Practice Before the Real Thing
Phishing Simulations
Most breaches start with someone clicking a link. Our phishing simulations put realistic, safe lures in front of your people, then turn every click into a teachable moment rather than a real incident.
See the engagement path, 5 phasesSee the full Managed Services service index
Overview
Phishing simulations measure how your people respond to a convincing lure and help them get better over time. We design scenarios that match the threats you actually face, launch them safely, and track who clicks, who reports and who enters credentials. Nobody is named and shamed. Instead, the moment someone clicks, they get short, targeted training that sticks. Run regularly, these simulations turn your workforce into a genuine layer of defence.
Methodology
How the Engagement Runs
Every phase has a named output, so you always know what is being worked on and what lands on your side of the table.
5 Phases, 5 Named Handovers
Flow
Flow chart of the Phishing Simulations engagement, 5 phases in order, each one selectable. Phase 1, Baseline and Scenario Design. We measure your starting point and design lures that match real threats to your teams, from invoice fraud to fake internal notices, tuned to be believable without being cruel. Activities: Measure a baseline click and report rate; Design pretexts matched to real lures your staff receive; Rate each scenario with the NIST Phish Scale; Agree exclusions and tone limits with HR and leadership. Hands over Baseline Susceptibility Report. Phase 2, Launch. We send the campaign safely to the agreed audience, at a realistic pace, without touching live systems or exposing anyone's real credentials. Activities: Allowlist sending domains with your mail team; Stage delivery in waves so results stay clean; Brief the service desk so genuine reports are handled well; Monitor delivery for bounces and filtering issues. Hands over Campaign Launch Record. Phase 3, Tracking and Capture. We record who opens, clicks, reports or enters details on the landing page, giving you an honest, anonymous picture of behaviour. Activities: Track opens, clicks, submissions and reports per scenario; Measure how quickly the first report reaches the service desk; Discard real credentials at the point of capture; Aggregate results by team so no individual is named. Hands over Anonymised Behaviour Dataset. Phase 4, Reporting. We report the results by team and scenario, show trends over time, and highlight where the real risk sits so you can focus effort. Activities: Compare click and report rates against the baseline; Break results down by team, role and scenario difficulty; Show the trend across previous campaigns; Recommend where training effort will pay off most. Hands over Campaign Results Report. Phase 5, Targeted Follow-up Training. People who clicked receive short, relevant training straight away, and we repeat the simulation later to prove the lift is real. Activities: Deliver a short training module at the moment of the click; Explain the exact cues that gave the lure away; Run a repeat simulation for the same group later; Report the improvement between the two rounds. Hands over Improvement Trend Report. Each phase begins from the artefact the phase before it produced.
Phase 01 Baseline and Scenario Design
We measure your starting point and design lures that match real threats to your teams, from invoice fraud to fake internal notices, tuned to be believable without being cruel.
What Happens In This Phase
- Measure a baseline click and report rate
- Design pretexts matched to real lures your staff receive
- Rate each scenario with the NIST Phish Scale
- Agree exclusions and tone limits with HR and leadership
The Handover
Baseline Susceptibility Report
The next phase starts from this.
Phase 01 Baseline and Scenario Design
We measure your starting point and design lures that match real threats to your teams, from invoice fraud to fake internal notices, tuned to be believable without being cruel.
What Happens In This Phase
- Measure a baseline click and report rate
- Design pretexts matched to real lures your staff receive
- Rate each scenario with the NIST Phish Scale
- Agree exclusions and tone limits with HR and leadership
The Handover
Baseline Susceptibility Report
The next phase starts from this.
- 01
Baseline and Scenario Design
We measure your starting point and design lures that match real threats to your teams, from invoice fraud to fake internal notices, tuned to be believable without being cruel.
OutputBaseline Susceptibility ReportActivities
- Measure a baseline click and report rate
- Design pretexts matched to real lures your staff receive
- Rate each scenario with the NIST Phish Scale
- Agree exclusions and tone limits with HR and leadership
- 02
Launch
We send the campaign safely to the agreed audience, at a realistic pace, without touching live systems or exposing anyone's real credentials.
OutputCampaign Launch RecordActivities
- Allowlist sending domains with your mail team
- Stage delivery in waves so results stay clean
- Brief the service desk so genuine reports are handled well
- Monitor delivery for bounces and filtering issues
- 03
Tracking and Capture
We record who opens, clicks, reports or enters details on the landing page, giving you an honest, anonymous picture of behaviour.
OutputAnonymised Behaviour DatasetActivities
- Track opens, clicks, submissions and reports per scenario
- Measure how quickly the first report reaches the service desk
- Discard real credentials at the point of capture
- Aggregate results by team so no individual is named
- 04
Reporting
We report the results by team and scenario, show trends over time, and highlight where the real risk sits so you can focus effort.
OutputCampaign Results ReportActivities
- Compare click and report rates against the baseline
- Break results down by team, role and scenario difficulty
- Show the trend across previous campaigns
- Recommend where training effort will pay off most
- 05
Targeted Follow-up Training
People who clicked receive short, relevant training straight away, and we repeat the simulation later to prove the lift is real.
OutputImprovement Trend ReportActivities
- Deliver a short training module at the moment of the click
- Explain the exact cues that gave the lure away
- Run a repeat simulation for the same group later
- Report the improvement between the two rounds
Specification
What We Run, and What We Measure You Against
The tooling our engineers use on this work, and the published standards the findings and evidence are mapped to.
What Is Examined, and What it Is Measured Against
Map
Map of the Phishing Simulations scope, running left to right in three stages. Stage one, what we run, 6 tools and techniques: GoPhish, KnowBe4, Microsoft Attack Simulator, evilginx, Mailtrap, custom landing pages. Stage two, findings from all of it are proven by hand and written up once. Stage three, measured against 4 published standards: NIST Phish Scale, NIST SP 800-50, MITRE ATT&CK, SANS Security Awareness Maturity Model.
What We Run
6 tools
- Microsoft Attack Simulator
- custom landing pages
Converges On
One Set of Proven Findings
Every issue is reproduced by hand before it is written down, and it is written down once.
Measured Against
4 standards
- SANS
Deliverables
What You Receive
- Baseline phishing susceptibility report
- Realistic simulation campaigns on an agreed schedule
- Anonymous results by team and scenario
- Just-in-time training for those who click
- Trend report showing improvement over time
Scope This Engagement
Tell us about your environment, your timelines and any audit dates you are working to. We come back with scope, effort and a start date.
Will this embarrass our staff?
No. Results are reported anonymously and framed as practice, not punishment. The goal is to build instincts, so the tone stays supportive and the training that follows is genuinely helpful.
How often should we run simulations?
Regularly beats rarely. A monthly or quarterly rhythm keeps instincts sharp and lets you measure real improvement, rather than a one-off snapshot that fades.
Are the simulations safe for our systems?
Yes. We never capture real passwords or touch live systems. The lures land in inboxes, the landing pages are ours, and everything is designed to teach without risk.
Keep Moving Through Managed Services
Service 5 of 7 in this practice area
Practice Area
More in Managed Services
- Red Team AssessmentGoal-based adversary simulation across people, process and technology
- SOC as a ServiceA 24/7 security operations centre run by our analysts
- vCISOSenior security leadership on demand, without a full-time hire
- vDPOA data protection officer as a service for the DPDP Act and beyond
- Awareness TrainingsSecurity training your people actually remember and use
- Digital and Cyber ForensicsSound investigation and evidence when something has gone wrong