Phishing simulation — because your staff is your last line of defence.
Realistic phishing emails sent to your team on a rotating schedule. Immediate training when someone clicks. Monthly reports that show your click-through rate dropping over time. Baseline campaign $299, ongoing plans from $99/month.
The best firewall in the world doesn't matter if someone gives away their password.
Every year we see the same pattern: businesses invest heavily in firewalls, endpoint security, and backup — and get compromised anyway because someone clicked a convincing-looking email and typed their password into a fake Microsoft login page. Phishing is still, by a wide margin, the number one entry point for ransomware and business-email-compromise attacks.
You can't fix that with more software. You fix it by teaching your staff to recognize what real phishing looks like — not through a boring annual video, but through repeated, realistic simulations that build the reflex to hesitate before clicking.
That's what this service does. Real phishing emails, sent to your team on a schedule they don't know about, using templates crafted for your industry. When someone clicks, they get an immediate teaching moment (not a public shaming). Over months, the click-through rate drops measurably and stays down.
Baseline first, then ongoing. Every month builds on the last.
Baseline campaign (month 1)
Every employee gets at least one phishing test across the month, using a variety of templates. Gives us a map of who's vulnerable, what patterns work, and where the risk is concentrated. Wraps with a risk-assessment report naming individual users if you want that level of detail.
Ongoing monthly plan (month 2+)
10-15 randomly selected users per month (Standard tier) get realistic phishing emails. Rotating targets — no one knows when they're next. Monthly report shows click rate, reporting rate, and month-over-month improvement. Templates evolve as attackers evolve.
A real service, not a self-serve platform.
Custom phishing templates
Rotating targets
Monthly reports
Immediate training on click
Recognition for good behaviour
Templates evolve monthly
One-time setup, then simple monthly tiers.
Full-organization assessment. Every employee tested at least once with varied templates. Includes risk report identifying most vulnerable users.
| Tier | Monthly | Coverage |
|---|---|---|
| Standard | $99/mo | 10-15 random users targeted per month |
| Enhanced | $149/mo | Up to 30 users targeted per month |
| Full Coverage | $199/mo | Entire organization targeted every month |
| Large Organization | $299/mo | 51-100 employees, entire org each month |
No long-term contract. Cancel at any month boundary — no fees. Larger organizations (100+ employees) quoted separately.
Phishing simulation FAQ
Why phishing simulation? Won't my staff resent being 'tested'?+
The opposite, in our experience — done right, staff appreciate it. The point isn't to shame anyone; it's to spot the specific patterns your team falls for so we can train against them. We frame every campaign as a team-improvement exercise, not an individual gotcha. After the first month or two, most staff actually enjoy trying to spot the tests.
How does the baseline campaign work?+
The baseline is a one-month setup phase where we send a variety of phishing templates to every single employee at least once. That gives us a starting map — who clicks, who reports, who ignores. From there, we identify your most vulnerable users and craft the ongoing monthly plan around what your team actually needs training on. The $299 baseline fee covers the setup, templates, and initial risk assessment.
What kind of phishing emails do you use?+
Realistic ones — the kind you'd actually see in the wild. Fake DocuSign links, fake Microsoft 365 login pages, fake courier delivery notices, fake HR memos, fake IT-department password-reset requests. We customize the templates for your industry — an insurance office gets different lures than a construction company. The point is realism; if the tests are obviously fake, they don't teach anything.
What happens if someone clicks or enters their credentials?+
They see a landing page immediately that explains it was a test, points out what should have tipped them off, and links to a short training module. No public shaming, no HR incident — just a teaching moment. We track it in your monthly report so we can see trends, but individual results are between the employee and management.
Do you provide the actual training too, or just the simulation?+
The simulation IS the training — that's the point. Every failed test triggers a short module that explains what went wrong. Over time, the click-through rate on your organization drops as staff learn to spot the patterns. For clients wanting deeper training (regulated industries, higher-risk staff), we can layer on optional monthly training modules; ask us during the baseline call.
What do the monthly reports include?+
Click-through rate, credential-submission rate, reporting rate (people who identified the phish and reported it), which templates worked, which specific users are consistently at risk, and month-over-month trend charts. Delivered by email on the first of each month, with your account manager available if you want to talk through anything.
Can we run this alongside our own IT team?+
Yes — this is an outsourced service that runs independently of whoever manages your IT day-to-day. Your IT team gets copied on reports if you want, and we coordinate with them so simulated attacks don't trigger real alerts. Works whether we're your MSP or not.
Are there setup or cancellation fees beyond the baseline?+
The $299 baseline fee is one-time. After that, monthly plans are month-to-month with no cancellation fee. If you decide it's not working after 6 months, drop it and pay nothing more. Most clients see meaningful click-rate drops within the first 3-4 months.
Book a baseline campaign.
One call, we agree on which employee list to test, we run the baseline campaign over 30 days, and you get a report showing exactly where your organization is most vulnerable — and how to fix it.