Email is still the way in.
Credential phishing and malicious attachments remain the most common initial access route into organisations of every size. It requires no vulnerability and no exploit, only one person, once, on a busy afternoon.
Operations & People
Phishing simulation services in India are usually sold on a single number: the click rate. It is the wrong metric to optimise. A workforce that clicks less because it distrusts all email has not become safer, and a click rate driven down by fear produces the outcome you least want: people who click and then say nothing.
The number that predicts whether you survive a real campaign is the reporting rate, and the time it takes. One person who reports a phish in four minutes lets your security team pull it from every other mailbox before it is opened. Twenty people who quietly delete it leave the twenty-first to click it an hour later.
So we run simulations that teach at the moment of the mistake, measure reporting alongside clicking, and treat repeated failure as a signal about the control environment rather than about the individual. It pairs directly with security awareness training, which builds the capability the simulation measures.
Why you need it
01 / 06Credential phishing and malicious attachments remain the most common initial access route into organisations of every size. It requires no vulnerability and no exploit, only one person, once, on a busy afternoon.
Secure email gateways stop the bulk of commodity phishing. Targeted messages written for your organisation, sent from a legitimate compromised account or a newly registered domain, get through, which is precisely why the human layer has to work.
People complete a module, score well and click anyway three weeks later, because recognising a phish in a slide deck and recognising one in a busy inbox are different tasks. The simulation is the practice.
You will never get click rates to zero and should not try. You can get reporting to happen fast and consistently, and that is what turns an incoming campaign into a contained event.
Instrument
02 / 06One is a phish. Pick it, and every message shows its tells. Sender domains use reserved example names.
What we deliver
03 / 06Scenarios built around your organisation (your tools, your vendors, your internal processes, your busy periods) because a generic template tests almost nothing. Difficulty is matched to maturity rather than set to maximum, since a simulation nobody could plausibly catch teaches nothing.
A baseline campaign, then a schedule that increases in sophistication as capability improves: from obvious commodity phishing through to targeted pretexts, sender spoofing, credential harvesting pages and, where authorised, business email compromise scenarios against finance.
Anyone who clicks lands on a short, specific page showing exactly which signals in that message would have given it away. Delivered at the moment of the mistake, when it is memorable, and framed as a lesson rather than a reprimand.
A one-click report button in the mail client, measured for adoption and speed. Reporting rate and median time to first report are the headline metrics, ahead of click rate, because they are what your security team can act on.
Results by department, role and scenario type, showing where the risk actually concentrates. Follow-up training is directed at the groups and the specific weaknesses the data identifies rather than delivered uniformly.
What happens after a report is as important as the report. We review the handling path (triage, mailbox search and purge, credential reset) and feed the findings into your incident response plan, which is where a simulation programme pays off during a real campaign.
How we run it
04 / 06What the programme is for: baseline measurement, capability building, compliance evidence, or testing the response process. Agreement in advance on how results will be used, and explicitly not used, which determines whether people trust the programme.
Week 1Realistic pretexts drawn from your environment, difficulty calibrated to current maturity, and sender infrastructure prepared. Legal and HR review the approach before anything is sent.
Weeks 1-2Delivery staggered across the population so results are not contaminated by word of mouth, with allow-listing arranged so the test measures people rather than your email gateway.
Week 3Click rate, credential submission rate, reporting rate and time to first report, broken down by department, role and scenario, plus how quickly your security team acted on the first report.
Week 4Aggregate results shared openly with the whole organisation, targeted follow-up for the groups the data identifies, and recognition for fast reporters. Individual results are not published.
Weeks 4-5Programme effectiveness reviewed, scenarios adjusted for the next cycle, and lessons folded into the incident response plan and the technical controls the simulation exposed as insufficient.
QuarterlyKey benefits
05 / 06People report in minutes rather than deleting quietly, which lets your team purge a live campaign from every mailbox before most of them are opened.
Susceptibility by department, role and scenario type, so training and technical controls are aimed at the groups the data identifies rather than spread evenly.
Triage, search, purge and reset get practised on a simulation, which is a considerably better place to discover a gap than during a real one.
Tools we use
06 / 06No “latest tech tools”. These are the ones your report will cite, alongside the manual work that a tool cannot do for you.
Simulation platforms
Reporting and triage
Email authentication
Measurement
Follow-through
Why Aphelion
SharedDarshap Nayak, formerly of KPMG, holds a master’s degree in cybersecurity and more than seven years in security operations. Jaimin Somani brings fifteen-plus years of academic and hands-on VAPT. Hemang Desai is an ICT network specialist from Australia. You will meet them, not a logo.
Meet the teamEvery finding arrives with the reproduction steps, the affected asset and the fix, ranked by what it actually reaches in your environment, not by a CVSS number copied from a scanner. You get the report and the raw output, not a summary of a summary.
See how we testAhmedabad and Sharjah, working the same methodology on the same tooling. Indian data-residency requirements and UAE delivery are both ordinary here, and the AphelioNYX AD Pen-Test module runs entirely inside your perimeter when regulation says it must.
The platformInvent a statistic to make a slide land. Publish your name as a client without written permission. Print an award badge nobody awarded. Founded in 2024. We say so, and we attribute experience to the people who have it.
Ask us anythingAcross the globe, and across eight industries. We name a client only with their written permission.
AphelioNYX is SOC 2, ISO and GDPR compliant; attestations are available on request under NDA. We would rather hand you the report than print a badge.
Questions
FAQNext door
RelatedA personalised walkthrough and a free readiness assessment against the frameworks you are actually being asked for. Pick a time that suits you, or write to us. We reply within one business day.