Cybersecurity
Phishing simulation (Jigphish®)
Find out who clicks before a criminal does.
What this work consists of
We send fake scam emails, written with the same care a real scammer would put into theirs, and measure actual behavior: who opens, who clicks, who hands over a password. Nobody who falls for it ends up on a blame list. They get training at the exact moment of the mistake, which is when the lesson sticks.
The campaign starts before anything is sent. We write the lures for your context, using themes that actually circulate in your operation, and set up the technical allowlisting so the message reaches the inbox instead of dying in the filter. Without that preparation, the result measures your filter, and what we want to measure is people.
On your side, we need a point of contact on the team that manages email, for the allowlisting, and a decision on who participates. You receive the behavior report and the comparison across departments, with no individual exposure: the data is there to steer the next round of training.
The pilot shows where you stand today, the snapshot you present internally to decide the next step. The ongoing program is what answers whether the company is improving. Behavior changes through repetition, and it is the curve dropping round after round, with quarterly indicators, that proves the investment.
How we conduct it, stage by stage
The stages and deliverables below describe the Continuous programme modality. The other modalities appear when you request the proposal.
Campaign preparation
We write the scams for your context and sort out the technical allowances, so the email reaches the inbox instead of the filter.
Send and measure
The campaign goes live and we measure real behaviour: who opened, who clicked, who handed over a password.
Training and results
Anyone who fell for it gets the training at the moment of the mistake. You get the result by area, with nobody named.
Continuous operation
Throughout the contract we keep what was built alive: we review it at every relevant change, run what is on the calendar and report at the agreed frequency. It is what separates a delivered document from a practice still worth something a year later.
What is not included
- Punishing or exposing individuals who clicked, which destroys trust and teaches people to hide the next mistake
- Phone calls or in-person social engineering, which is a separate service
- Configuring your environment's email defenses, which stays with your team; we only request the campaign allowlisting
- A full formal security training program, which comes as a separate offering; here the training is the just-in-time kind, at the moment of the mistake
- Investigating real phishing that reaches your employees during the campaign, which is incident response
- Internal communication of the results beyond the report: what the company shares, and how, is your decision
Usually comes together with
Not a bundle, and it changes nothing you have already chosen. It is what tends to come up next, in the experience of companies that have been through this.