Skip to content

Managed Phishing Simulation

The email always gets through. What happens next is the finding.

Anyone can tell you who clicked. We test whether your controls actually held — including whether multi-factor authentication stops a credential phish. Then we train, and re-test to prove the number moved.

From $997 / campaign
Scales with mailbox count · report in 48h
Price your org →
Pretexts built per engagement Localized, not translated MFA-bypass capable Re-tests on the programme Training-led, not punitive

01 · The Gap

Most phishing tests measure the wrong thing

A click rate tells you a human is a human. It does not tell you whether the click turned into an account takeover — which is the only part your board cares about.

Click rate is a vanity metric

Send a soft lure, get a low number, put it in a slide. Send a good one and the number triples. The figure says more about the email than about your defences. Report rate and time-to-report are the metrics that predict containment.

MFA is treated as the finish line

“We have MFA” is the most common reason a phishing test is scoped shallow. But adversary-in-the-middle kits have been commodity since 2022 — they relay your real login page and steal the session after the second factor succeeds. Most organisations have never tested this.

One campaign is a snapshot

A single campaign gives you a baseline and nothing else. Improvement is only visible across campaigns, against varied pretexts, with training in between. A test that is never repeated cannot show you a trend — only a moment.

From the field
On a telecom engagement we measured a 30% click rate on the first campaign. After targeted training built from what that campaign actually showed, the follow-up campaign came back at 5%. The number that changed the conversation was not the 30% — it was the delta, because it was the only thing that proved the spend worked.

02 · Anatomy

What the attack actually looks like

Four stages. Your controls get a chance to break the chain at each one, and the report tells you exactly which ones did. Select a stage.

01 · Pretext — a reason to act now

The lure is built from something your staff genuinely expect this month: a benefits window, a tax deadline, a system migration, a new tool rollout. Urgency plus plausibility beats sophistication every time.

Inbox · simulated
FromIT Services <it-support@kestrel-Iogistics.com>
Subject[Action Required] Enterprise AI Assistant access — activate by Friday
BodyA licence has been provisioned to your account. Licences not activated by this date will be reallocated…

The sender domain is not yours. The lowercase l in “logistics” has been replaced with a capital I — in most sans-serif fonts the two are pixel-identical. This is the single most common indicator staff are taught to spot, and the one they miss most often.

Premium upgrade

03 · Beyond the click

Testing whether MFA actually saves you

A second factor proves someone authenticated. It does not prove they authenticated to you.

In an adversary-in-the-middle campaign, the sign-in page is not a copy — it is a relay. The victim sees your real login screen because it is your real login screen, proxied. They enter their password, they approve the push notification, and everything succeeds. The attacker keeps the resulting session token, and the second factor is never needed again.

Employee
Enters password
Approves MFA
Relay
Passes both through
Keeps the session
Your identity provider
Sees a valid login
Grants the token

Every log entry looks legitimate, because every step was legitimate. This is why the technique defeats awareness training alone: there is nothing for the user to notice after the click.

What the campaign proves

Whether a valid session can be established from an unmanaged device.
Whether conditional access notices the location, device and impossible travel.
How long a stolen session stays usable before re-authentication is forced.
Whether your SOC detects the anomalous sign-in, and how quickly.

What actually stops it

01Phishing-resistant factors. FIDO2 security keys and passkeys are bound to the real origin, so a relay simply fails.
02Device compliance. Requiring a managed, compliant device turns a stolen credential into a dead end.
03Token protection. Binding sessions to the device that created them makes a lifted token unusable elsewhere.
04Shorter lifetimes. Aggressive re-authentication shrinks the window a stolen session is worth anything.

Rules of engagement
This campaign is opt-in, separately authorised in writing, and scoped to a named group agreed with you in advance. Captured sessions are terminated at the end of the test window and no action is ever taken with an account beyond proving access was possible.

04 · The lure library

Localized pretexts, not translated ones

A tax-refund lure that names the wrong revenue authority gets ignored. A festival bonus email sent in the wrong month gets reported. Multi-lingual content is translation; it puts the same email in another language. Localisation means the institutions, the season and the deadline are the ones your staff actually recognise — wherever in the world they sit.

You will not be picking from a catalogue — your pretexts get designed for your industry, region and calendar. These exist to show the range that design draws on. Every one is re-rendered against a fictional company on an unregistered domain; client templates are never published.

0%
Authorised in writing
0
Difficulty levels
0h
Report turnaround
0
Passwords stored

Every pretext is graded easy, moderate or hard, so a campaign can be tuned to your maturity rather than engineered for a headline number. You see the exact emails before anything is sent.

05 · Method

How a campaign runs

Roughly three weeks end to end, most of which is us working quietly in the background. Your time commitment is the first step and the debrief.

1

Scope & authorise

Target groups, difficulty, exclusions, escalation contact and written authorisation.

2

Build & localise

Pretexts selected and adapted to your industry, region and calendar. Infrastructure warmed.

3

Launch the campaign

Staggered send, live monitoring, immediate stop if anything behaves unexpectedly.

4

Debrief & train

Teachable moment on click, then training built from what this campaign actually showed.

5

Re-test

A fresh pretext against the same population, so the delta is evidence and not a claim.

The teachable moment does the work

Where a debrief page is used, anyone who clicks lands on it immediately — not a punishment, not a leaderboard, just the specific indicators they walked past while the moment is still fresh. Learning happens in the ten seconds after the mistake, or it does not happen at all. Some organisations would rather stay silent until the campaign closes and cover it in a debrief session afterwards. Both work; it is set at scoping.

Results are per person, because targeted training needs them to be. The report goes to the contact you nominate and includes a department-level summary you can circulate without singling anyone out. What you do with the detail is your policy — but we will say plainly that punitive programmes destroy reporting rates, because staff learn that admitting a click is worse than hiding one.

