Authorised · done-for-you · from £499

Would your staff actually click?

You can lock down every filter and still lose to one click. We run a controlled, harmless phishing test against your own team — with your written permission — and show you exactly who clicked, in a report you can take to the board. Then we train the people who need it.

Written authorisation required · your team only · no passwords ever captured

The question a filter can't answer

Your spam filter stops the email it recognises. It can't tell you what your people would do with the one that gets through.

Phishing is the single most common way UK businesses are breached — and it works on people, not software. One controlled test tells you where you actually stand, before a real attacker does.

How it works

A spoofable domain becomes a measured, trained team

One controlled test, one clear report, one gate that keeps it a security service rather than a phishing kit.

01

You authorise the test

You sign a one-page scope: your domain, your staff, a named contact, a window. No signature, no campaign — it is the line between a security service and an attack, and we hold it hard.

02

We send a realistic, safe lure

On an agreed date your team receives a believable email — a password-expiry notice, an overdue invoice, a shared document. Tailored to your sector, reviewed by a human before it sends.

03

Anyone who clicks learns instantly

A click lands on a safe page that immediately says "this was a test" and shows the exact red flags they missed. The lesson lands at the moment of the mistake — never a quarterly slideshow.

04

You get a board-ready report

Click rate, report rate, repeat offenders, and a sector benchmark — the evidence your insurer, your clients and your board now ask for.

#1

Phishing is how most UK firms get breached

£499

One-off assessment — keep the report either way

London

UK engineers — no offshore helpdesk

4.9/5

Across 47 client reviews

The £499 assessment

Everything in the one-off test

A fixed price, a clear deliverable, and no obligation to buy anything else.

One realistic simulation

A sector-tailored phishing email sent to your whole team on an agreed date — the same pretexts real attackers use against UK firms.

Immediate, personalised training

Whoever clicks gets a short, friendly "here is what you missed" the instant they click, tied to the exact email they fell for.

Branded board report

A clear PDF: click rate, report rate, repeat offenders, sector benchmark — evidence you can hand to your board, insurer or clients.

30-minute debrief

A senior engineer walks you through the result, what it means, and the two or three changes that cut your risk the most.

Pricing

Start with one test. Scale only if you want to.

No lock-in, no long-term contract. The one-off assessment stands on its own — everything beyond it is your choice.

Most popular

Would your staff click?

The one-off assessment

£499 one-off · ex VAT
  • ✓ One realistic, sector-tailored simulation
  • ✓ Instant training for anyone who clicks
  • ✓ Branded board-ready report
  • ✓ 30-minute debrief with a senior engineer
  • ✓ Keep the report whatever you decide next
Book the assessment

Per seat

For larger teams

from £3 /user/mo · ex VAT
  • ✓ Scales cleanly across 50+ staff
  • ✓ Continuous simulations, not one-off
  • ✓ New starters onboarded automatically
  • ✓ Per-user reporting for HR & the board
  • ✓ Volume pricing on request
Get a quote

Ongoing programme

Optional · after your first test

from £249 /mo · 30-day rolling
  • ✓ Quarterly simulations, varied lures
  • ✓ Continuous training for repeat clickers
  • ✓ Click rate tracked falling month on month
  • ✓ Monthly board report
  • ✓ Cancel any time — no lock-in
Talk it through

MSP or reseller? We white-label the whole programme for your clients — ask about partner pricing.

The line we never cross

A security service, not a phishing kit

The difference is consent and care. Both are built into how we work — not bolted on.

Written authorisation, always

We only ever test an organisation that has, in writing, authorised a test of its own staff. No exceptions — it is enforced in our system, not just our process.

We never capture a password

The landing page has no login box and no form. It records the click, reveals the test, and teaches. It cannot harvest a credential — by design.

Your data stays yours

The staff list is provided by you, held only for the engagement, and deleted on request. GDPR by design.

FAQ

Frequently asked questions

What is a phishing simulation?

A phishing simulation is a controlled, authorised test where we send your staff a realistic but completely safe fake phishing email, with your written permission, to measure who would click and who would report it. Anyone who clicks lands on a safe page that immediately tells them it was a test and teaches them what to look for. It answers the question a spam filter cannot: not "can we be impersonated?" but "would our own people actually fall for it?"

How much does it cost?

The one-off "Would your staff click?" assessment is £499 + VAT — one realistic simulation, immediate training for anyone who clicks, a branded board report, and a 30-minute debrief. For larger organisations we price per seat. Most firms then move to an optional ongoing programme (quarterly simulations plus continuous training) once they have seen the first result, but there is no obligation to.

Is it safe? Could it actually harm us?

Yes, it is safe. The lure lands on a page that has no login box and no form — it cannot capture a password or any data, by design. We only ever run a test an organisation has authorised in writing for its own staff, the training is supportive rather than punitive, and your staff list is held only for the engagement and deleted on request.

Will this embarrass or punish staff who click?

No — that is the fastest way to make people hide mistakes. The teachable moment is short, friendly and private to the person who clicked. The goal is a falling click rate over time, not a name-and-shame. Repeat clickers get a little more coaching, not a telling-off.

How is this different from just having a spam filter?

A spam filter blocks known-bad email before it arrives. It cannot tell you whether your people would fall for the message that gets through — and something always gets through. A simulation measures the human layer directly, and the training strengthens it. The two work together: filter to reduce what arrives, trained staff to catch the rest.

Do we have to commit to anything ongoing?

No. The £499 assessment is a one-off and you keep the report whatever you decide next. One test is a snapshot; risk moves as staff and tactics change, so most firms choose the ongoing programme — but that is your call to make after you have seen where you stand.

Find out before an attacker does.

One controlled test, a clear report, and the training to fix what it finds. £499, and you keep the report whatever you decide next.