a real incident.
See the engagement path, 5 phasesSee the full Managed Services service index
Overview
Phishing simulations measure how your people respond to a convincing lure and help them get better over time. We design scenarios that match the threats you actually face, launch them safely, and track who clicks, who reports and who enters credentials. Nobody is named and shamed. Instead, the moment someone clicks, they get short, targeted training that sticks. Run regularly, these simulations turn your workforce into a genuine layer of defence.
Methodology
How the Engagement Runs
Every phase has a named output, so you always know what is being worked on and what lands on your side of the table.
5 Phases, 5 Named Handovers
Flow
Flow chart of the Phishing Simulations engagement, 5 phases in order, each one selectable. Phase 1, Baseline and Scenario Design. We measure your starting point and design lures that match real threats to your teams, from invoice fraud to fake internal notices, tuned to be believable without being cruel. Activities: Measure a baseline click and report rate; Design pretexts matched to real lures your staff receive; Rate each scenario with the NIST Phish Scale; Agree exclusions and tone limits with HR and leadership. Hands over Baseline Susceptibility Report. Phase 2, Launch. We send the campaign safely to the agreed audience, at a realistic pace, without touching live systems or exposing anyone's real credentials. Activities: Allowlist sending domains with your mail team; Stage delivery in waves so results stay clean; Brief the service desk so genuine reports are handled well; Monitor delivery for bounces and filtering issues. Hands over Campaign Launch Record. Phase 3, Tracking and Capture. We record who opens, clicks, reports or enters details on the landing page, giving you an honest, anonymous picture of behaviour. Activities: Track opens, clicks, submissions and reports per scenario; Measure how quickly the first report reaches the service desk; Discard real credentials at the point of capture; Aggregate results by team so no individual is named. Hands over Anonymised Behaviour Dataset. Phase 4, Reporting. We report the results by team and scenario, show trends over time, and highlight where the real risk sits so you can focus effort. Activities: Compare click and report rates against the baseline; Break results down by team, role and scenario difficulty; Show the trend across previous campaigns; Recommend where training effort will pay off most. Hands over Campaign Results Report. Phase 5, Targeted Follow-up Training. People who clicked receive short, relevant training straight away, and we repeat the simulation later to prove the lift is real. Activities: Deliver a short training module at the moment of the click; Explain the exact cues that gave the lure away; Run a repeat simulation for the same group later; Report the improvement between the two rounds. Hands over Improvement Trend Report. Each phase begins from the artefact the phase before it produced.
Phase 01 Baseline and Scenario Design
We measure your starting point and design lures that match real threats to your teams, from invoice fraud to fake internal notices, tuned to be believable without being cruel.
What Happens In This Phase
- Measure a baseline click and report rate
- Design pretexts matched to real lures your staff receive
- Rate each scenario with the NIST Phish Scale
- Agree exclusions and tone limits with HR and leadership
The Handover
Baseline Susceptibility Report
The next phase starts from this.
Phase 01 Baseline and Scenario Design
We measure your starting point and design lures that match real threats to your teams, from invoice fraud to fake internal notices, tuned to be believable without being cruel.
What Happens In This Phase
- Measure a baseline click and report rate
- Design pretexts matched to real lures your staff receive
- Rate each scenario with the NIST Phish Scale
- Agree exclusions and tone limits with HR and leadership
The Handover
Baseline Susceptibility Report
The next phase starts from this.
- 01
Baseline and Scenario Design
We measure your starting point and design lures that match real threats to your teams, from invoice fraud to fake internal notices, tuned to be believable without being cruel.
OutputBaseline Susceptibility ReportActivities
- Measure a baseline click and report rate
- Design pretexts matched to real lures your staff receive
- Rate each scenario with the NIST Phish Scale
- Agree exclusions and tone limits with HR and leadership
- 02
Launch
We send the campaign safely to the agreed audience, at a realistic pace, without touching live systems or exposing anyone's real credentials.
OutputCampaign Launch RecordActivities
- Allowlist sending domains with your mail team
- Stage delivery in waves so results stay clean
- Brief the service desk so genuine reports are handled well
- Monitor delivery for bounces and filtering issues
- 03
Tracking and Capture
We record who opens, clicks, reports or enters details on the landing page, giving you an honest, anonymous picture of behaviour.
OutputAnonymised Behaviour DatasetActivities
- Track opens, clicks, submissions and reports per scenario
- Measure how quickly the first report reaches the service desk
- Discard real credentials at the point of capture
- Aggregate results by team so no individual is named
- 04
Reporting
We report the results by team and scenario, show trends over time, and highlight where the real risk sits so you can focus effort.
OutputCampaign Results ReportActivities
- Compare click and report rates against the baseline
- Break results down by team, role and scenario difficulty
- Show the trend across previous campaigns
- Recommend where training effort will pay off most
- 05
Targeted Follow-up Training
People who clicked receive short, relevant training straight away, and we repeat the simulation later to prove the lift is real.
OutputImprovement Trend ReportActivities
- Deliver a short training module at the moment of the click
- Explain the exact cues that gave the lure away
- Run a repeat simulation for the same group later
- Report the improvement between the two rounds
Specification
What We Run, and What We Measure You Against
The tooling our engineers use on this work, and the published standards the findings and evidence are mapped to.
