Strategy & Governance

Managed Security

Cyber Defense

Governance, Risk & Compliance

Operations & People

Talk to us

Operations & People

Phishing simulation measured on who reports, not who clicks.

Phishing simulation services in India are usually sold on a single number: the click rate. It is the wrong metric to optimise. A workforce that clicks less because it distrusts all email has not become safer, and a click rate driven down by fear produces the outcome you least want: people who click and then say nothing.

The number that predicts whether you survive a real campaign is the reporting rate, and the time it takes. One person who reports a phish in four minutes lets your security team pull it from every other mailbox before it is opened. Twenty people who quietly delete it leave the twenty-first to click it an hour later.

So we run simulations that teach at the moment of the mistake, measure reporting alongside clicking, and treat repeated failure as a signal about the control environment rather than about the individual. It pairs directly with security awareness training, which builds the capability the simulation measures.

Why you need it

01 / 06

Why simulate at all.

01

Email is still the way in.

Credential phishing and malicious attachments remain the most common initial access route into organisations of every size. It requires no vulnerability and no exploit, only one person, once, on a busy afternoon.

02

Filters catch most, and most is not all.

Secure email gateways stop the bulk of commodity phishing. Targeted messages written for your organisation, sent from a legitimate compromised account or a newly registered domain, get through, which is precisely why the human layer has to work.

03

Awareness training alone does not transfer.

People complete a module, score well and click anyway three weeks later, because recognising a phish in a slide deck and recognising one in a busy inbox are different tasks. The simulation is the practice.

04

Reporting is the control you can actually build.

You will never get click rates to zero and should not try. You can get reporting to happen fast and consistently, and that is what turns an incoming campaign into a contained event.

Instrument

02 / 06

Three messages from a morning inbox.

One is a phish. Pick it, and every message shows its tells. Sender domains use reserved example names.

What we deliver

03 / 06

How we run it.

01

Tailored campaign design

Scenarios built around your organisation (your tools, your vendors, your internal processes, your busy periods) because a generic template tests almost nothing. Difficulty is matched to maturity rather than set to maximum, since a simulation nobody could plausibly catch teaches nothing.

02

Progressive campaign programme

A baseline campaign, then a schedule that increases in sophistication as capability improves: from obvious commodity phishing through to targeted pretexts, sender spoofing, credential harvesting pages and, where authorised, business email compromise scenarios against finance.

03

Immediate teaching moments

Anyone who clicks lands on a short, specific page showing exactly which signals in that message would have given it away. Delivered at the moment of the mistake, when it is memorable, and framed as a lesson rather than a reprimand.

04

Reporting mechanism and measurement

A one-click report button in the mail client, measured for adoption and speed. Reporting rate and median time to first report are the headline metrics, ahead of click rate, because they are what your security team can act on.

05

Analysis and targeted follow-up

Results by department, role and scenario type, showing where the risk actually concentrates. Follow-up training is directed at the groups and the specific weaknesses the data identifies rather than delivered uniformly.

06

Response process improvement

What happens after a report is as important as the report. We review the handling path (triage, mailbox search and purge, credential reset) and feed the findings into your incident response plan, which is where a simulation programme pays off during a real campaign.

How we run it

04 / 06

Six steps per cycle.

  1. 01

    Identify objectives

    What the programme is for: baseline measurement, capability building, compliance evidence, or testing the response process. Agreement in advance on how results will be used, and explicitly not used, which determines whether people trust the programme.

    Week 1
  2. 02

    Design scenarios

    Realistic pretexts drawn from your environment, difficulty calibrated to current maturity, and sender infrastructure prepared. Legal and HR review the approach before anything is sent.

    Weeks 1-2
  3. 03

    Conduct the simulation

    Delivery staggered across the population so results are not contaminated by word of mouth, with allow-listing arranged so the test measures people rather than your email gateway.

    Week 3
  4. 04

    Analyse results

    Click rate, credential submission rate, reporting rate and time to first report, broken down by department, role and scenario, plus how quickly your security team acted on the first report.

    Week 4
  5. 05

    Feedback and training

    Aggregate results shared openly with the whole organisation, targeted follow-up for the groups the data identifies, and recognition for fast reporters. Individual results are not published.

    Weeks 4-5
  6. 06

    Review and improve

    Programme effectiveness reviewed, scenarios adjusted for the next cycle, and lessons folded into the incident response plan and the technical controls the simulation exposed as insufficient.

    Quarterly

Key benefits

05 / 06

What changes after.

