Awareness & Training

Phishing Simulation

Controlled, realistic phishing campaigns that measure human risk for real — turning results into targeted training and a metric you can show the board and the regulator.

What's included

  • Email phishing simulations across the whole organisation or targeted segments, using scenarios modelled on real attacker tradecraft — not generic templates.
  • Scenarios tailored to high-risk groups: executives, finance and procurement, HR, and IT staff holding privileged access.
  • Spear-phishing and Business Email Compromise (BEC) simulations, including executive impersonation and fraudulent payment requests.
  • Optional additional channels: SMS (smishing), voice calls (vishing), and malicious QR codes.
  • Behavioural measurement, not just clicks: open, click, credential-entry and attachment-execution rates, plus the reporting rate.
  • Response-readiness testing: did the SOC pick up the reports, and how long did escalation and containment take?

Methodology & standards

01

1. Planning and authorisation: define scope, target groups and rules of engagement, and obtain signed written authorisation from an empowered sponsor before anything is sent.

02

2. Scenario build: craft realistic lures grounded in open-source information and your actual business context, with client sign-off on every scenario before launch.

03

3. Controlled execution: staggered delivery that avoids disrupting operations, with simulation infrastructure allow-listed and operational impact monitored in real time.

04

4. Measurement and analysis: score metrics per department and job family, analysing behavioural gaps and mapping them to technical controls that can be improved.

05

5. Corrective training: route anyone who fell for the simulation into immediate micro-training, and deliver an executive report with an awareness plan for the next cycle.

Deliverables

  • Campaign plan, rules of engagement and the signed authorisation record.
  • Detailed results report with metrics per department and job family, benchmarked against previous cycles.
  • A human-risk matrix highlighting the most exposed groups and remediation priority.
  • Analysis of technical gaps exposed during the simulation (mail filtering, endpoint protection, the reporting path).
  • An executive summary with a single metric you can put in front of the board and the auditor.
  • The corrective-training package and the plan for the next cycle.

Regulatory controls it satisfies

SAMA Cyber Security Framework
Supports the continuous cyber-awareness requirement with real measurement of employee behaviour, not just training attendance.
NCA Essential Cybersecurity Controls (ECC-2)
Provides objective evidence that the awareness programme is effective and periodically measured.
ISO/IEC 27001 — Annex A
Serves the awareness, education and training control with documented periodic testing evidence.
Personal Data Protection Law (PDPL)
Participant data is minimised and used solely for awareness purposes; management reporting uses aggregated, not individual, results.

Typical timeline

The first (baseline) campaign is planned, executed and reported within two to three weeks. The real value comes from continuity: quarterly cycles that show a trend of improvement — which is what an auditor actually asks for, not a one-off result.

Common questions

Will this damage trust or make staff feel entrapped?

Not if it is run properly. We agree upfront on an educational, non-punitive tone: no names are published, management sees aggregated results, and anyone who falls for the simulation lands on a short training page explaining the signs they missed. The goal is immunity, not embarrassment.

Which metric actually matters?

The reporting rate, not the click rate alone. An organisation where 5% click but 40% report is far stronger than one where 2% click and nobody reports — because a report is what gives the security team the chance to contain early.

Do you need special authorisation before running it?

Yes, and this is non-negotiable. No campaign starts without signed written authorisation from an empowered sponsor defining scope, rules of engagement, the execution window and an emergency contact.

Does the simulation cover channels other than email?

Yes on request: SMS, voice calls and QR codes. We usually start with email as the highest-risk channel, then expand as your programme matures.