Baseline
A first simulated phishing campaign establishes where you stand, by team and by role.
You can vault every credential and monitor every endpoint, and one convincing email to one distracted person still opens the door. Security awareness training turns that layer from your softest target into an active control: a baseline simulation that shows where you actually stand, role-based lessons for the attacks each team is targeted with, and the completion records HIPAA, PCI-DSS and SOC 2 ask for.
The metric that matters is not how many finished the training. It is how many reported the real one.
A once-a-year training video produces a completion record and almost nothing else. A real program moves an organization up three rungs, and gives you the numbers to prove it moved.
| Stage | What it looks like |
|---|---|
| Untested | An annual slideshow, no simulation, no data. Nobody knows who would click, including the security team. |
| Measured | A first simulation reveals real susceptibility by team and by role. Uncomfortable, and the most useful day of the whole program. |
| Resilient | Regular role-based training and simulation. Clicks fall and — more importantly — reports rise, because people are actively flagging what reaches them. |
The metric that matters is not how many finished the training. It is how many reported the real one.
A first simulated phishing campaign establishes where you stand, by team and by role.
Short role-based lessons, with anyone who clicked given immediate, specific teaching rather than a scolding.
Regular simulations and brief refreshers keep awareness live between the moments that matter.
Click rates, report rates and completion records tracked over time — for you, and for your auditor.
Generic training fails because it describes threats in the abstract. These are the specific plays our penetration testing team uses in social engineering engagements, which is where the training content comes from.
A message that appears to come from an executive, demanding something immediately and discouraging the recipient from checking with anyone. The pressure is the payload — it exists to stop people verifying.
A supplier emails new bank details just ahead of a genuine payment. Finance teams see this monthly, and it works because the request is entirely ordinary and the timing is right.
A caller with just enough real detail talks support into resetting a password or adding an MFA device. Some of the largest recent breaches began exactly here, with a phone call and no technology at all.
An attacker holding a stolen password pushes approval prompts until somebody taps accept to stop the buzzing. Staff need to know that a prompt they did not trigger is an incident to report, not an annoyance to dismiss.
Executives and finance staff researched individually: real names, real projects, real timing, often lifted from LinkedIn and a press release. This is where generic training fails hardest.
Most programs are bought because a framework or an insurer asked for one. What each asks for differs, and the difference matters at audit time.
HIPAA requires a security awareness and training program for all workforce members, including periodic reminders rather than a single annual event. Completion records are what an OCR review asks to see, and "we showed everyone a video in January" is not a record. See identity security for healthcare.
PCI-DSS requires awareness training at hire and at least annually for personnel with access to the cardholder data environment, covering the threats relevant to their role. Role-relevant is the operative phrase — a generic course for everyone technically satisfies the letter and reliably fails the intent. Common across identity security for retail.
SOC 2 expects evidence that people were trained and that the training was current, collected across the observation window rather than at the end of it. That pairs with a compliance readiness assessment, where the training records are one artifact in the evidence pack.
Insurers increasingly ask for awareness training and phishing simulation on the renewal questionnaire, alongside MFA on privileged access. The answer needs to be a program with numbers behind it, not a video everyone skipped.
| What | Detail |
|---|---|
| Phishing simulation | Realistic campaigns that test who is susceptible, turning every click into a lesson rather than a statistic |
| Ongoing awareness training | Short regular lessons on credential theft, business email compromise and social engineering — not a once-a-year video |
| Role-based content | Finance learns invoice fraud, executives learn spear-phishing, the help desk learns manipulation, because those are the attacks each of them actually receives |
| Social engineering awareness | The manipulation tactics behind real breaches, taught through the lens of how our own testers use them |
| Measurable reporting | Click rates, report rates and resilience trends over time, by team and by role |
| Compliance-ready records | Completion documentation that satisfies HIPAA, PCI-DSS, SOC 2 and cyber-insurance requirements |
A phishing test tells you who clicked. A program changes what happens next time: immediate teaching for the person who clicked, role-based content for the attacks each team faces, and a trend line that shows whether reporting is rising. A test on its own produces a number and a slightly embarrassed workforce.
Continuously in small pieces, rather than annually in one block. Most frameworks require at least annual training; behavior change requires more frequent, shorter contact. The practical shape is a quarterly simulation with short lessons in between.
The completion and training records are the artifact HIPAA, PCI-DSS, SOC 2 and most insurers ask for. What each framework specifically requires differs, so we scope against the one you are being held to rather than producing a generic certificate that satisfies nobody in particular.
Click rate falling matters. Report rate rising matters more, because it means people are actively flagging what reaches them rather than quietly deleting it. A program where clicks fall and reports stay flat has taught people to be cautious, not to be useful.
Not if it is run properly. Results are reported by team and by role rather than by name, and anyone who clicks gets teaching rather than a note to their manager. A program that makes people afraid to admit a mistake is worse than no program at all, because the reporting rate is the number you were trying to raise.
It reaches the people watching for exactly that. Reported messages feed the managed SOC queue, which is how a single alert employee turns into an early warning for everybody else.
A free consultation covers what training you run today, what your framework requires and what a baseline simulation would tell you. You get the findings in writing.
Needed for the site to work — page delivery, and the spam protection on our forms. These do not track you and cannot be switched off.
Google Analytics and Microsoft Clarity, so we can see which pages are useful and which are confusing. Clarity hides anything you type into a form. We use this to improve the site, not to identify you.
ZoomInfo WebSights, which tells us which organisation a visit is likely to have come from and which pages were read. With this on, ZoomInfo may also set third-party cookies that help it recognise a visit across other websites, and may share that with its own partners. Turning this off stops all of it.