Phishing as a service
Realistic phishing simulations with measurable results on employee resilience — as a one-off or across the whole year.
What this solution includes
We run one-off or continuous phishing simulations as a service. Organizations can purchase several campaigns a year, tailored to their needs — from generic to fully targeted scenarios. Realistic simulations, detailed reports and advanced analytics deliver measurable results on employee resilience.
Assess current knowledge
Measure each employee's current level of knowledge in information and cyber security. The results form the basis for a tailored annual training plan that closes the knowledge gaps you have identified.
Test your employees
The phishing module supports both continuous and campaign-based testing. You can send randomised phishing messages to individuals day by day, or run a coordinated campaign across the whole organization. The platform lets you compare results, follow trends and measure progress over time.
Deliver targeted training
Every employee is trained in the areas of information security where they need it most, which makes the training more effective and better suited to the individual. The content is broken into short modules spread across the year, and on successful completion each person receives a certificate of attendance.
The PhishStrike platform consists of three modules. The list above shows what is included in this solution — the remaining modules can be added at any time.
One-off or year-round, generic or tailored to your company
A campaign is built from two decisions: how often the messages arrive, and how closely they resemble your own environment. The combination determines what the campaign actually measures.
One-off campaigns
A single message sent to every employee at once. Well suited to taking a snapshot before or after a training programme.
Longer, continuous campaigns
Messages are sent to employees at random throughout the year. Nobody knows when the next one is coming, so this measures genuine readiness rather than momentary attention.
Targeted phishing
The scenario and visual design are tailored to your company — a dedicated domain, a cloned corporate identity and content drawn from your own business context.
Generic phishing
General scenarios without your corporate branding — quicker and more affordable to run, well suited to regular checks.
What each targeted phishing campaign includes
The complete package, from registering the domain to reporting by department.
Preparation and delivery
- domain registration and creation of a sending account
- cloning of your company's visual identity
- preparation of the phishing scenario
- integration of the landing page into the PhishStrike platform
- execution of the phishing activity
Platform access and reporting
- administrator access to the platform
- an overview of campaign results
- audit trails of activity
- the option of reporting by department
Training for every employee who failed to recognise the phishing message.
What a phishing campaign report shows
Every campaign ends with a report that shows clearly how well employees recognise an attack — and where the gaps remain.
Campaign scope
A continuous phishing campaign between 1 January 2026 and 30 June 2026, across all departments.
Users included
1,254Phishing messages sent
1,680Entered a username and password
24%301 of 1,254 users
Phishing results
Percentages are calculated against all 1,254 users included.
In numbers: 602 users clicked the link, 401 entered personal data and 301 entered a username and password.

Rates across all employees
How many of the 1,254 users included took each action during the campaign.
Clicked the link
602 of 1,254 users
Entered personal data
401 of 1,254 users
Entered a username and password
301 of 1,254 users