Phishing simulation program

Built to change behavior, not catch people out

Weekly sends, monthly unique templates. Every failed simulation triggers immediate micro-training. The report button is celebrated as much as not clicking.

Quarterly difficulty ramp

Q1

Foundation sims

Generic templates with high visual cues. Goal: establish baseline, not to trick. Every click triggers a 2-min teachable moment module immediately.

Q2

Targeted sims

Role-specific sends. BEC and payroll themes for finance. Cloud app themes for ops. Templates become more polished and harder to spot.

Q3

Multi-vector sims

QR, SMS, and vishing added alongside email. MFA push bombing. Tests whether training generalized beyond email to other attack surfaces.

Q4

Advanced sims

AI-personalized, contextually accurate templates. Near-zero visual cues. Measures whether trained behavioral skepticism holds under realistic pressure.

12-month template library

Template / scenarioDifficultyTargetVectorMonth
IT helpdesk password resetBeginnerAll staffEmailM2
Shared document notificationBeginnerAll staffEmailM2
Payroll portal updateModerateFinance/HREmailM3
MFA push bombModerateAll staffMFA simM3
CEO gift card requestModerateAdmin/EAEmailM4
Vendor invoice updateModerateFinanceEmailM8
Package delivery SMSModerateAll staffSMSM4
QR code phishAdvancedAll staffQRM9
IT helpdesk vishing callAdvancedAll staffPhoneM4
AI-personalized spear phishAdvancedLeadershipEmailM9
Fake security alertAdvancedAll staffEmailM10
Year-end baseline repeatBeginnerAll staffEmailM12

When someone clicks: the teachable moment flow

1
Instant redirect(0 sec)

Landing page immediately reveals 'This was a simulated phish.' No blame, no shame — shows exactly which cues they missed.

2
2-min micro-module(Immediate)

Bite-sized lesson specific to the template type they fell for. Right-time, right-context learning is the highest-retention intervention available.

3
Auto-enrolled in remediation(Within 24 hrs)

Platform auto-enrolls the employee in the full module for that threat type. Completes in their own time within 5 business days. No manager intervention required.

4
Manager digest(Weekly)

Department managers receive a weekly roll-up — team-level trends, not individual names. Used for coaching conversations, not performance management.

5
Repeat offender protocol(3+ clicks same vector)

After 3 fails on the same vector within 90 days: personal coaching session with IT/MSP, not disciplinary action. Re-test in 30 days.