Retainer · Human risk

Phishing Simulation & Awareness (Retainer)

One simulation gives you a number. Four a year, each followed by training built from what actually happened, gives you a trend — and a trend is the only thing that tells you whether anything improved.

A single phishing test measures one morning. Behaviour is what you're trying to change, and behaviour only shows up over time.

Run one simulation and you learn your click rate on a Tuesday in March. Useful, but it tells you nothing about whether your people are getting better, and it gives a false sense of resolution — the number gets reported, everyone winces, and nothing structural changes.

Running quarterly changes the question from "how many clicked?" to "is reporting going up?" That second number is the one worth managing. A workforce that clicks occasionally but reports quickly is in far better shape than one that clicks rarely and says nothing, because the reports are what give your team time to respond.

What's included

Four simulations a year — lures written for your organisation and sector, varied each quarter so nobody learns the pattern instead of the lesson.

Click and report-rate tracking — both numbers, quarter on quarter, with reporting treated as the primary measure.

Training built from your results — a short session on the lures your people actually fell for, not a generic annual module.

A management debrief — the trend, what moved, and what to do about the parts that didn't.

BEC scenarios where appropriate — including finance-targeted payment redirection, which is where the real money is lost.

On naming and shaming

We don't do it, and we'll push back if you ask us to. Publishing the list of who clicked reliably produces one outcome: people stop reporting, because reporting means admitting they engaged. That destroys the number you actually need. Results come to you aggregated by default, and where individual follow-up matters, it should be supportive rather than punitive — we'll help you frame it that way.

Each quarter

A loop, not an annual event

01

Design

Lures built around your sector, your suppliers and the season — varied so the exercise stays honest.

02

Deliver

Safe, controlled delivery to the agreed groups, with click and report behaviour recorded.

03

Teach

A short session built from what happened this quarter — specific enough that people recognise themselves in it.

04

Compare

This quarter against the last, so you can see whether reporting is rising and where it isn't.

Where this ends

Training is not a control

Awareness reduces how often people fall for things. It does not stop determined attackers, and it is not a substitute for multi-factor authentication, mail filtering or payment verification procedures. Any vendor selling training as your phishing defence is selling you the cheapest part of the answer as though it were the whole one.

We also don't monitor your mail flow, respond to live phishing incidents, or operate your reporting mailbox. This measures and improves human behaviour on a schedule — the technical controls around it are a separate conversation, and one we're happy to have.

Find out where you actually stand

Start with one simulation if you'd rather see the number first. We'll tell you honestly whether a quarterly cycle is worth it for a team your size.