From one click to a board-ready score

PhishingPulse runs a continuous loop: simulate a realistic attack, measure exactly what each person does, teach them the moment they slip, score the behaviour, and adapt to the individual.

1

Upload & segment

HR provides a simple employee list. PhishingPulse auto-segments everyone into departments, roles and hierarchy — no manual work.

2

Simulate

Realistic simulations go out. Each person in a wave receives a different payload at a different time, so nobody can warn the floor.

3

Measure

Every action — opened, clicked, submitted, approved — is captured through a privacy-safe token. We record what happened, never what was typed.

4

Teach

The instant someone falls for a simulation, they see a short, tailored lesson explaining the exact tell they missed.

5

Score

Behaviour becomes a number out of 100 — per person, per department, and organisation-wide.

6

Adapt

Those who fail are re-tested on the same attack type until they master it, or are flagged with a precise, named weakness.

Detection, explained

How we detect each action — without agents

Everything rests on one idea: a unique, meaningless token for each recipient, and a handful of ordinary web requests. No software on any device. No access to your mailbox.

  • Link / QR: a tracked redirect carrying the token records the click.
  • Credentials: a neutered page logs that a submission happened — the values are discarded instantly.
  • Attachment: a tracked download, then an inert beacon if it's opened.
  • Approval: a mock approval screen — no connection to your real identity provider.
Employee
name · work email
Unique token
7f3a92e1 · random
Event log
token + action · never content
The adaptive loop

Fail once, and the system responds to you

Failing a simulation doesn't just cost points — it triggers a response tailored to that individual. Not a generic course months later, but the same attack type, again, now.

  • Re-tested on the same category and tactic — a different payload each time
  • Up to three attempts, then the system stops and records the weakness
  • The output is a precise, named gap the security team can act on
  • Targeted micro-training at the point of failure — coming soon
Failed
Cred. Harvesting
Re-sent
new payload
Flagged
named weakness
Fairness

Why everyone gets the same test — just jumbled

Across the year, every employee faces the same standardised set of simulations. Only the order and timing vary per person. So comparing two people's scores is comparing like with like — and no single warning at the water cooler covers everyone.

Questions

Frequently asked

Do you ever see or store our employees' passwords? +
Never. When someone submits a simulated login, the system records only that a submission happened. The values are discarded at the point of receipt and never reach storage, logs, or telemetry. There is no code path by which a real password enters the platform.
Do you use real malware in attachment simulations? +
No — never. We use safe, inert test artifacts and replicas that reproduce an attack's delivery method with a harmless core. No live malware ever enters the platform or your environment.
What do you need from us to get started? +
A simple employee list (name, email, ID, department, role), permission to deliver simulations to inboxes, your brand assets, and sign-off on which lure themes are off-limits. That's it — no mailbox access, no agents, no network access.
How many simulations does each person receive? +
Nine mandatory simulations a year — three from each attack category — spread roughly one every five to six weeks, with difficulty rising toward spear-phishing. Those who fail receive additional adaptive simulations, subject to strict frequency caps.
Can we see individual scores, or only department-level? +
That's your decision, configured before the first campaign. Many customers restrict everyone below the security team to department-level aggregates. We default to the more private option.

See the full workflow in action

A tailored walkthrough of the simulation engine, the scoring model, and the reports your board will actually use.