The simulated email as it appears in the employee's inbox, from a lookalike sender domain
The page the link opens, on a lookalike domain shown in the browser address bar
After the click — your call
What they see next is your decision
Three options, agreed at scoping before anything is sent.
ADebrief page. Teaches while the moment is fresh — but word spreads and the rest of the campaign is warned.
BSilent redirect to your real intranet. The campaign stays live for slower responders; learning happens later.
CNothing on screen. Handled offline in a debrief session once the campaign closes.

Most first-time clients pick B, then move to A once the baseline is set.

About nine seconds from inbox to click. What the employee sees after that is your decision, not a default — step 3.

06 · Investment

Price it yourself, before you talk to us

Phishing pricing scales with how many mailboxes are in scope. Move the slider.

$997
per campaign · up to 100 mailboxes
100
1005001,000+
Pretext design and localisation
Dedicated sending infrastructure
Teachable-moment debrief page
Report within 48 hours of close
Targeted training material

Estimate — not a quote. Indicative only and not an offer. Final pricing is confirmed in writing after scoping, and is fixed before you are invoiced.

Should you just buy a phishing tool instead?

Sometimes, genuinely — and we would rather say so here than waste your time on a call. Self-service phishing platforms cost a fraction of this and several are very good. The question is not which is cheaper, it is which one you have the people to operate.

Buy the tool if…
You have someone in-house with the time and judgement to write convincing pretexts and read the results.
You want continuous, low-touch drip testing rather than a measured engagement.
Budget is the binding constraint and a baseline is better than nothing. It is.
Bring us in if…
Nobody owns this. A licence nobody drives produces a dashboard nobody reads.
You need to know whether MFA actually holds — no self-service platform relays against your real identity provider.
An auditor, board or enterprise client needs a signed report, not a CSV export.
Your staff sit in several countries and a translated template is not the same as a local one.

The honest summary: a platform sells you the send. We sell the pretext design, the interpretation, the report and the accountability — the ~20 hours of skilled work that sits either side of it. If you already have those hours in-house, buy the tool.

Why the annual programme costs less per campaign

The first campaign is full price; the next three are half. That is not a volume discount, it is the actual cost curve — scoping, authorisation, infrastructure build and baselining all happen once, and only the pretext, the send and the analysis repeat. It is also where re-testing lives. Each repeat measures the population trained after the last one, so the programme produces a trend line rather than four disconnected snapshots. A single campaign can only ever give you a baseline.

Not in this engagement

Voice and SMS pretexting, physical social engineering and USB drops are quoted separately. Testing the applications behind the login is a different discipline — that is web and API assessment. We will tell you which one you actually need.

The deliverable

What lands in your inbox

The numbers that matter

Delivered, opened, clicked, submitted and — the one most reports omit — reported, with time-to-first-report.

Per person, and by department

Per-recipient results so training can be targeted, plus a department and seniority summary you can circulate more widely.

Control-by-control verdict

Which technical controls fired, which stayed silent, and what a real attacker would have reached.

The re-test delta

Same population, fresh pretext, measured after training. The single slide your board will actually read.

Want to see the depth before you commit? Request an anonymized sample report →

Questions

Before you ask

01 Do we need to tell staff in advance?
That is your call, and both approaches are defensible. Announcing that a programme exists in general terms — that periodic phishing tests are run — keeps trust high and still produces a usable baseline, because nobody knows which email is coming or when. Announcing a specific campaign does not, because it then measures the announcement rather than the awareness. Most clients tell staff a programme exists, agree that wording with us beforehand, and never announce individual campaigns.
02 Do you ever see or store our passwords?
By default, no — the standard configuration records only that a submission happened, not what was typed, so there is nothing sensitive to hold in the first place. Some clients specifically want proof that staff would hand over a real credential or upload a real document, because “they clicked” does not carry the same weight in a board paper. Where that is asked for it is agreed in writing first, captured data is encrypted at rest on infrastructure built for your engagement alone, it is never reused for anything, and it is destroyed with the rest of that environment at the end. We will always tell you which of the two you are buying.
03 We already have MFA. Do we still need this?
That is usually the strongest argument for testing rather than against it. Adversary-in-the-middle phishing relays your genuine login page and captures the session after the second factor succeeds, so the login looks legitimate in every log. If your MFA is phishing-resistant — FIDO2 keys or passkeys — the relay fails and we will report that as a control that held.
04 How long does a campaign take, and what do you need from us?
About three weeks from scoping to report, most of it invisible to you. We need three things: a list of target mailboxes, written authorisation from someone empowered to give it, and a named escalation contact we can reach during the send window. Allowlisting our sending domain is optional — without it you learn what your gateway does, which is often worth knowing.
05 Can you run pretexts for our region and language?
Yes — that is the point of the library. Lures are built around the calendar and institutions your staff actually recognise: the right tax authority, the right benefits window, the right national holidays, the right banks and couriers. A translated lure that references the wrong jurisdiction is the fastest way to get reported, which flatters your numbers and teaches nobody anything.
06 What happens to our data and your infrastructure afterwards?
Every engagement runs on its own environment — its own server and its own sending domain, built for you and used for nothing else. Nothing is shared between clients, so there is no pooled store of campaign results sitting anywhere. When the engagement closes that environment is destroyed rather than wiped and recycled, and we are happy to do it on a call with you watching if you want to see it happen. What you keep is the report.

Not on the list? info@vanshield.io

Find out what a click actually costs you.

Tell us roughly how many mailboxes are in scope. You will get a fixed price and a proposed pretext plan back — usually within 24 hours.

Carried over from the calculator
100 mailboxes · Single campaign · no MFA-bypass
Change →