Phishing Simulation & Security Awareness
Train the click, not the fear.
Realistic phishing simulations designed to assess employee preparedness against social engineering attacks.
Structured security-awareness programs enhance organizational resilience by promoting secure user behaviour and threat recognition. Campaigns are customized to your company context and delivered with just-in-time coaching.
- Campaign design & calendar
- Per-employee risk scoring
- Manager dashboards
- Quarterly awareness review
- Just-in-time micro-training module
- Measurable reduction in click rate and time-to-report
- Behaviour-based risk score per department
- Evidence package for auditors and cyber-insurance renewal
- Culture shift from 'don't click' to 'report fast'
How the engagement runs. Phase by phase.
Baseline assessment
Unannounced baseline campaign establishes honest click/report rates per department.
Segmentation
Risk scoring by role, tenure, and previous incidents; define tiers.
Campaign design
Quarterly calendar with 3–4 lures per tier, aligned to your threat model.
Launch & training
Staggered sends, just-in-time micro-training, manager visibility dashboards.
Quarterly review
Cohort comparison, trend analysis, program tuning, board-level summary.
What we actually use. No secrets.
Every tool earns its place. We publish our stack so your team can audit, review, and integrate with what we bring.
- GO
GoPhish (hardened build)Campaign orchestration, landing pages, tracking - KN
KnowBe4 / Proofpoint (optional)Enterprise training library integration
- MIMicrosoft Defender for Office 365Attack simulator + report-phish button wiring
- CUCustom lure library50+ industry-specific templates (vendor, HR, IT)
- EV
Evilginx2 (scoped)MFA-aware reverse-proxy phishing for red-team ops
- DM
DMARC / DKIM / SPF toolingSender reputation and deliverability validation
- POPower BI / Looker dashboardsDepartmental risk trends, cohort comparison
- LMLMS integration (SCORM)Auto-enroll clickers into targeted micro-courses
How we do the work. Not just what.
Graduated difficulty
Start with obvious lures and escalate to plausible spear-phishing that matches your vendor landscape.
Context-aware pretexts
Lures reference real vendors, recent company news, and quarterly events, not generic Nigerian-prince templates.
Report-first incentives
Reward reporting behaviour, not just non-clicking. A reported phish is worth more than an ignored one.
Just-in-time coaching
Clickers see a 90-second micro-lesson immediately. Retention is 6× higher than quarterly training.
Executive tier
High-risk roles (finance, execs, admins) get separate, harder lures aligned to BEC playbooks.
MFA-aware lures (optional)
For red-team engagements: Evilginx-based reverse proxy to test MFA fatigue and token replay detection.
Real problems. Real fixes.
Anonymized incidents from actual engagements: what broke, why it mattered, and how we fixed it.
Executive team refused to participate. They saw simulations as 'gotcha' exercises.
The highest-value targets were excluded, so BEC risk remained unmeasured.
Reframed program around team reporting rates (not individual shame). Ran a closed-door exec tabletop first. Participation went from 0 to 100% once leaders saw the dashboard focused on team learning, not blame.
First campaign's click rate was 42%, risk of a morale crisis.
HR leadership wanted to pause the program after week one.
Shifted the narrative: the 42% was already happening with real attackers. The program now made it visible. Paired with a 2-week reporting-championship and the rate dropped to 18% by month two.
Client's email gateway marked our sends as phishing, skewing delivery.
Campaigns looked effective only because emails never arrived.
Whitelisted our sending domain at the gateway and measured raw delivery vs. user behaviour separately. Later simulations tested whether the gateway catches our lures. Gap became a separate finding.
Campaign telemetry flow
Every event (delivered, opened, clicked, reported, trained) is captured and de-identified for aggregate reporting.
Targets, not promises.
Will employees feel punished?
Can we integrate with our existing training platform?
Is this GDPR / PIPEDA compliant?
How do you handle MFA-aware phishing?
Scope a phishing simulation engagement.
30-minute scoping call. You'll talk to an operator, not a BDR.