What Is Examined, and What it Is Measured Against
Map
Map of the Phishing Simulations scope, running left to right in three stages. Stage one, what we run, 6 tools and techniques: GoPhish, KnowBe4, Microsoft Attack Simulator, evilginx, Mailtrap, custom landing pages. Stage two, findings from all of it are proven by hand and written up once. Stage three, measured against 4 published standards: NIST Phish Scale, NIST SP 800-50, MITRE ATT&CK, SANS Security Awareness Maturity Model.
What We Run
6 tools
- GoPhish
- KnowBe4
- Microsoft Attack Simulator
- evilginx
- Mailtrap
- custom landing pages
Converges On
One Set of Proven Findings
Every issue is reproduced by hand before it is written down, and it is written down once.
Measured Against
4 standards
- NIST Phish Scale
- NIST SP 800-50
- MITRE ATT&CK
- SANSAwareness Maturity Model
Deliverables
What You Receive
- Baseline phishing susceptibility report
- Realistic simulation campaigns on an agreed schedule
- Anonymous results by team and scenario
- Just-in-time training for those who click
- Trend report showing improvement over time
Scope This Engagement
Tell us about your environment, your timelines and any audit dates you are working to. We come back with scope, effort and a start date.
Who has to authorise a campaign, and what do you need from us before it runs?
Written authorisation from someone in your organisation empowered to give it, before a single message is sent. A simulation puts deceptive mail in front of your own staff under your own name, so the decision belongs to the business rather than to a supplier. In the scoping call, a 30 to 45 minute conversation, we agree the audience, the exclusions, the tone limits and the sending window with the security or IT owner and with HR and leadership, and those terms go into a written scope with a timeline and a fixed price before work begins. From you we need a named approver for the scenarios, a mail team who can allowlist our sending domains, and a service desk briefed to handle genuine reports properly. We do not ask individual recipients to consent in advance, because a pre-announced campaign measures nothing useful. The authorisation sits with the organisation, and it is on paper.
What do you measure besides the click rate?
Four behaviours per scenario, plus one timing. We record who opened, who clicked, who submitted details on the landing page and who reported the message, and we measure how quickly the first report reached your service desk. Click rate alone is the easiest number to move and the weakest signal, because scenario difficulty shifts it as much as behaviour does, so each scenario is rated with the NIST Phish Scale and results are broken down by team, role and difficulty rather than published as one organisational figure. Submission is counted separately from clicking, since the two carry different risk and need different follow-up. Reporting speed matters because a fast report is what turns a click into a contained incident. The Campaign Results Report sets each of these against your baseline and the rounds before it. Our guide to phishing simulation services in India goes further into which metrics predict resilience.
How often should we run simulations, and when do the results start to mean something?
Monthly or quarterly, agreed at scoping and then held steady. The first campaign is a baseline rather than a score: it tells you where you stand and nothing about whether you are improving. Meaning arrives at the repeat, when the same group meets a comparable scenario later and the Improvement Trend Report shows the difference between the two rounds. Scenario difficulty rises as performance does, which is why the Phish Scale rating travels with every result; a falling click rate against easier lures is not progress. A single campaign has its uses, as an audit artefact or a first look, and we will run one, but it is honest to say it produces a snapshot that fades rather than a change in behaviour. Cadence is what makes this work, and the rhythm matters more than the frequency you pick.
Results identify people who failed a test. How is that handled?
Individual behaviour is captured, because targeted training needs it, but it is not what we report. Results are aggregated by team, role and scenario before they reach you, so the Campaign Results Report shows where risk sits without naming anyone. Real credentials are discarded at the point of capture and never stored or passed on, so a submission is recorded as an event rather than as a password. The framing is practice, not punishment, and the tone limits agreed with HR and leadership in phase one are a scope boundary, not a courtesy. We will not supply a per-person leaderboard or a ranked list for management review, because programmes that do it stop getting reports, and the report rate is the number worth protecting. If you want individual data for your own purposes, that is a decision to take deliberately, with HR involved.
What actually happens to someone who clicks?
They get a short training module immediately, on the landing page, explaining the specific cues that gave that lure away while the moment is still fresh. Nothing is sent to their manager and no disciplinary step follows from us. The landing pages are ours, no live system is touched, and anything typed into a credential field is discarded at capture rather than checked or kept. The same group meets a comparable scenario in a later round, and the improvement between the two is reported. What this service does not include is a full awareness curriculum: the follow-up here is a few minutes tied to one click, and broader training for your whole workforce is a separate service, Awareness Trainings, in this practice area. A genuine report from a colleague goes to your service desk as usual, which is why we brief them before launch.
Related Reading
Articles on Phishing Simulations
Keep Moving Through Managed Services
Service 7 of 9 in this practice area
Practice Area
More in Managed Services
- Red Team AssessmentGoal-based adversary simulation across people, process and technology
- SOC as a ServiceA 24/7 security operations centre run by our analysts
- Attack Surface ManagementRecurring discovery of what you expose to the internet, and what is wrong with it
- Dark Web MonitoringAnalyst-validated monitoring for leaked credentials, documents and brand abuse
- vCISOSenior security leadership on demand, without a full-time hire
- vDPOA data protection officer as a service for the DPDP Act and beyond
- Awareness TrainingsSecurity training your people actually remember and use
- Digital and Cyber ForensicsSound investigation and evidence when something has gone wrong