Phishing Simulation Campaign
A controlled phishing campaign measuring click, credential submission and reporting rates, with follow-up training for those who engage.
Fee & intake
Sign in to see the engagement fee (plus 7.5% VAT), complete the intake form, save a draft if you need to, then pay to submit.
- Standard
- 10 business days
- Express
- 5 business days
- Renews
- Every 6 months
Regulatory and standards basis
This engagement is performed against the following instruments. Each is cited in the deliverable at the point it is relied on.
- ISO/IEC 27001:2022 Annex A 6.3
- CBN Risk-Based Cybersecurity Framework awareness requirements
Who this is for
- Every firm with an awareness training obligation
What you receive
- 01Campaign report with click, submission and reporting rates by department
- 02Comparison against prior campaigns where available
- 03Targeted follow-up training for users who engaged
- 04Recommendations for technical email controls
How the engagement runs
Phase 1
Scope and authorisation
You define targets and sign a Testing Authorisation Form. Every in-scope target must have verified ownership — DNS TXT record, well-known file, cloud role or written attestation — before any traffic is sent.
Phase 2
Preflight
Targets are resolved, shared hosting is detected and flagged, and your emergency contact is notified that testing is beginning. Any gate failure aborts the run.
Phase 3
Automated testing
An industry-standard toolchain is run against the verified scope, mapped to OWASP ASVS, MASVS or PCI DSS 11.4 as applicable. All raw output is retained.
Phase 4
Triage and manual validation
Findings are deduplicated across tools and false positives eliminated with a recorded reason. Every critical and high finding is then reproduced and confirmed by a consultant, who also performs a scoped manual pass on business logic.
Phase 5
Reporting and retest
You receive the report with reproduction steps and evidence, plus one free retest within 90 days.
Questions
Who approves the deliverable?
A named member of the engagement team reviews it and a partner approves it. Their name, title and credentials are printed on the report, and the approval is recorded against the engagement in the portal.
Is this a manual or an automated test?
Both, and we are specific about the split. An automated toolchain covers known vulnerability classes — misconfiguration, known CVEs, injection, weak TLS, exposed services, dependency issues and secrets. A consultant then reproduces and confirms every critical and high finding, and performs a scoped manual pass on business logic: authentication flows, authorisation boundaries, insecure direct object references, workflow abuse and race conditions. We do not describe this as a fully manual test, because it is not.
What is explicitly not included?
This is not a load or stress test, not a social engineering assessment, not a physical security assessment, and not a source code review, unless you purchase those separately. Denial-of-service testing is never performed.
What do you need from us before testing starts?
A signed Testing Authorisation Form from someone with authority to give it, and proof of ownership for every in-scope target. We will also give you the static IP addresses our scanners egress from so you can allowlist them.
What happens next year?
The portal reminds you 90, 60 and 30 days before it is due, and you start a new version of this engagement pre-filled from the answers you gave last time. You update only what has changed, and you see a side-by-side of what changed before you submit.
Where do our documents live?
In private storage, accessible only through short-lived signed links, with every view and download logged. Nothing is attached to email. Our sub-processors and data residency are published on the trust page.
How do we pay?
By card through Stripe after you complete intake in the portal. You can save a draft without paying; submission happens only after payment succeeds.
Related engagements in Cybersecurity and Assurance
Business Continuity and Disaster Recovery Plan
Continuity and recovery planning built from a business impact analysis, with recovery objectives that reflect what your infrastructure can actually deliver.
CBN Risk-Based Cybersecurity Framework Assessment
An assessment against the CBN Risk-Based Cybersecurity Framework, producing the evidence base for your annual return.
Incident Response Plan and Playbooks
An incident response plan with scenario playbooks, written so an on-call engineer at 3am can follow it.