Skip to content

ISO 27001, SOC 2, the DPDP Act and manual VAPT. Book a Free Scoping Call

Part of Managed Services9 services in this practice area

Practice Before the Real Thing

Phishing Simulations

Most breaches start with someone clicking a link. Our phishing simulations put realistic, safe lures in front of your people, then turn every click into a teachable moment rather than a real incident.

See the engagement path, 5 phasesSee the full Managed Services service index

Overview

Phishing simulations measure how your people respond to a convincing lure and help them get better over time. We design scenarios that match the threats you actually face, launch them safely, and track who clicks, who reports and who enters credentials. Nobody is named and shamed. Instead, the moment someone clicks, they get short, targeted training that sticks. Run regularly, these simulations turn your workforce into a genuine layer of defence.

Methodology

How the Engagement Runs

Every phase has a named output, so you always know what is being worked on and what lands on your side of the table.

The Engagement, End to End

5 Phases, 5 Named Handovers

Flow

Flow chart of the Phishing Simulations engagement, 5 phases in order, each one selectable. Phase 1, Baseline and Scenario Design. We measure your starting point and design lures that match real threats to your teams, from invoice fraud to fake internal notices, tuned to be believable without being cruel. Activities: Measure a baseline click and report rate; Design pretexts matched to real lures your staff receive; Rate each scenario with the NIST Phish Scale; Agree exclusions and tone limits with HR and leadership. Hands over Baseline Susceptibility Report. Phase 2, Launch. We send the campaign safely to the agreed audience, at a realistic pace, without touching live systems or exposing anyone's real credentials. Activities: Allowlist sending domains with your mail team; Stage delivery in waves so results stay clean; Brief the service desk so genuine reports are handled well; Monitor delivery for bounces and filtering issues. Hands over Campaign Launch Record. Phase 3, Tracking and Capture. We record who opens, clicks, reports or enters details on the landing page, giving you an honest, anonymous picture of behaviour. Activities: Track opens, clicks, submissions and reports per scenario; Measure how quickly the first report reaches the service desk; Discard real credentials at the point of capture; Aggregate results by team so no individual is named. Hands over Anonymised Behaviour Dataset. Phase 4, Reporting. We report the results by team and scenario, show trends over time, and highlight where the real risk sits so you can focus effort. Activities: Compare click and report rates against the baseline; Break results down by team, role and scenario difficulty; Show the trend across previous campaigns; Recommend where training effort will pay off most. Hands over Campaign Results Report. Phase 5, Targeted Follow-up Training. People who clicked receive short, relevant training straight away, and we repeat the simulation later to prove the lift is real. Activities: Deliver a short training module at the moment of the click; Explain the exact cues that gave the lure away; Run a repeat simulation for the same group later; Report the improvement between the two rounds. Hands over Improvement Trend Report. Each phase begins from the artefact the phase before it produced.

Phase 01 Baseline and Scenario Design

We measure your starting point and design lures that match real threats to your teams, from invoice fraud to fake internal notices, tuned to be believable without being cruel.

What Happens In This Phase

  • Measure a baseline click and report rate
  • Design pretexts matched to real lures your staff receive
  • Rate each scenario with the NIST Phish Scale
  • Agree exclusions and tone limits with HR and leadership

The Handover

Baseline Susceptibility Report

The next phase starts from this.

Read the handover cards on their own and you have the paper trail. Select a phase to see what happens inside it.
  1. 01

    Baseline and Scenario Design

    We measure your starting point and design lures that match real threats to your teams, from invoice fraud to fake internal notices, tuned to be believable without being cruel.

    OutputBaseline Susceptibility Report

    Activities

    • Measure a baseline click and report rate
    • Design pretexts matched to real lures your staff receive
    • Rate each scenario with the NIST Phish Scale
    • Agree exclusions and tone limits with HR and leadership
  2. 02

    Launch

    We send the campaign safely to the agreed audience, at a realistic pace, without touching live systems or exposing anyone's real credentials.

    OutputCampaign Launch Record

    Activities

    • Allowlist sending domains with your mail team
    • Stage delivery in waves so results stay clean
    • Brief the service desk so genuine reports are handled well
    • Monitor delivery for bounces and filtering issues
  3. 03

    Tracking and Capture

    We record who opens, clicks, reports or enters details on the landing page, giving you an honest, anonymous picture of behaviour.

    OutputAnonymised Behaviour Dataset

    Activities

    • Track opens, clicks, submissions and reports per scenario
    • Measure how quickly the first report reaches the service desk
    • Discard real credentials at the point of capture
    • Aggregate results by team so no individual is named
  4. 04

    Reporting

    We report the results by team and scenario, show trends over time, and highlight where the real risk sits so you can focus effort.

    OutputCampaign Results Report

    Activities

    • Compare click and report rates against the baseline
    • Break results down by team, role and scenario difficulty
    • Show the trend across previous campaigns
    • Recommend where training effort will pay off most
  5. 05

    Targeted Follow-up Training

    People who clicked receive short, relevant training straight away, and we repeat the simulation later to prove the lift is real.

