Law 25 — run your compliance in our platform, 1 month free

Measure the human risk, and prove you did

Realistic campaigns with click and report rates by department, plus the evidence pack your ISO 27001 auditor asks for.

Fixed scope
The challenge

Awareness training without measurement proves nothing. Auditors ask for evidence that phishing resilience is tested, not that a video was watched.

Scope — included and not included
Included
  • Campaign design and pretext development
  • Landing pages
  • Click, submit and report rate measurement
  • Departmental breakdown
  • Awareness recommendations
  • Evidence pack for certification
Not included
  • Credential harvesting beyond the simulation
  • Targeting individuals without HR agreement
  • Ongoing awareness training delivery
  • Vishing or smishing unless scoped
How it works
01
Scope and consent

HR and legal sign-off, target list, communications plan.

02
Pretext design

Realistic campaigns matched to what your staff actually receive.

03
Campaign execution

Delivery, measurement, no shaming of individuals.

04
Results and evidence

Rates by department, debrief, and the evidence pack.

What you receive
  • Campaign results with click, submit and report rates
  • Departmental breakdown
  • Pretext library used
  • Awareness recommendations
  • Evidence pack referencing the relevant controls
What we need from you
  • ·HR and legal sign-off
  • ·Target list
  • ·Mail gateway allowlisting
  • ·A communications plan for afterwards
Timeline and engagement

2 to 4 weeks per campaign. Fixed scope, or recurring quarterly.

Standards, methods and tooling
GoPhishMailgunISO 27001 A.6.3Portal hosted in Canada
Frequently asked questions

Get a baseline before someone else does

One campaign tells you where you stand, by department, with evidence.