Phishing simulation software

Phishing simulation that runs itself.

Realistic phishing sims for your whole company, sent on a schedule you set once. Every person gets the difficulty they need, a short lesson the moment they click, and a one-click way to report. You watch the numbers improve instead of building campaigns.

The basics

What is a phishing simulation?

A phishing simulation is a safe, realistic fake phishing email sent to your own people. It shows who clicks, who types in their details, and who reports it. Nothing harmful happens: a click leads to a short lesson instead of an attacker.

One phishing sim is a snapshot. Phishing simulations run over months are the real value: they show whether your people are getting better at spotting attacks, and they build the habit of reporting a suspicious email instead of ignoring it.

The usual measure is the phish-prone percentage: the share of people who fall for a simulated phish. The commonly cited industry baseline for untrained people is about 33%. A mature program aims for single digits.

How it works

Phishing sims that adapt to each person.

Connect your directory once. From there the program runs on its own, and nothing is sent until you go live.

01

Baseline

One phishing sim to everyone measures where you start: your phish-prone percentage against the industry baseline.

02

Adaptive difficulty

On Pro, AI Driven picks each person's next phishing sim by how they actually did: easier for people still learning, harder for people who spot everything.

03

Training at the click

Someone who clicks gets a short lesson on the spot, and an assignment by email if they leave it unfinished. Reminders follow on your schedule.

04

Report, then measure

A Report Phishing button in the mail app turns spotting into a habit, and your posture score shows the trend month by month.

What you get

Everything a phishing simulation program needs.

01 / TEMPLATES

Realistic phishing sims

More than 140 hand-built templates across credential, invoice, delivery, social and consumer themes, each with a matching sign-in or notice page. On Pro, AI drafts new ones from a short brief, and you review each before it is used.

02 / SCHEDULE

Set it once

Choose weekly, every two weeks or monthly. Sends can spread over 48 hours so people cannot warn each other, and a schedule change moves the run without redrafting it.

03 / INBOX

Lands in the inbox

Allowlist our sending servers once with step-by-step instructions for Microsoft 365 and Google Workspace, or turn on Inbox: Direct Injection and each phishing sim is placed straight into the inbox.

04 / SAFE

Nothing typed is kept

When someone types into a simulated sign-in page, we never store what they typed. We record only that it happened, so they can be offered training.

05 / REAL THREATS

From report to response

On Pro, every reported real email gets an AI verdict, your team is warned when an attack is spreading, and a confirmed phish can be pulled from every mailbox. A real attack can even become your next phishing sim.

06 / PROOF

Proof for leadership

A single posture score, a one-page board report, an insurance evidence pack, and policies signed by name. Everything your board or insurer asks for, ready when they ask.

Pricing

Phishing simulation software, priced per person.

Billed monthly for the people you actually have. When someone leaves, their seat goes to your next hire. Try it free for 30 days.

Core

$1.80 per person per month

Phishing simulations, training, reporting, directory sync and the insurance evidence pack.

Pro

$2.50 per person per month

Everything in Core, plus AI Driven, the Report Phishing button, attack alerts, mailbox removal and white label.

Questions

Phishing simulation FAQ.

What is a phishing simulation?

A safe, realistic fake phishing email sent to your own people to see who clicks, who enters details, and who reports it. Nothing harmful happens: a click leads to a short lesson instead of an attacker. Run over time, phishing sims show whether your people are getting better at spotting real attacks.

How often should you run phishing simulations?

Regularly and unpredictably works best. Many programs send phishing sims monthly. You can choose weekly, every two weeks or monthly, and spread sends over 48 hours so people cannot warn each other.

What is a good phish-prone percentage?

The commonly cited industry baseline is about 33%: roughly a third of untrained people click a simulated phish. Below that is better than average. A mature program aims for single digits.

Do phishing simulations need access to our mailboxes?

Not with The Human Vector. Simulations, training and reporting run on a read of your directory. Mailbox access is optional: you can grant it to place sims straight into inboxes or to remove a confirmed phishing email from every mailbox.

Will simulated phishing emails reach the inbox?

Yes. Either allowlist our sending servers once, with step-by-step instructions for Microsoft 365 and Google Workspace, or turn on Inbox: Direct Injection, which places each phishing sim straight into the inbox with nothing to allowlist.

How much does phishing simulation software cost?

Per person per month: Core at $1.80 and Pro at $2.50, billed monthly for the people you actually have, with a 30-day trial. Volume and contract pricing are available.

Can an MSP run phishing simulations for its clients?

Yes. MSPs add clients in bulk, launch one phishing sim across many clients at once, bill a line per client, and on Pro run the whole program under their own brand. See how it works for MSPs.

Run your first phishing sim this week.

Connect your directory, look over the baseline in Preview Mode, and go live when you are ready. Early access customers get 20% off their first 12 months.