Skip to content

Security Awareness & Phishing Simulation

Test and train the people attackers actually target. Realistic phishing simulations and practical staff training, measured so you can see risk drop over time.

Most breaches start with someone clicking something, not with a firewall failing. We run controlled phishing simulations against your team, then turn the results into short, practical training that speaks to what actually happened, rather than a generic annual video nobody remembers.

You get a clear baseline, repeat testing to show whether it is improving, and reporting you can take to your board, insurer, or auditor.

Why the annual video does not work

Nearly every business has done security awareness training. Very few have changed anybody’s behaviour with it.

The reason is structural rather than a failure of content. Training delivered once a year, covering everything, in the abstract, competes for attention with the actual job and loses. By the time a convincing invoice arrives in March, July’s module has gone. And because the training was generic, it never resembled the thing that eventually turns up.

Short, frequent, and specific works considerably better. Ten minutes, immediately after a simulation that caught you, about the exact technique that caught you, is worth more than an hour in a room in a way that is easy to demonstrate and hard to argue with.

What the simulations look like

Scenarios are built to resemble what actually targets Australian businesses: invoice and payment redirection attempts, a Microsoft 365 login prompt, a message that appears to come from a manager, a delivery notice, a shared document. We vary difficulty deliberately, because a programme where every test is obvious measures nothing and one where every test is expert-level teaches only despair.

We agree the scope with leadership first, including which techniques are off limits. Some scenarios are effective and inappropriate: we do not use fake redundancy notices, bonus announcements, or anything touching somebody’s health or family. A test that damages trust in the business costs more than it measures.

Report rate is the number to watch

Click rate is the figure everybody asks about first, and it is the less useful of the two.

An attacker only needs one person to click, so driving click rate to zero is not a realistic target. What actually changes outcomes is how fast you find out. A business where someone clicks and reports it within a minute can reset a password and end the incident. A business where somebody clicks and says nothing finds out weeks later from a customer.

So we measure and report both, and we deliberately make reporting easy and socially safe. The goal is a team where telling somebody is the reflex, not one where nobody ever fails a test.

What you can show somebody

Each cycle produces reporting designed to be handed over: participation, click rate, report rate, time to first report, and the trend across rounds.

That is the evidence an insurer asks for at renewal, the answer to the staff training question on a client security questionnaire, and something concrete to put in front of a board that has been told human risk is the biggest exposure and would like to know what is being done about it.

Typical timeframe
Baseline in 2 weeks, then a rolling quarterly cycle
Best for
Any business where staff handle email, invoices, or customer data
How SPF, DKIM and DMARC combine to decide what happens to a messageSPF authenticates the return-path domain rather than the visible From address, which is why the alignment step exists.

The engagement

How it runs

Every engagement follows the same shape, so you always know which part you are in and what is coming next.

  1. 1

    Baseline

    A realistic simulation against your team, with no prior warning beyond what leadership agrees. This measures where you genuinely start rather than where a survey says you do.

  2. 2

    Train to what happened

    Short, specific training built around the scenarios your people actually fell for, delivered close to the event while it still means something.

  3. 3

    Make reporting easy

    A one-click way to report a suspicious message, and a culture where doing so is welcomed. Report rate matters more than click rate and is measured alongside it.

  4. 4

    Repeat and report

    Quarterly simulations with varied scenarios, tracked over time, with reporting suitable for a board, an insurer, or an auditor.

Common questions

Is this going to humiliate our staff?

Not the way we run it. Individual results are not circulated, nobody is named in reporting to leadership, and the framing to staff is that the business is testing its own defences rather than testing them. Programmes that shame people produce staff who hide their mistakes, which is the opposite of what you want: the goal is somebody who clicked telling you within a minute.

Do we have to tell staff it is coming?

We recommend announcing that a programme exists without announcing the timing of individual simulations. Telling people a test is coming this week measures who remembered a warning. Telling them the business runs simulations, and why, sets expectations honestly while keeping the measurement real.

What is a good click rate?

Untrained organisations commonly sit somewhere around one in four to one in three on a convincing scenario. What matters more is the direction of travel and your report rate: a team with a 10 per cent click rate and a 60 per cent report rate is in far better shape than one with a 5 per cent click rate where nobody tells anybody. We report both from the first round.

Is annual training not enough?

Annual training produces a compliance record and very little behaviour change, because a video watched in July does nothing for an invoice that arrives in March. Short, frequent, and specific beats long and annual, which is why this is structured as a quarterly cycle rather than an event.

Will this satisfy our insurer or an auditor?

Generally yes, and the reporting is built with that in mind. Insurers increasingly ask whether you run simulated phishing and can evidence staff training, and a documented programme with figures over time is a much better answer than a policy document saying you consider it important.

Incident Response

What to do in the first hour of a cyber incident

When something goes wrong, the first hour shapes how bad it gets. A calm, non-technical playbook for business owners to act on before the experts arrive.

· 3 min read

Need help with Security Awareness & Phishing Simulation?

Tell us where you are and what is worrying you. We will tell you honestly what we would do first.

Get in touch