Realistic phishing sims for your whole company, sent on a schedule you set once. Every person gets the difficulty they need, a short lesson the moment they click, and a one-click way to report. You watch the numbers improve instead of building campaigns.
A phishing simulation is a safe, realistic fake phishing email sent to your own people. It shows who clicks, who types in their details, and who reports it. Nothing harmful happens: a click leads to a short lesson instead of an attacker.
One phishing sim is a snapshot. Phishing simulations run over months are the real value: they show whether your people are getting better at spotting attacks, and they build the habit of reporting a suspicious email instead of ignoring it.
The usual measure is the phish-prone percentage: the share of people who fall for a simulated phish. The commonly cited industry baseline for untrained people is about 33%. A mature program aims for single digits.
Connect your directory once. From there the program runs on its own, and nothing is sent until you go live.
One phishing sim to everyone measures where you start: your phish-prone percentage against the industry baseline.
On Pro, AI Driven picks each person's next phishing sim by how they actually did: easier for people still learning, harder for people who spot everything.
Someone who clicks gets a short lesson on the spot, and an assignment by email if they leave it unfinished. Reminders follow on your schedule.
A Report Phishing button in the mail app turns spotting into a habit, and your posture score shows the trend month by month.
More than 140 hand-built templates across credential, invoice, delivery, social and consumer themes, each with a matching sign-in or notice page. On Pro, AI drafts new ones from a short brief, and you review each before it is used.
Choose weekly, every two weeks or monthly. Sends can spread over 48 hours so people cannot warn each other, and a schedule change moves the run without redrafting it.
Allowlist our sending servers once with step-by-step instructions for Microsoft 365 and Google Workspace, or turn on Inbox: Direct Injection and each phishing sim is placed straight into the inbox.
When someone types into a simulated sign-in page, we never store what they typed. We record only that it happened, so they can be offered training.
On Pro, every reported real email gets an AI verdict, your team is warned when an attack is spreading, and a confirmed phish can be pulled from every mailbox. A real attack can even become your next phishing sim.
A single posture score, a one-page board report, an insurance evidence pack, and policies signed by name. Everything your board or insurer asks for, ready when they ask.
Billed monthly for the people you actually have. When someone leaves, their seat goes to your next hire. Try it free for 30 days.
Phishing simulations, training, reporting, directory sync and the insurance evidence pack.
Everything in Core, plus AI Driven, the Report Phishing button, attack alerts, mailbox removal and white label.
A safe, realistic fake phishing email sent to your own people to see who clicks, who enters details, and who reports it. Nothing harmful happens: a click leads to a short lesson instead of an attacker. Run over time, phishing sims show whether your people are getting better at spotting real attacks.
Regularly and unpredictably works best. Many programs send phishing sims monthly. You can choose weekly, every two weeks or monthly, and spread sends over 48 hours so people cannot warn each other.
The commonly cited industry baseline is about 33%: roughly a third of untrained people click a simulated phish. Below that is better than average. A mature program aims for single digits.
Not with The Human Vector. Simulations, training and reporting run on a read of your directory. Mailbox access is optional: you can grant it to place sims straight into inboxes or to remove a confirmed phishing email from every mailbox.
Yes. Either allowlist our sending servers once, with step-by-step instructions for Microsoft 365 and Google Workspace, or turn on Inbox: Direct Injection, which places each phishing sim straight into the inbox with nothing to allowlist.
Per person per month: Core at $1.80 and Pro at $2.50, billed monthly for the people you actually have, with a 30-day trial. Volume and contract pricing are available.
Yes. MSPs add clients in bulk, launch one phishing sim across many clients at once, bill a line per client, and on Pro run the whole program under their own brand. See how it works for MSPs.
Connect your directory, look over the baseline in Preview Mode, and go live when you are ready. Early access customers get 20% off their first 12 months.