Awareness
Practice the email, then talk about what happened.
Security awareness training here means simulated phishing and a written debrief. We host the simulator ourselves. We do not claim a library of hundreds of video courses, and we do not publish your click rate as a badge.
- Bundles
- Essentials, Pro, and Complete
- Coverage
- Continuous automated monitoring, with on-call response
- Price status
- Proposed — pending validation of hosting and staffing cost
What we watch
- Nothing in the network sense. This service is an exercise, plus the conversation after it.
- Who opened the simulation, who submitted credentials to the fake page, and who reported it.
- Whether the firm’s actual process worked: did anyone know who to tell?
What runs it
- A GoPhish fork we maintain, on a host that is not the detection stack. The upstream project has not endorsed us.
- A sending domain used only for exercises, so a campaign does not burn the domain clients already trust.
- A short briefing we write. If we later license someone else’s course library, we will say whose it is.
What a person does
- Agrees the lure with you before it goes out. Fake invoices and fake login pages are in scope. Real client, patient, or counterparty names are not.
- Runs the exercise to the list you provide.
- Debriefs in writing: what the lure was, what to change, and what not to be ashamed of.
What you decide
- Provide the list of people, and a warning that exercises happen. Surprise has a use. Surprise that includes the managing partner’s assistant on the day of a closing does not.
- Decide whether results are shared by name inside the firm. We will not post them on this website.
- Give us a reporting address so “I think this is phishing” has a destination.
Limits
- A click rate is a teaching number. It is not a measure of whether the firm is safe.
- We do not sell guaranteed behavior change.
- We will not phish a client, a patient, an opposing party, or a tax authority.
- Deliverability and abuse complaints are our operational problem to handle. They are also why this service stays on its own host.
We are not affiliated with or endorsed by the open-source projects named on this page.
The other services
- Managed EDRAn agent on the computers people work on, and a person who reads what it finds.
- Managed ITDRSign-ins, inbox rules, and admin changes in Microsoft 365 and Google Workspace.
- Managed SIEMLog sources the endpoint agent does not already cover, kept and reviewed.
- M365 Security PostureA written Microsoft 365 baseline, checked on a schedule, with drift called out.