Services / Phishing simulation

Template tests teach people to spot templates.

We build campaigns from your actual vendor relationships, your actual invoice cycle, and your actual internal language. Then we report what got clicked, what got submitted, what your controls caught, and what nobody reported.

Hover any highlighted element below to see the tell.

FROMHarborline Accounts <billing@harborline-invoices.com>
TOap@harborlinemotors.com
DATEFri 4:42 PM
Updated remittance details before Monday's run

Hi,

Our banking details changed with the move to the new processor. Please update the record before Monday's payment run so nothing gets returned.

Andrea asked me to get this squared away today if possible.

Review updated details

Harborline Accounts Receivable

SPECIMEN: 4 tells, none of them a typo. Built from public reconnaissance, not a template library.

How we build them

The convincing ones do not have spelling mistakes.

Most simulation platforms ship generic templates with obvious tells, which produce reassuring numbers and teach almost nothing. We build from what reconnaissance turns up about your organization specifically.

Campaign types

  • Vendor invoice and remittance change, aimed at accounts payable
  • Internal IT notice using your real portal and SSO language
  • Shared document and file request from a platform you actually use
  • OAuth consent grant, where the target approves access rather than typing a password
  • Attachment payload simulation, macro and archive variants
  • Executive request targeting finance, with executive consent on file
  • Paired campaign: an email that lands, then a phone call that follows up

What we measure

  • Delivery rate, and which messages your filters stopped
  • Open and click rates by department
  • Credential submission rate, the number that actually matters
  • Attachment execution and consent grant rates
  • Report rate and median time to report
  • Repeat engagement across waves, aggregated not named
  • Which technical control caught it and which one let it through
Click rate The number everyone quotes. It tells you the least on its own.
Submit rate Who actually typed credentials into the page. This is the real exposure.
Report rate The only metric that improves your incident response. We track it as the headline.

How a program runs

One wave tells you where you stand. Four tell you whether anything changed.

01

Authorization and allowlisting

Signed rules of engagement, plus the technical setup on your mail platform so simulation messages reach mailboxes rather than dying in the filter. We document what was allowlisted, because that changes how the results should be read.

02

Campaign design and approval

You see every message, landing page, and pretext before it sends. Anything you veto does not run.

03

Send and monitor

Staggered delivery so the office does not compare notes in the first ten minutes. Live tracking of clicks, submissions, and reports.

04

Immediate coaching

Anyone who engages gets a short, non-punitive explanation within the hour, showing the specific tells in the message they just received. That timing is where the learning actually happens.

05

Report and trend

Results by department, control performance, and a written summary formatted as compliance evidence for FTC Safeguards 314.4(e) or HIPAA 164.308(a)(5) training requirements. Subsequent waves trend against the first.

Limits

What we will not send.

Some pretexts work extremely well and cause real harm. We do not use them.

Nothing that fakes a personal crisis

No bonus announcements, no layoff notices, no benefits terminations, no health or family emergencies. These produce high click rates and lasting resentment, and they poison the program you are trying to build.

No real brands or named people

We do not impersonate a specific vendor's real employee, a bank you use, or a government agency. Generic roles and lookalike infrastructure we control, always.

Nothing is captured beyond the fact of submission

Landing pages record that a credential was submitted. They do not store the credential. Passwords typed into our page are discarded, never logged.

Results are aggregate

Rates by department, with our contract barring results from being the sole basis for discipline. Repeat clickers are addressed through coaching patterns, not name lists.

Reporting is always rewarded

Every campaign includes a report path and every report gets acknowledged. If reporting feels pointless, staff stop doing it, and then you lose the hours that matter during a real incident.

Customers never receive anything

Simulation mail goes to authorized employee mailboxes only. Nothing leaves the approved roster.

Common questions

Before you scope it.

We already run phishing tests through our security awareness platform. Why add this?

Because those campaigns are built from a shared template library, and after two rounds your staff are pattern-matching the platform rather than the tactic. Our value is in campaigns built from your specific vendor relationships and reconnaissance, which is what a targeted attacker does. Many clients keep their existing platform for volume and use us for a sharper annual assessment.

Should we allowlist your messages?

It depends what you want to learn. Allowlisting tests your people. Not allowlisting tests your controls and your people together, but a heavy filter can eat the campaign and leave you with meaningless numbers. We usually run one wave each way and report them separately, because those are two different questions.

Do you store the passwords people type in?

No. The landing page records that a submission occurred and nothing about its contents. There is no scenario where holding your employees' real passwords improves the report, and every scenario where it creates liability.

What counts as a good result?

A low submit rate and a high, fast report rate. A campaign where nobody clicked but nobody reported either is not a win, it means a real message would have sat unnoticed. We treat report rate as the headline metric for exactly that reason.

Can you combine this with the phone calls?

Yes, and it is the most realistic thing we offer. An email that establishes a pretext followed by a call that closes it is how real intrusions run. Scoped as a paired campaign with both authorizations in one agreement.

Will this satisfy our compliance requirement?

The report is formatted as evidence of the training and testing obligations under the FTC Safeguards Rule and the HIPAA Security Rule, with dates, scope, results, and remediation. Whether that satisfies your specific obligation is a determination for your compliance counsel, and we will give them whatever documentation they ask for.

Request a scope

Find out what lands in your inboxes.

We come back with a scope, a fixed price, and the authorization paperwork you would need to sign. No obligation to run it.

Or call 888.788.ZERO
An Espyonaj engagement is delivered by Nwaj Tech.

We reply within one business day. Nothing runs without a signed authorization.

Request captured. Connect this form to your backend to deliver it.