Services / Phishing simulation
Template tests teach people to spot templates.
We build campaigns from your actual vendor relationships, your actual invoice cycle, and your actual internal language. Then we report what got clicked, what got submitted, what your controls caught, and what nobody reported.
Hover any highlighted element below to see the tell.
Hi,
Our banking details changed with the move to the new processor. Please update the record before Monday's payment run so nothing gets returned.
Andrea asked me to get this squared away today if possible.
Review updated detailsHarborline Accounts Receivable
How we build them
The convincing ones do not have spelling mistakes.
Most simulation platforms ship generic templates with obvious tells, which produce reassuring numbers and teach almost nothing. We build from what reconnaissance turns up about your organization specifically.
Campaign types
- Vendor invoice and remittance change, aimed at accounts payable
- Internal IT notice using your real portal and SSO language
- Shared document and file request from a platform you actually use
- OAuth consent grant, where the target approves access rather than typing a password
- Attachment payload simulation, macro and archive variants
- Executive request targeting finance, with executive consent on file
- Paired campaign: an email that lands, then a phone call that follows up
What we measure
- Delivery rate, and which messages your filters stopped
- Open and click rates by department
- Credential submission rate, the number that actually matters
- Attachment execution and consent grant rates
- Report rate and median time to report
- Repeat engagement across waves, aggregated not named
- Which technical control caught it and which one let it through
How a program runs
One wave tells you where you stand. Four tell you whether anything changed.
Authorization and allowlisting
Signed rules of engagement, plus the technical setup on your mail platform so simulation messages reach mailboxes rather than dying in the filter. We document what was allowlisted, because that changes how the results should be read.
Campaign design and approval
You see every message, landing page, and pretext before it sends. Anything you veto does not run.
Send and monitor
Staggered delivery so the office does not compare notes in the first ten minutes. Live tracking of clicks, submissions, and reports.
Immediate coaching
Anyone who engages gets a short, non-punitive explanation within the hour, showing the specific tells in the message they just received. That timing is where the learning actually happens.
Report and trend
Results by department, control performance, and a written summary formatted as compliance evidence for FTC Safeguards 314.4(e) or HIPAA 164.308(a)(5) training requirements. Subsequent waves trend against the first.
Limits
What we will not send.
Some pretexts work extremely well and cause real harm. We do not use them.
Nothing that fakes a personal crisis
No bonus announcements, no layoff notices, no benefits terminations, no health or family emergencies. These produce high click rates and lasting resentment, and they poison the program you are trying to build.
No real brands or named people
We do not impersonate a specific vendor's real employee, a bank you use, or a government agency. Generic roles and lookalike infrastructure we control, always.
Nothing is captured beyond the fact of submission
Landing pages record that a credential was submitted. They do not store the credential. Passwords typed into our page are discarded, never logged.
Results are aggregate
Rates by department, with our contract barring results from being the sole basis for discipline. Repeat clickers are addressed through coaching patterns, not name lists.
Reporting is always rewarded
Every campaign includes a report path and every report gets acknowledged. If reporting feels pointless, staff stop doing it, and then you lose the hours that matter during a real incident.
Customers never receive anything
Simulation mail goes to authorized employee mailboxes only. Nothing leaves the approved roster.
Common questions
Before you scope it.
We already run phishing tests through our security awareness platform. Why add this?
Because those campaigns are built from a shared template library, and after two rounds your staff are pattern-matching the platform rather than the tactic. Our value is in campaigns built from your specific vendor relationships and reconnaissance, which is what a targeted attacker does. Many clients keep their existing platform for volume and use us for a sharper annual assessment.
Should we allowlist your messages?
It depends what you want to learn. Allowlisting tests your people. Not allowlisting tests your controls and your people together, but a heavy filter can eat the campaign and leave you with meaningless numbers. We usually run one wave each way and report them separately, because those are two different questions.
Do you store the passwords people type in?
No. The landing page records that a submission occurred and nothing about its contents. There is no scenario where holding your employees' real passwords improves the report, and every scenario where it creates liability.
What counts as a good result?
A low submit rate and a high, fast report rate. A campaign where nobody clicked but nobody reported either is not a win, it means a real message would have sat unnoticed. We treat report rate as the headline metric for exactly that reason.
Can you combine this with the phone calls?
Yes, and it is the most realistic thing we offer. An email that establishes a pretext followed by a call that closes it is how real intrusions run. Scoped as a paired campaign with both authorizations in one agreement.
Will this satisfy our compliance requirement?
The report is formatted as evidence of the training and testing obligations under the FTC Safeguards Rule and the HIPAA Security Rule, with dates, scope, results, and remediation. Whether that satisfies your specific obligation is a determination for your compliance counsel, and we will give them whatever documentation they ask for.
Request a scope
Find out what lands in your inboxes.
We come back with a scope, a fixed price, and the authorization paperwork you would need to sign. No obligation to run it.
Or call 888.788.ZERO
An Espyonaj engagement is delivered by Nwaj Tech.
We reply within one business day. Nothing runs without a signed authorization.