
Operate
Phishing simulation
Realistic campaigns that measure whether people report, with coaching instead of blame — and a firm line on the pretexts we will not use, because a simulation that humiliates staff buys you one number and costs you the reporting culture.
Duration
Quarterly campaigns, or monthly at higher maturity
Built on
ISO/IEC 27001 Annex A · GDPR
Indicative price
On request
Who this is for
CISO
Wants a real measurement, not a vanity one.
IT manager
Has run simulations and seen no improvement.
HR director
Has had complaints about the last campaign.
Compliance officer
Needs the evidence, done defensibly.
You can design a simulation that anyone will fail
Every security team eventually discovers that click rate is easy to manipulate. A sufficiently cruel pretext — a bonus announcement, a redundancy list, a message appearing to come from a named colleague in distress — will catch most of any workforce, and produces a dramatic slide. It also teaches people that the security team lies to them, which costs you the thing you were trying to build.
So the position we take is that the simulation exists to raise reporting, not to prove people are fallible. Everybody is fallible; that is established. The useful questions are whether the route to report is obvious, whether people use it, and how fast.
There are pretexts we will not run. Anything touching pay, employment status, bereavement, health or a named individual's personal circumstances. They work, in the narrow sense that people click. They also generate genuine distress, HR complaints and a measurable drop in reporting for months afterwards, and no security programme recovers that quickly.
What we do run is what your people will actually receive: supplier bank detail changes, invoice and payment pretexts, internal tool notifications, shared document requests, and — increasingly — messages that are well written because a model wrote them. The old advice to look for bad spelling is dead, and the training has to say so.
Then the response matters more than the campaign. Someone who clicks gets thirty seconds of coaching at the moment of the click, not a report to their manager. Someone who reports gets an acknowledgement and a thank you, even when it was a simulation, because that is the behaviour you are paying to create.
How we do it
- 01
Scope and rules of engagement
1 week
Agreed in writing with security and HR: which pretexts are acceptable, which are excluded, who is informed in advance, and how results will be used. This document prevents the argument that otherwise happens after the first campaign.
- 02
Baseline campaign
1–2 weeks
Unannounced, realistic, measuring report rate, time to report and click rate in that order of importance.
- 03
Coaching at the moment
immediate
Thirty seconds, delivered at the click, explaining what the cue was. No manager notification, no leaderboard, no name in a report.
- 04
Analysis
1 week
By department and by workflow rather than by individual. A finance team clicking payment pretexts is a process finding, not a training finding.
- 05
Campaign cycle
quarterly
Varied pretexts, increasing realism, with difficulty matched to demonstrated maturity rather than escalating for its own sake.
- 06
Reporting
per campaign
Report rate and time to report as the headline, trend over campaigns, and the specific workflow issues each campaign exposed.
Named artefacts
What you receive
- Written rules of engagement, agreed with security and HR
- Quarterly campaigns using pretexts matched to your sector
- Report rate, time to report and click rate per campaign, by department
- In-the-moment coaching content
- Workflow findings — the process problems each campaign exposed
- Trend reporting across campaigns
- Evidence pack for auditors and insurers
What we need from you
- HR at the table when the rules of engagement are agreed. Their objections are legitimate and cheaper to hear early.
- A leadership statement that results are never used against individuals.
- A working reporting route. If reporting is hard today, fix that before the first campaign — otherwise you are measuring your own process.
- Executives in scope. Excluding leadership from simulations is common and indefensible, since they are the most impersonated people you have.
What changes
- 01Report rate and time to report improve campaign over campaign.
- 02You learn which workflows invite fraud, not which individuals are gullible.
- 03No HR complaints, because the boundaries were agreed in writing first.
- 04Executives are included, so the impersonation risk is measured.
- 05Evidence an auditor and an insurer both accept.
What it costs
On request
All prices exclude VAT.
Questions
Why is click rate not the headline?
Because it can be engineered to any value you like by choosing the pretext, which makes it useless as a trend and dangerous as a target. Report rate cannot be gamed in the same way, and it maps directly to how fast you would learn about a real attack.
Will you use a pretext about salaries or job cuts?
No. It works and it causes real distress, generates HR complaints and suppresses reporting for months. If a client insists, we will explain the trade and decline that specific pretext — that is a line we hold.
Do managers see who clicked?
No. Coaching happens at the moment of the click, and reporting is by department. If a specific individual needs support, that is a conversation with security rather than a line in a management report.
Should executives be included?
Yes, and they usually ask not to be. Executives are the most impersonated people in any organisation and the most consequential to compromise, so excluding them removes the measurement you most need.
Can we run it ourselves after a year?
That is a reasonable goal and we will hand over the rules of engagement, the scenario library and the reporting format. Most clients keep the campaign design with us and run the operational side themselves.

Leave with your top three risks documented
Thirty minutes with a senior practitioner. No slideware, no sales engineer.