Services

Phishing simulation

Controlled, authorized campaigns that measure employees' real reaction to a phishing email — not just whether they know in theory what phishing is.

How it works

  1. 1You launch a campaign using a realistic email template (you can pick from ready-made scenarios)
  2. 2Each target gets a unique link — opens, clicks, and form submissions are tracked separately
  3. 3The fake form intercepts the submission directly in the browser, before any data leaves the device
  4. 4Anyone who interacts (submits the form or tries to leave the page) is taken to a page explaining the test
  5. 5Relevant training is assigned automatically, with direct access via a link, no extra steps

Data & ethics

  • Emails are only sent in campaigns explicitly authorized by the client organization
  • No password or real data entered in the fake form is ever transmitted or retained
  • The purpose is strictly educational — we measure behavior, not collect sensitive personal data
  • Results can be reported in aggregate (by department/organization), not just per person

What we measure

Open rate, click rate, and form submission rate, per campaign and per person — aggregated into a simple, explainable risk score, not an opaque model. Progress is visible over time, across successive campaigns.

Want to see how your team reacts?

Book a call — we'll define the right scenario for your first campaign.