Skip to content

Phishing simulation

Test people the way attackers actually test them

Most programmes send one email template to everybody once a quarter. SafeLoop generates a lure per person from role, department, tenure and prior behaviour, then delivers it over the channel that person is genuinely reachable on — including the staff who have no corporate mailbox.

4
delivery channels
5
difficulty tiers
0
credentials stored
Parcel ServiceDelivery failed — rescheduleT1IT HelpdeskMailbox quota exceededT2HR TeamUpdated leave policyT3Northwind SupplyRemittance advice — new detailsT4Priya RamanRe: Q3 migration — one more thingT5Written per person from role, tenure and what they fell for last time.

Coverage

Four channels in one campaign builder

Pick an audience and an objective. SafeLoop chooses the channel per person based on reachability and role exposure, so a depot driver gets an SMS and a finance controller gets a phone call — from the same campaign, scored on the same scale.

  • Spear-phishing and business email compromise
  • Smishing over SMS with regional short-code delivery
  • Vishing with synthesised voice and a call script
  • Quishing with QR codes sized for printed lures
EmailSpear-phishing, BEC
SMSSmishing
VoiceVishing, deepfake
QRQuishing

Targeting

Difficulty that moves with the person

Tier one is an obvious mass-market scam. Tier five is a thread hijack referencing a real internal project name. People climb as they improve and drop back when they struggle, which keeps the programme teaching instead of just recording failures.

  • Lures generated per person, not per campaign
  • Role, department, tenure and prior-failure inputs
  • Cool-down windows so nobody is tested twice in a week
Delivered: 12,000 people (100%)Delivered100%Opened: 5,280 people (44%)Opened44%Clicked: 1,140 people (9.5%)Clicked9.5%Credentials submitted: 312 people (2.6%)Credentials submitted2.6%Reported to security: 4,690 people (39%) — the outcome we optimise forReported it39%
One campaign, 12,000 recipients. Every stage is a drill-down to the people in it — the bottom row is the number SafeLoop optimises for.

How it works

The parts that decide whether a simulation is worth sending

Deliverability, safety and evidence — the three places programmes usually fall down.

Deliverability

Verified before it sends

Every campaign runs an inbox-placement test against a seed group first. If a rule is missing, you find out before 12,000 people don't receive it.

  • Dedicated simulation mail infrastructure
  • Per-tenant sending domains
Safety

Credentials are never captured

A submit is recorded as an event with a timestamp. The characters typed are discarded at the collector before anything is written to storage.

  • Enforced in code, not policy
  • Verified in third-party testing
Timing

Time-to-click, to the second

Median time to click is 21 seconds. Knowing which of your people are inside that window is more useful than knowing your average.

  • Per-person click and submit latency
  • Reported-in-under-a-minute cohort
Audiences

Directory-driven, never a CSV

Audiences follow your IdP. Dynamic rules on any attribute mean a new joiner is in scope the day their account is created.

  • SCIM with a 15-minute sync
  • Department, site and manager scoping
Consequence

A failure becomes a lesson

Anyone who clicks, submits or misses a report is enrolled in the matching module within seconds — no administrator in the loop.

  • Matched to the failure type
  • Completion written to the audit log
Automation

Campaigns over the API

Create audiences, launch campaigns and stream every event into your SIEM. The console is one client of the same API.

  • REST + signed webhooks
  • Idempotent event delivery

Specification

Channel detail

ChannelDeliveryWhat it tests
EmailDedicated MTA, per-tenant domains, allow-list wizardSpear-phishing, BEC, thread hijack, attachment lures
SMSRegional short code or long code, 40+ countriesSmishing, delivery-notification and payroll scams
VoiceOutbound call with synthesised speech and a branching scriptVishing, callback fraud, IT-helpdesk impersonation
QRPrintable and on-screen codes with per-person tokensQuishing from posters, invoices and parking notices

Every channel produces the same funnel and feeds the same Behavioral Risk Score, so results are comparable across a mixed workforce.

Questions

Asked on every first call

The ones that decide whether a first call turns into a second one.

3 questions

Will simulated phishing emails reach the inbox?

Yes. SafeLoop generates the exact allow-list configuration for Microsoft 365 Advanced Delivery, Google Workspace and your secure email gateway, then runs an inbox-placement test to a seed group before the campaign goes live. Simulations send from dedicated infrastructure rather than a shared transactional provider, whose terms forbid simulated phishing.

Do you store the passwords people type into a simulation?

Never. The submit is recorded as an event — who, which campaign, how long after delivery — and the person is coached immediately. The characters themselves are discarded at the collector before any write occurs.

How often should simulations run?

Monthly per person is the pattern that holds results. Quarterly campaigns produce a short-lived improvement that reverts within two quarters; weekly testing produces fatigue and complaints. SafeLoop paces per person with cool-down windows rather than sending to everyone on the same day.

See a live campaign against your own test group

Twenty minutes, your people, real delivery. You keep the funnel and the provisional score.

See your human risk in 20 minutes

Book a demo and we’ll run a sample campaign against a test group.