Phishing Simulation

A simulation everybody passes has taught you nothing. We run campaigns calibrated to what is actually being sent to your sector, and report the click as a process problem rather than a person problem.

Typical duration
3–12 months
Primary audience
Both
You leave with
A measured, improving reporting rate — and a short list of the processes that let a convincing email through.

Three phases, start to finish.

  1. 01 Baseline and rules One unannounced campaign to establish where you actually are, and a written agreement on what we will never simulate. Redundancy, bonuses and bereavement are off the table. Unannounced baseline campaign across the whole population Prohibited pretexts agreed in writing before anything is sent Reporting route tested end to end, so a report reaches a human
  2. 02 Calibrated campaigns Lures built from what is currently landing in your sector — invoice fraud, supplier impersonation, MFA fatigue, internal-tool clones. Difficulty rises as the population improves. Sector-specific pretexts refreshed each cycle from current threat reporting Business email compromise and MFA-fatigue scenarios, not credential pages alone Difficulty stepped up as reporting rates improve, so the signal stays real
  3. 03 Measure and fix the process Click rate is the vanity metric. Reporting rate, time-to-report and what happened after the report are the ones that predict how a real incident goes. Reporting rate and median time-to-report tracked cycle over cycle Named-individual results kept out of management reporting by default Findings routed into process fixes — payment verification, out-of-band approval, mail controls

Click rate is the wrong metric

A population trained against one template will show an excellent click rate and still fall to a well-made lure. Click rate measures familiarity with your simulations. It does not measure what happens when a real one arrives.

The numbers that predict a real incident are reporting rate and time-to-report. A company where forty per cent of staff click but ninety per cent report within ten minutes is in far better shape than one where nobody clicks and nobody reports, because the second company has no idea an attack is under way.

How a programme runs

  1. Baseline. One unannounced campaign across the whole population, so every later number has something to be measured against.
  2. Rules of engagement. Prohibited pretexts agreed in writing first. Redundancy, bonuses, disciplinary action and bereavement are off the table — a simulation that damages trust costs more than the finding is worth.
  3. Quarterly campaigns. Lures built from what is currently landing in your sector: invoice fraud, supplier bank-detail changes, MFA fatigue, internal-tool clones, and the executive impersonation that arrives the week your funding round is announced.
  4. Escalating difficulty. As reporting rates improve, the lures get better. A programme that stays at the same difficulty stops measuring anything after two cycles.
  5. Process fixes. Every campaign produces at least one finding that is not about people — an unverified payment path, a missing out-of-band approval, a mail control that should have caught the spoof.

Nobody gets named

Individual results route training and nothing else. Management reporting is aggregate by default. Programmes that punish clicks train staff to stay quiet about the one that mattered, which is precisely the behaviour you are paying to eliminate.

Reporting your board can read

Each cycle produces a one-page trend — reporting rate, median time-to-report, and the process gaps closed since the last campaign — alongside the detail your security team needs. Attendance and outcome records are formatted for ISO 27001 Annex A 6.3 and the relevant Trust Services Criteria, so the programme doubles as audit evidence.

Phishing Simulation: the questions we get asked.

Will staff be named or disciplined for clicking?

Not through us. Individual results are used to route training and nothing else; management reporting is aggregate by default. Programmes that punish clicks train people to stay quiet, which is the opposite of what you are buying.

How often should we run simulations?

Quarterly is the cadence that changes behaviour without producing fatigue. Monthly campaigns tend to be recognised as tests rather than read as email; annual ones measure nothing but the week they run in.

What is a good click rate?

It is the wrong question. A population trained to recognise a specific template will show a low click rate and still fall to a well-made lure. Track reporting rate and time-to-report — those tell you what will actually happen when a real one arrives.

Do you provide the training that follows a click?

Yes — see Security Awareness Training. The two run as one programme when you buy both, so the training a person receives is the one matched to the lure they fell for.

Other lines of work

All services

Tell us what triggered the search. We will scope to that.

We reply to every assessment request within one business day.