Measure the human risk, and prove you did
Realistic campaigns with click and report rates by department, plus the evidence pack your ISO 27001 auditor asks for.
The challenge
Awareness training without measurement proves nothing. Auditors ask for evidence that phishing resilience is tested, not that a video was watched.
Scope — included and not included
Included
- Campaign design and pretext development
- Landing pages
- Click, submit and report rate measurement
- Departmental breakdown
- Awareness recommendations
- Evidence pack for certification
Not included
- Credential harvesting beyond the simulation
- Targeting individuals without HR agreement
- Ongoing awareness training delivery
- Vishing or smishing unless scoped
How it works
01
Scope and consent
HR and legal sign-off, target list, communications plan.
02
Pretext design
Realistic campaigns matched to what your staff actually receive.
03
Campaign execution
Delivery, measurement, no shaming of individuals.
04
Results and evidence
Rates by department, debrief, and the evidence pack.
What you receive
- →Campaign results with click, submit and report rates
- →Departmental breakdown
- →Pretext library used
- →Awareness recommendations
- →Evidence pack referencing the relevant controls
What we need from you
- ·HR and legal sign-off
- ·Target list
- ·Mail gateway allowlisting
- ·A communications plan for afterwards
Timeline and engagement
2 to 4 weeks per campaign. Fixed scope, or recurring quarterly.
Standards, methods and tooling
GoPhishMailgunISO 27001 A.6.3Portal hosted in Canada
Frequently asked questions