Reporting becomes reflexive

People report in minutes rather than deleting quietly, which lets your team purge a live campaign from every mailbox before most of them are opened.

You know where the risk sits

Susceptibility by department, role and scenario type, so training and technical controls are aimed at the groups the data identifies rather than spread evenly.

The response path has been rehearsed

Triage, search, purge and reset get practised on a simulation, which is a considerably better place to discover a gap than during a real one.

Tools we use

06 / 06

Named, and used on your engagement.

No “latest tech tools”. These are the ones your report will cite, alongside the manual work that a tool cannot do for you.

Simulation platforms

  • GoPhish
  • Microsoft Attack Simulation Training
  • KnowBe4
  • Custom scenario infrastructure

Reporting and triage

  • Report Phishing button integration
  • Mailbox search and purge
  • TheHive

Email authentication

  • DMARC
  • SPF
  • DKIM
  • Allow-listing for controlled delivery

Measurement

  • Reporting rate and time to first report
  • Departmental susceptibility analysis
  • Repeat-clicker tracking

Follow-through

  • Targeted micro-training modules
  • Incident response playbook review

Why Aphelion

Shared

Four things you can check.

01

The work is done by people with names.

Darshap Nayak, formerly of KPMG, holds a master’s degree in cybersecurity and more than seven years in security operations. Jaimin Somani brings fifteen-plus years of academic and hands-on VAPT. Hemang Desai is an ICT network specialist from Australia. You will meet them, not a logo.

Meet the team
02

Evidence, not adjectives.

Every finding arrives with the reproduction steps, the affected asset and the fix, ranked by what it actually reaches in your environment, not by a CVSS number copied from a scanner. You get the report and the raw output, not a summary of a summary.

See how we test
03

Two offices, one practice.

Ahmedabad and Sharjah, working the same methodology on the same tooling. Indian data-residency requirements and UAE delivery are both ordinary here, and the AphelioNYX AD Pen-Test module runs entirely inside your perimeter when regulation says it must.

The platform
04

What we will not do.

Invent a statistic to make a slide land. Publish your name as a client without written permission. Print an award badge nobody awarded. Founded in 2024. We say so, and we attribute experience to the people who have it.

Ask us anything

100+ organizations secured

Across the globe, and across eight industries. We name a client only with their written permission.

  • Finance & Banking
  • Healthcare
  • Retail & E-commerce
  • Technology
  • SaaS
  • Hospitality
  • Manufacturing
  • Pharmaceuticals

AphelioNYX is SOC 2, ISO and GDPR compliant; attestations are available on request under NDA. We would rather hand you the report than print a badge.

Questions

FAQ

What clients ask about phishing simulation.

Will this damage trust with our employees?
It will if it is run as a trap, and that is a design choice rather than an inherent property. Announce that a programme exists without announcing dates, share aggregate results openly, never publish individual names, and make the landing page a two-minute lesson rather than a reprimand. Programmes that discipline clickers reliably destroy the reporting culture they were meant to build, because the safest thing for an employee becomes saying nothing.
How often should we run simulations?
Quarterly suits most organisations: frequent enough to build a habit, infrequent enough that people are not permanently suspicious of internal email. Monthly is appropriate for high-risk populations such as finance and executive teams. Annual is close to useless, because the effect has decayed entirely by the time the next one arrives.
What is a good click rate?
It is the wrong question, and providers who lead with a benchmark are usually selling one. Click rate depends heavily on how difficult the scenario was; a sufficiently convincing pretext catches security professionals. Watch the trend on your own reporting rate and your median time to first report, and treat a falling click rate with a flat reporting rate as a warning rather than a success. It often means people have started deleting silently.
What happens to someone who fails repeatedly?
They get support, not punishment, and their manager gets a conversation about workload and process. A repeat clicker is usually someone whose job requires opening attachments from strangers all day (recruitment, accounts payable, customer support) which is a control-environment problem rather than a personal failing. The right response is usually a technical one: tighter attachment handling for that role, or a process that removes the judgement call from the individual.
Can you simulate business email compromise?
Yes, with explicit written authorisation and careful scoping, because these scenarios are targeted at named individuals and involve real financial processes. A finance-directed payment request purportedly from an executive tests the control that matters most: whether the out-of-band verification step actually happens under pressure. We run them with the executive whose identity is used fully briefed and consenting, and we never carry a simulation through to an actual transaction.

Forty-five minutes. Your environment, not a slide deck.

A personalised walkthrough and a free readiness assessment against the frameworks you are actually being asked for. Pick a time that suits you, or write to us. We reply within one business day.