Phishing Campaigns
One convincing email is still the most reliable way into most organisations. Our managed phishing campaigns show you how yours would fare — using realistic pretexts built from research on your organisation, measured properly over time rather than as a one-off gotcha.
Who this is for
- You run awareness training and want to know whether it changes behaviour, not just completion rates
- An insurer, client or framework asks for evidence of simulated phishing
- Your last campaign used an obvious template and told you nothing you did not already know
- You want a difficulty benchmark: how sophisticated does an email have to be before your people click?
What we test
Coverage runs in depth, not breadth alone — each stage goes past where the one above it stops.
- Pretext
Built from your own footprint
Your suppliers, tooling, terminology and public footprint shape the scenarios, so what lands in the inbox is something an employee might genuinely receive.
- Ladder
Escalating difficulty, deliberately
Campaigns progress from broad, lower-effort lures to targeted spear-phishing — so you learn the sophistication level at which resilience actually breaks, not simply that someone clicked.
- Capture
Past the click
Convincing landing pages that record submissions, not just clicks. A click is curiosity; a submission is the real signal. Whether the submitted passwords come back to you — a real read on password quality, the same evidence a password audit gives — or are withheld entirely is a choice you make at scoping.
- Response
Whether the reporting channel works
Whether the report-phishing button, mailbox or helpdesk route actually gets used and how fast — the control that limits damage once a lure succeeds.
What you get
The package in three parts — what you read, what you act on, and what happens after.
What you read
Trend, not a single embarrassing number.
- Click, credential-submission and report-rate metrics per campaign, tracked over time
- A difficulty-calibrated read of resilience: which pretexts succeed, and at what sophistication level
What you act on
Aimed at training spend, not individuals.
- Aggregate, blame-free reporting designed to direct awareness training where it will do most good
- A record of who submitted, with immediate reset advice where a scenario warrants it
How it runs
How a simulation runs
Scoping & Rules of Engagement
Which hosts, people or systems are in play, at what intensity, in what window — plus your point of contact, the escalation route, and who holds the authority to stop it.
Reconnaissance & Scenario Build
Building the thing that will actually run: a pretext assembled from your own public footprint, an agent and scope for a ransomware run, or a load suite from your API collection.
Written Authorisation
Nothing executes until it is signed. Where a simulation touches your people or your availability, that authorisation is a separate document from the standard engagement terms.
Controlled Execution
The exercise runs inside the agreed window, watched by a named engineer, with the means to halt and reverse it immediately if you ask or if anyone becomes distressed.
Detection & Response Measurement
What your tooling saw, what your people did, and how long each took. This is the output that matters — the simulation itself is only the instrument for producing it.
Stand-down & Reporting
Everything is reversed and removed: files restored, assets deleted, campaigns closed, with the restoration reconciled. Then the annotated timeline, the findings and what to change.
This is our simulation sequence. The six-phase methodology CREST assessed governs our penetration testing, which is a different service.
Prerequisites
- Target mailing lists (or agreed departments) supplied by an authorised contact
- Mail-filter allowlisting where the goal is measuring user behaviour — or no allowlisting where the goal is testing your filtering itself; we agree the objective up front
- A signed Laneden authorisation form and a small informed group who will not tip off recipients
Frequently asked questions
What happens to credentials people enter on the landing page?
The submission happens over an encrypted connection and is recorded against the recipient — that is the signal that matters. What you see afterwards is your choice, agreed at scoping. Most clients want only the fact of a submission, in which case the passwords are never reported and the campaign data is destroyed with the rest of the engagement data. Some want the passwords themselves, because a real credential typed by a real employee under pressure tells you more about password quality than any policy document — the same value an offline password audit gives, from a different angle. Either way the captured data is held encrypted, access-controlled, and destroyed on the same schedule as the report. Where a scenario means a real credential may genuinely have been exposed, we tell your informed contacts immediately so a reset can happen the same day.
Will individual employees be named in the report?
No. Results are aggregated by campaign, department or role as agreed. The purpose is to measure and improve organisational resilience, and blame-free reporting is what keeps people willing to report real phishing.
Our mail filter will just block it. Doesn't that make the exercise pointless?
That is itself a result worth having. We can run it both ways: unassisted, to test your filtering, and allowlisted, to test your people. Most clients want both answers.
How often should we run campaigns?
Quarterly gives a meaningful trend line without exhausting goodwill. A single campaign is a snapshot; the value compounds when difficulty and metrics are tracked across a programme.
Related services
Social Engineering
Attackers rarely start with technology; they start with a phone call, an email or a confident walk through reception.
Learn more →
Executive Threat Assessment
Senior leaders are targeted precisely because of who they are: their names authorise payments, their inboxes carry weight, and their personal lives leak online in ways corporate controls never touch.
Learn more →
Ready to test your defences?
Tell us about your phishing campaign requirement — we'll come back with a scoped proposal within two working days.
Free remediation retesting* to confirm your fixes (subject to assessment size).
