What's included
- Email phishing simulations across the whole organisation or targeted segments, using scenarios modelled on real attacker tradecraft — not generic templates.
- Scenarios tailored to high-risk groups: executives, finance and procurement, HR, and IT staff holding privileged access.
- Spear-phishing and Business Email Compromise (BEC) simulations, including executive impersonation and fraudulent payment requests.
- Optional additional channels: SMS (smishing), voice calls (vishing), and malicious QR codes.
- Behavioural measurement, not just clicks: open, click, credential-entry and attachment-execution rates, plus the reporting rate.
- Response-readiness testing: did the SOC pick up the reports, and how long did escalation and containment take?
Methodology & standards
1. Planning and authorisation: define scope, target groups and rules of engagement, and obtain signed written authorisation from an empowered sponsor before anything is sent.
2. Scenario build: craft realistic lures grounded in open-source information and your actual business context, with client sign-off on every scenario before launch.
3. Controlled execution: staggered delivery that avoids disrupting operations, with simulation infrastructure allow-listed and operational impact monitored in real time.
4. Measurement and analysis: score metrics per department and job family, analysing behavioural gaps and mapping them to technical controls that can be improved.
5. Corrective training: route anyone who fell for the simulation into immediate micro-training, and deliver an executive report with an awareness plan for the next cycle.
Deliverables
- Campaign plan, rules of engagement and the signed authorisation record.
- Detailed results report with metrics per department and job family, benchmarked against previous cycles.
- A human-risk matrix highlighting the most exposed groups and remediation priority.
- Analysis of technical gaps exposed during the simulation (mail filtering, endpoint protection, the reporting path).
- An executive summary with a single metric you can put in front of the board and the auditor.
- The corrective-training package and the plan for the next cycle.
Regulatory controls it satisfies
Typical timeline
The first (baseline) campaign is planned, executed and reported within two to three weeks. The real value comes from continuity: quarterly cycles that show a trend of improvement — which is what an auditor actually asks for, not a one-off result.
Common questions
Will this damage trust or make staff feel entrapped?
Not if it is run properly. We agree upfront on an educational, non-punitive tone: no names are published, management sees aggregated results, and anyone who falls for the simulation lands on a short training page explaining the signs they missed. The goal is immunity, not embarrassment.
Which metric actually matters?
The reporting rate, not the click rate alone. An organisation where 5% click but 40% report is far stronger than one where 2% click and nobody reports — because a report is what gives the security team the chance to contain early.
Do you need special authorisation before running it?
Yes, and this is non-negotiable. No campaign starts without signed written authorisation from an empowered sponsor defining scope, rules of engagement, the execution window and an emergency contact.
Does the simulation cover channels other than email?
Yes on request: SMS, voice calls and QR codes. We usually start with email as the highest-risk channel, then expand as your programme matures.
From the same practice