    OutputImprovement Trend Report

    Activities

    • Deliver a short training module at the moment of the click
    • Explain the exact cues that gave the lure away
    • Run a repeat simulation for the same group later
    • Report the improvement between the two rounds

Specification

What We Run, and What We Measure You Against

The tooling our engineers use on this work, and the published standards the findings and evidence are mapped to.

Scope

What Is Examined, and What it Is Measured Against

Map

Map of the Phishing Simulations scope, running left to right in three stages. Stage one, what we run, 6 tools and techniques: GoPhish, KnowBe4, Microsoft Attack Simulator, evilginx, Mailtrap, custom landing pages. Stage two, findings from all of it are proven by hand and written up once. Stage three, measured against 4 published standards: NIST Phish Scale, NIST SP 800-50, MITRE ATT&CK, SANS Security Awareness Maturity Model.

What We Run

6 tools

  • GoPhish
  • KnowBe4
  • Microsoft Attack Simulator
  • evilginx
  • Mailtrap
  • custom landing pages

Converges On

One Set of Proven Findings

Every issue is reproduced by hand before it is written down, and it is written down once.

Measured Against

4 standards

  • NIST Phish Scale
  • NIST SP 800-50
  • MITRE ATT&CK
  • SANSAwareness Maturity Model
One pass of testing and analysis, one set of findings, then that single set is graded against every standard on the right. You are not paying for the same work once per framework.

Deliverables

What You Receive

  • Baseline phishing susceptibility report
  • Realistic simulation campaigns on an agreed schedule
  • Anonymous results by team and scenario
  • Just-in-time training for those who click
  • Trend report showing improvement over time

Scope This Engagement

Tell us about your environment, your timelines and any audit dates you are working to. We come back with scope, effort and a start date.

Questions

What Clients Ask Us

Something here not covered? Ask Us Directly.

Who has to authorise a campaign, and what do you need from us before it runs?

Written authorisation from someone in your organisation empowered to give it, before a single message is sent. A simulation puts deceptive mail in front of your own staff under your own name, so the decision belongs to the business rather than to a supplier. In the scoping call, a 30 to 45 minute conversation, we agree the audience, the exclusions, the tone limits and the sending window with the security or IT owner and with HR and leadership, and those terms go into a written scope with a timeline and a fixed price before work begins. From you we need a named approver for the scenarios, a mail team who can allowlist our sending domains, and a service desk briefed to handle genuine reports properly. We do not ask individual recipients to consent in advance, because a pre-announced campaign measures nothing useful. The authorisation sits with the organisation, and it is on paper.

What do you measure besides the click rate?

Four behaviours per scenario, plus one timing. We record who opened, who clicked, who submitted details on the landing page and who reported the message, and we measure how quickly the first report reached your service desk. Click rate alone is the easiest number to move and the weakest signal, because scenario difficulty shifts it as much as behaviour does, so each scenario is rated with the NIST Phish Scale and results are broken down by team, role and difficulty rather than published as one organisational figure. Submission is counted separately from clicking, since the two carry different risk and need different follow-up. Reporting speed matters because a fast report is what turns a click into a contained incident. The Campaign Results Report sets each of these against your baseline and the rounds before it. Our guide to phishing simulation services in India goes further into which metrics predict resilience.

How often should we run simulations, and when do the results start to mean something?

Monthly or quarterly, agreed at scoping and then held steady. The first campaign is a baseline rather than a score: it tells you where you stand and nothing about whether you are improving. Meaning arrives at the repeat, when the same group meets a comparable scenario later and the Improvement Trend Report shows the difference between the two rounds. Scenario difficulty rises as performance does, which is why the Phish Scale rating travels with every result; a falling click rate against easier lures is not progress. A single campaign has its uses, as an audit artefact or a first look, and we will run one, but it is honest to say it produces a snapshot that fades rather than a change in behaviour. Cadence is what makes this work, and the rhythm matters more than the frequency you pick.

Results identify people who failed a test. How is that handled?

Individual behaviour is captured, because targeted training needs it, but it is not what we report. Results are aggregated by team, role and scenario before they reach you, so the Campaign Results Report shows where risk sits without naming anyone. Real credentials are discarded at the point of capture and never stored or passed on, so a submission is recorded as an event rather than as a password. The framing is practice, not punishment, and the tone limits agreed with HR and leadership in phase one are a scope boundary, not a courtesy. We will not supply a per-person leaderboard or a ranked list for management review, because programmes that do it stop getting reports, and the report rate is the number worth protecting. If you want individual data for your own purposes, that is a decision to take deliberately, with HR involved.

What actually happens to someone who clicks?

They get a short training module immediately, on the landing page, explaining the specific cues that gave that lure away while the moment is still fresh. Nothing is sent to their manager and no disciplinary step follows from us. The landing pages are ours, no live system is touched, and anything typed into a credential field is discarded at capture rather than checked or kept. The same group meets a comparable scenario in a later round, and the improvement between the two is reported. What this service does not include is a full awareness curriculum: the follow-up here is a few minutes tied to one click, and broader training for your whole workforce is a separate service, Awareness Trainings, in this practice area. A genuine report from a colleague goes to your service desk as usual, which is why we brief them before launch.

Keep Moving Through Managed Services

Service 7 of 9 in this practice area