Skip to main content
Home/Services/Phishing Simulation
Security Testing

Phishing Simulation

Test your employees with realistic phishing campaigns before real attackers do

SOC 2 HIPAA PCI-DSS ISO 27001 NIST CSF CMMC GDPR
engagement log Phishing Simulation testing
day 01scopetargets confirmed · rules of engagement signedagreed
day 01reconattack surface mappedcomplete
day 02findingHigh click rates on CEO/executive impersonationcritical
day 03findingFinance teams vulnerable to invoice fraudhigh
day 04triagereviewed and countersigned by a Lorikeet pentesterpublished
day 04delivertickets opened in your tracker201
afterretestfixes verified · included in scopeno charge
retest included human countersigned report your auditor accepts
Annual subscriptiontypical duration $7,500/yearfixed scope, from 8deliverables 8methodology stages
Scope

What this engagement covers

The service

Our Phishing Simulation service sends realistic, customized phishing emails to your employees and measures who clicks, who reports, and who enters credentials. You get detailed analytics showing which departments, roles, and individuals are most at risk - plus automated follow-up training for anyone who fails. Run campaigns monthly, quarterly, or on-demand. Every simulation is built from real-world attack templates and customized for your industry.

What we test

Our simulations cover all major phishing vectors: credential harvesting with fake login pages, business email compromise (CEO fraud), spear phishing targeting specific roles, attachment-based payloads (macros, PDFs), QR code phishing (quishing), SMS phishing (smishing), multi-stage campaigns with follow-up emails, invoice and payment fraud scenarios, IT support impersonation, and vendor/supply chain phishing.

Method

How we run it

We start by profiling your organization to create relevant, believable scenarios. Campaigns are deployed on a schedule you choose, with randomized send times to avoid pattern detection. Employees who click get immediate, non-punitive training that explains what they missed. Results feed into a risk dashboard where you can track improvement over time, compare departments, and export reports for compliance auditors.

01

Profile organization for realistic scenarios

02

Create customized phishing templates

03

Build credential harvesting landing pages

04

Deploy campaign with randomized send times

05

Track opens, clicks, credential submissions

06

Trigger immediate training for failures

07

Generate analytics and risk scores

08

Produce compliance reports and trend analysis

Deliverables

What you receive

Findings land in your tracker as you go, not only in a PDF at the end. Retest is in scope, not a change order.

  • Custom phishing campaign templates
  • Fake landing pages with credential capture
  • Automated training for employees who fail
  • Department-level risk scoring and analytics
  • Individual employee phishing susceptibility profiles
  • Campaign comparison reports (month over month)
  • Compliance-ready audit documentation
  • Executive summary with risk trends
Typical results

What we usually find

The issues this engagement surfaces most often. Yours will differ, but this is the shape of it.

High click rates on CEO/executive impersonation Finance teams vulnerable to invoice fraud IT staff susceptible to fake system alerts Low reporting rates for suspicious emails Credential submission on fake login pages Mobile users more likely to click phishing links New hires with no security training click most Seasonal spikes in susceptibility (holidays, tax season)
Fit

Who this is for

Companies with SOC 2 phishing testing requirements
Organizations with high-value financial targets
Healthcare companies with HIPAA compliance needs
Companies with remote or distributed workforces
Security teams measuring human risk reduction
Organizations that want to benchmark against industry rates
Standards this supports

Findings are mapped to SOC 2, HIPAA, PCI-DSS, ISO 27001, NIST CSF, CMMC, GDPR, so the report drops into an audit package rather than needing to be translated first. If you need the readiness work behind one of those, that is a separate engagement.

Next

Scope it in one call

Tell us what is in scope and we come back with a fixed price and a start date. No discovery-call maze, no hourly estimate that moves.

Lory waving

Hi, I'm Lory! Need help finding the right service? Click to chat!