Defined scope
Coverage, responsibilities, and exclusions documented first.
Risk & Testing
Clear priorities. Practical protection. A partner accountable for the next step.
Measure employee behavior through controlled phishing simulations and targeted follow-up coaching.
Coverage, responsibilities, and exclusions documented first.
Designed around current tools and practical constraints.
Activity, findings, and next actions made understandable.
02 / Service overview
A managed phishing exercise is a controlled learning activity, not a covert attempt to embarrass employees. Written authorization defines the audience, scenario limits, data captured, reporting route, privacy treatment, escalation contacts, and how anyone who reports the simulation will be handled.
Results are interpreted at the campaign and role level. Message delivery, reporting, link interaction, submitted simulation data, support impact, and repeat behavior can guide coaching and control improvements, but a single click does not prove that a person or organization is secure or insecure.
Core capability
Final inclusions, tooling dependencies, coverage, and response authority are confirmed during scoping.
03 / Operating fit
The strongest fit is a defined operating gap with clear owners, available inputs, and a decision the service is expected to improve.
The organization needs a controlled way to understand reporting, credential-entry, and follow-up behaviour across relevant user groups.
Finance, executives, administrators, service desks, or other exposed teams need scenarios matched to the decisions they actually make.
Campaigns require written approval, privacy boundaries, escalation contacts, and a plan for handling reports without creating unnecessary harm.
04 / Scope design
These details are confirmed during discovery and written into the proposal so both teams understand what delivery depends on and what remains outside the service.
05 / Proposal checks
A useful proposal should make the operating commitment understandable before signature. Use these checks to compare the written scope with the outcome your team actually needs.
Required inputs: written authorization and approved audiences; mail-flow and allow-list coordination where required; privacy, employee-relations, and data-retention decisions; a reporting channel and follow-up education plan. Assign an owner and readiness check to each dependency.
Expected evidence: campaign plan and scenario rationale; aggregate behaviour and reporting analysis; role-aware coaching recommendations; repeat-test plan tied to observed gaps. Name the recipient, review cadence, and decision supported by each output.
Cost assumptions: audience size and segmentation; scenario complexity and localization; campaign frequency; integration and reporting requirements. Separate onboarding, recurring delivery, and approved changes in the proposal.
Responsibility limits: campaigns do not request real passwords or sensitive data; results are not used as proof that an individual is secure or insecure; targeting and data handling follow the approved employee policy. Assign excluded decisions and adjacent work to a named owner or service.
06 / Delivery
A repeatable path from defining the need to operating and improving the service.
Confirm sponsor approval, audience, exclusions, privacy rules, scenario constraints, support contacts, data retention, and success questions.
Build role-relevant messages and landing behavior, coordinate mail flow, test tracking, and verify that no real credentials or sensitive data are requested.
Release through the approved schedule, monitor reports and operational impact, and stop or escalate the campaign if a defined safety threshold is reached.
Analyze aggregate behavior, deliver targeted guidance, assign control improvements, and plan a repeat exercise around the observed gap.
Questions
The final answer depends on your environment and agreed scope. These are useful starting points.
No. The exercise should use a controlled landing experience and capture only the minimum approved simulation events. Real credentials, payment details, and other sensitive data are not requested or retained.
Reporting and access follow the approved privacy, HR, and employee-relations policy. Aggregate and role-level analysis is usually more useful for identifying process and learning gaps; individual handling requires an explicit authorized purpose.
Observed behavior should lead to targeted coaching, clearer reporting routes, mail or identity control improvements, updated procedures, and a planned retest. A completion rate alone is not a sufficient outcome.
Related services
Explore other services in the same operating area.
Turn a broad list of possible vulnerabilities into a clear, evidence-based plan for reducing risk.
View capabilityCoordinate operating system and application patching with controlled deployments, exceptions, validation, and reporting.
View capabilitySimulate realistic attacks under controlled conditions, then turn validated findings into clear remediation priorities.
View capabilityTell us what you need to protect. We’ll help define a practical starting point around your environment, team, and priorities.