Adaptive Human Risk Intelligence

Your firewall is strong.
Your people are the target.

PhishingPulse continuously tests how your employees respond to realistic phishing attacks, measures their behaviour, and turns it into a live human-risk score — for every person, every department, and the whole organisation.

62%of breaches involve a human
9/yrsimulations per employee
1score your board understands
Human Risk Dashboard
82
Report rate▲ 71%
Click-through▼ 9%
Champions148
Need support21
BUILT FOR Banking & BFSI Insurance Healthcare Manufacturing Government Telecom
The problem

Most organisations can't answer one simple question

"How exposed are we, through our own people, right now?" Training completion tells you who attended. It doesn't tell you whether behaviour actually changed.

62%

of breaches involve a human element — one click, one password, one approval.

9.3%

average phishing simulation failure rate across 183M simulated messages.

33%

untrained click rate — falling under 5% after a year of a real programme.

How it works

Six steps, running continuously

Simulate, measure, teach, and adapt — then repeat, harder, as difficulty climbs toward spear-phishing across the year.

1

Upload

HR list in. Auto-segmented by department & role.

2

Simulate

Realistic lure — a different one per person, per wave.

3

Measure

Every action captured through a privacy-safe token.

4

Teach

An instant, tailored lesson the moment someone slips.

5

Score

Behaviour becomes a number out of 100.

6

Adapt

Those who fail get more — precisely targeted.

The simulation engine

Build a year of realistic attacks in minutes

Start from any angle — the attacker's goal, the tactic, the delivery technique, the psychological trigger, or who it impersonates. Describe what you want, and PhishingPulse recommends the rest.

  • A library of realistic payloads across Identity, Device & Data attacks
  • Twelve psychological triggers — authority, urgency, scarcity, fear and more
  • Time-sensitive lures scheduled for the high-pressure moments attackers use
  • Fully brandable, or build your own custom simulations
Simulation Builder
By GoalBy TacticBy TechniqueBy TriggerBy Sender
Detected from "CEO, credential link, urgent, before 5 PM"
Identity CompromiseCredential HarvestingWeb LinkCEOAuthority + Urgency
Recommended send window
Friday · 16:50
Human risk scoring

One score. Traceable to every action.

Every employee starts at 100. Each risky action carries a defined weight, capped by category, so the worst case is bounded and explainable to a board in a single line.

  • Category-capped model — Identity 25, Device 25, Data 20
  • Steps that sum exactly to the cap — no arbitrary penalties
  • Rolls up cleanly from person → department → organisation
  • Five clear risk bands, from "No Risk Detected" to "Critical"
Scoring journey — one Identity simulation
Click
−5
Submit creds
−20
=
Cap
25
Organisation score by category
Identity
81
Device
81
Data
86
The platform

Everything a modern awareness programme needs

One platform, from the first simulation to the board report — and the year that follows.

🎯

Adaptive simulations

Fail once and PhishingPulse re-tests you on the same attack type until you master it — or flags a precise, named weakness for the security team.

🧠

Psychological triggers

Learn not just that people are vulnerable, but exactly which manipulation — authority, scarcity, fear — works on your workforce.

📊

Board-ready reporting

One clear human-risk score with the trend, the department breakdown, and auto-written priority recommendations.

🎓

Adaptive learning

Targeted micro-training delivered at the moment of failure — when the lesson actually sticks. (Coming soon.)

📧

Email security posture

Test what your gateway actually catches with safe, inert artifacts — no real malware, ever.

🔒

Private & safe by design

Passwords are never captured. Tokens keep behaviour and identity separate. Minimal data, tenant-isolated.

Built on evidence

Fair, measurable, and grounded in real research

Every employee faces the same standardised set of simulations across the year — just in a different order and at different times. So comparing two people's scores is comparing like with like, and no single warning at the water cooler covers everyone.

⚖️

Fair by design

A standardised annual set means scores are directly comparable across people and departments — defensible to management and to employees.

🔬

Evidence-led

Grounded in published research — Verizon DBIR, Proofpoint, KnowBe4 benchmarks, and peer-reviewed field studies.

📋

Audit-ready

Produces the awareness and measurement evidence ISO 27001 clauses 7.2, 7.3, 9.1 and 10 expect — generated automatically.

Turn your people into your firewall

See PhishingPulse in action with a walkthrough tailored to your organisation. We'll show you the simulation engine, the scoring model, and the reports your board will actually use.