Would your staff actually click?
You can lock down every filter and still lose to one click. We run a controlled, harmless phishing test against your own team — with your written permission — and show you exactly who clicked, in a report you can take to the board. Then we train the people who need it.
Written authorisation required · your team only · no passwords ever captured
The question a filter can't answer
Your spam filter stops the email it recognises. It can't tell you what your people would do with the one that gets through.
Phishing is the single most common way UK businesses are breached — and it works on people, not software. One controlled test tells you where you actually stand, before a real attacker does.
How it works
A spoofable domain becomes a measured, trained team
One controlled test, one clear report, one gate that keeps it a security service rather than a phishing kit.
You authorise the test
You sign a one-page scope: your domain, your staff, a named contact, a window. No signature, no campaign — it is the line between a security service and an attack, and we hold it hard.
We send a realistic, safe lure
On an agreed date your team receives a believable email — a password-expiry notice, an overdue invoice, a shared document. Tailored to your sector, reviewed by a human before it sends.
Anyone who clicks learns instantly
A click lands on a safe page that immediately says "this was a test" and shows the exact red flags they missed. The lesson lands at the moment of the mistake — never a quarterly slideshow.
You get a board-ready report
Click rate, report rate, repeat offenders, and a sector benchmark — the evidence your insurer, your clients and your board now ask for.
#1
Phishing is how most UK firms get breached
£499
One-off assessment — keep the report either way
London
UK engineers — no offshore helpdesk
4.9/5
Across 47 client reviews
The £499 assessment
Everything in the one-off test
A fixed price, a clear deliverable, and no obligation to buy anything else.
One realistic simulation
A sector-tailored phishing email sent to your whole team on an agreed date — the same pretexts real attackers use against UK firms.
Immediate, personalised training
Whoever clicks gets a short, friendly "here is what you missed" the instant they click, tied to the exact email they fell for.
Branded board report
A clear PDF: click rate, report rate, repeat offenders, sector benchmark — evidence you can hand to your board, insurer or clients.
30-minute debrief
A senior engineer walks you through the result, what it means, and the two or three changes that cut your risk the most.
Pricing
Start with one test. Scale only if you want to.
No lock-in, no long-term contract. The one-off assessment stands on its own — everything beyond it is your choice.
Would your staff click?
The one-off assessment
- ✓ One realistic, sector-tailored simulation
- ✓ Instant training for anyone who clicks
- ✓ Branded board-ready report
- ✓ 30-minute debrief with a senior engineer
- ✓ Keep the report whatever you decide next
Per seat
For larger teams
- ✓ Scales cleanly across 50+ staff
- ✓ Continuous simulations, not one-off
- ✓ New starters onboarded automatically
- ✓ Per-user reporting for HR & the board
- ✓ Volume pricing on request
Ongoing programme
Optional · after your first test
- ✓ Quarterly simulations, varied lures
- ✓ Continuous training for repeat clickers
- ✓ Click rate tracked falling month on month
- ✓ Monthly board report
- ✓ Cancel any time — no lock-in
MSP or reseller? We white-label the whole programme for your clients — ask about partner pricing.
The line we never cross
A security service, not a phishing kit
The difference is consent and care. Both are built into how we work — not bolted on.
Written authorisation, always
We only ever test an organisation that has, in writing, authorised a test of its own staff. No exceptions — it is enforced in our system, not just our process.
We never capture a password
The landing page has no login box and no form. It records the click, reveals the test, and teaches. It cannot harvest a credential — by design.
Your data stays yours
The staff list is provided by you, held only for the engagement, and deleted on request. GDPR by design.
FAQ
Frequently asked questions
What is a phishing simulation?
A phishing simulation is a controlled, authorised test where we send your staff a realistic but completely safe fake phishing email, with your written permission, to measure who would click and who would report it. Anyone who clicks lands on a safe page that immediately tells them it was a test and teaches them what to look for. It answers the question a spam filter cannot: not "can we be impersonated?" but "would our own people actually fall for it?"
How much does it cost?
The one-off "Would your staff click?" assessment is £499 + VAT — one realistic simulation, immediate training for anyone who clicks, a branded board report, and a 30-minute debrief. For larger organisations we price per seat. Most firms then move to an optional ongoing programme (quarterly simulations plus continuous training) once they have seen the first result, but there is no obligation to.
Is it safe? Could it actually harm us?
Yes, it is safe. The lure lands on a page that has no login box and no form — it cannot capture a password or any data, by design. We only ever run a test an organisation has authorised in writing for its own staff, the training is supportive rather than punitive, and your staff list is held only for the engagement and deleted on request.
Will this embarrass or punish staff who click?
No — that is the fastest way to make people hide mistakes. The teachable moment is short, friendly and private to the person who clicked. The goal is a falling click rate over time, not a name-and-shame. Repeat clickers get a little more coaching, not a telling-off.
How is this different from just having a spam filter?
A spam filter blocks known-bad email before it arrives. It cannot tell you whether your people would fall for the message that gets through — and something always gets through. A simulation measures the human layer directly, and the training strengthens it. The two work together: filter to reduce what arrives, trained staff to catch the rest.
Do we have to commit to anything ongoing?
No. The £499 assessment is a one-off and you keep the report whatever you decide next. One test is a snapshot; risk moves as staff and tactics change, so most firms choose the ongoing programme — but that is your call to make after you have seen where you stand.
Find out before an attacker does.
One controlled test, a clear report, and the training to fix what it finds. £499, and you keep the report whatever you decide next.