Contact DEC
Language:ITEN
PhishGuard

Phishing simulations and continuous training

PhishGuard measures how an organisation recognises and reports phishing and smishing through authorised, controlled and repeatable campaigns. Results trigger targeted training and provide evidence for assessing human risk over time.

From testing to risk reduction

Each campaign follows a governed process, from scope definition through training and results review.

Preparation and authorisation

Recipients, domains, sending windows and scenarios are defined before launch. Approvals, separation of duties and an emergency stop keep the activity within the agreed scope.

Multi-channel execution

Email and SMS campaigns use templates and landing pages aligned with authorised scenarios. Sends can be scheduled, distributed over time and repeated at increasing levels of difficulty.

Response measurement

The timeline records delivery, opening, clicks, data submission, replies and reporting. Reporting rates are assessed alongside mistakes, so correct behaviour is measured as well.

Targeted training

Events defined by the organisation can automatically enrol personnel in specific training modules. Moodle integration also records course completion in the timeline.

Reporting and risk trends

Results become comparable indicators over time, rather than a personnel ranking.

Organisation-level analysis

Comparisons by campaign, period, department, channel and group identify recurring patterns, improvements and areas where training should be strengthened.

Verifiable evidence

Saved reports, scheduled exports and a tamper-evident audit log document authorisations, completed activities and training completion.

Participant protection

Retention, anonymisation, data access and separation of duties can be configured around organisational policy. Simulations always require explicit authorisation.

Integrations and access control

PhishGuard fits into existing processes without making the programme dependent on manual operations.

Corporate directories

Connectors for Microsoft Entra, Google Workspace, LDAP and SCIM keep groups, departments and personnel status current.

Delivery and reporting

SMTP, Microsoft Graph, Resend and Twilio support email and SMS; IMAP integration detects participant reports and replies.

Identity and roles

OIDC SSO, MFA, passkeys and separate roles for administration, authoring, approval, operation, data access and audit limit access to required functions.

API and automation

Scoped APIs and signed webhooks connect campaigns, events and reporting to security and training processes.

Deployment options

The scope is defined around the organisation, the systems to integrate and the required level of autonomy.

Managed service

DEC prepares and runs agreed campaigns, oversees operations, analyses results and coordinates training interventions.

Dedicated deployment

The platform can be deployed in a dedicated environment and configured for multiple organisations, with defined identity, role, integration and retention policies.

Awareness programme assessment

DEC can assess the existing programme, define the initial simulation scope and propose indicators aligned with the organisation’s risk profile.