Skip to content
LANEDEN

Threat Simulation

Phishing Campaigns

One convincing email is still the most reliable way into most organisations. Our managed phishing campaigns show you how yours would fare — using realistic pretexts built from research on your organisation, measured properly over time rather than as a one-off gotcha.

Who this is for

What we test

Coverage runs in depth, not breadth alone — each stage goes past where the one above it stops.

  1. Pretext

    Built from your own footprint

    Your suppliers, tooling, terminology and public footprint shape the scenarios, so what lands in the inbox is something an employee might genuinely receive.

  2. Ladder

    Escalating difficulty, deliberately

    Campaigns progress from broad, lower-effort lures to targeted spear-phishing — so you learn the sophistication level at which resilience actually breaks, not simply that someone clicked.

  3. Capture

    Past the click

    Convincing landing pages that record submissions, not just clicks. A click is curiosity; a submission is the real signal. Whether the submitted passwords come back to you — a real read on password quality, the same evidence a password audit gives — or are withheld entirely is a choice you make at scoping.

  4. Response

    Whether the reporting channel works

    Whether the report-phishing button, mailbox or helpdesk route actually gets used and how fast — the control that limits damage once a lure succeeds.

What you get

The package in three parts — what you read, what you act on, and what happens after.

What you read

Trend, not a single embarrassing number.

  • Click, credential-submission and report-rate metrics per campaign, tracked over time
  • A difficulty-calibrated read of resilience: which pretexts succeed, and at what sophistication level

What you act on

Aimed at training spend, not individuals.

  • Aggregate, blame-free reporting designed to direct awareness training where it will do most good
  • A record of who submitted, with immediate reset advice where a scenario warrants it

How it runs

How a simulation runs

  1. Scoping & Rules of Engagement

    Which hosts, people or systems are in play, at what intensity, in what window — plus your point of contact, the escalation route, and who holds the authority to stop it.

  2. Reconnaissance & Scenario Build

    Building the thing that will actually run: a pretext assembled from your own public footprint, an agent and scope for a ransomware run, or a load suite from your API collection.

  3. Written Authorisation

    Nothing executes until it is signed. Where a simulation touches your people or your availability, that authorisation is a separate document from the standard engagement terms.

  4. Controlled Execution

    The exercise runs inside the agreed window, watched by a named engineer, with the means to halt and reverse it immediately if you ask or if anyone becomes distressed.

  5. Detection & Response Measurement

    What your tooling saw, what your people did, and how long each took. This is the output that matters — the simulation itself is only the instrument for producing it.

  6. Stand-down & Reporting

    Everything is reversed and removed: files restored, assets deleted, campaigns closed, with the restoration reconciled. Then the annotated timeline, the findings and what to change.

This is our simulation sequence. The six-phase methodology CREST assessed governs our penetration testing, which is a different service.

Prerequisites

  • Target mailing lists (or agreed departments) supplied by an authorised contact
  • Mail-filter allowlisting where the goal is measuring user behaviour — or no allowlisting where the goal is testing your filtering itself; we agree the objective up front
  • A signed Laneden authorisation form and a small informed group who will not tip off recipients

Frequently asked questions

What happens to credentials people enter on the landing page?

The submission happens over an encrypted connection and is recorded against the recipient — that is the signal that matters. What you see afterwards is your choice, agreed at scoping. Most clients want only the fact of a submission, in which case the passwords are never reported and the campaign data is destroyed with the rest of the engagement data. Some want the passwords themselves, because a real credential typed by a real employee under pressure tells you more about password quality than any policy document — the same value an offline password audit gives, from a different angle. Either way the captured data is held encrypted, access-controlled, and destroyed on the same schedule as the report. Where a scenario means a real credential may genuinely have been exposed, we tell your informed contacts immediately so a reset can happen the same day.

Will individual employees be named in the report?

No. Results are aggregated by campaign, department or role as agreed. The purpose is to measure and improve organisational resilience, and blame-free reporting is what keeps people willing to report real phishing.

Our mail filter will just block it. Doesn't that make the exercise pointless?

That is itself a result worth having. We can run it both ways: unassisted, to test your filtering, and allowlisted, to test your people. Most clients want both answers.

How often should we run campaigns?

Quarterly gives a meaningful trend line without exhausting goodwill. A single campaign is a snapshot; the value compounds when difficulty and metrics are tracked across a programme.

Related services

Ready to test your defences?

Tell us about your phishing campaign requirement — we'll come back with a scoped proposal within two working days.

Free remediation retesting* to confirm your fixes (subject to assessment size).