Phishing simulations crafted by the people who actually break in.

Train your employees against the lures real attackers are sending this quarter — email, SMS, voice, QR and MFA fatigue — designed by our network of 400+ white-hat hackers. Compliance evidence for ISO 27001, SOC 2, NIS2 and DORA included by default.

Global Brands That Trust AuditOne

32%
Industry baseline click-through rate on a first campaign
<5%
Typical click rate after 12 months of regular campagins
all 5
Attack vectors covered: email, SMS, voice, QR, MFA fatigue
48h
From kick-off to first campaign live in your inbox
Why simulations matter

Phishing is the entry vector for the majority of breaches. Training is the cheapest control you have.

Untrained employees click between a quarter and a third of phishing emails. Trained employees click almost none. The difference between those two outcomes is whether your firm makes the news.
Untrained baseline
First campaign, no prior simulation programme
50%
~32%
After 90 days
2-3 campaigns + just-in-time training
50%
~14%
After 12 months
Monthly cadence + escalating sophistication
50%
<5%
The compounding effect: a 1,000-employee company at 32% click rate exposes ~320 people on every phishing wave. At <5%, that drops to fewer than 50. For ransomware operators who need a single foothold, that 270-person delta is the difference between a successful intrusion and a deflected campaign.
Click rate figures are indicative averages drawn from public industry benchmark reports (KnowBe4, Proofpoint State of the Phish, Verizon DBIR) across SMB and mid-market populations. Your baseline will vary by industry, geography, and prior training.
Attack vectors

Five channels. Real attackers use all of them.

Email-only simulations train employees against half of today's threat landscape. Our programmes cover every channel a real adversary would touch — and the multi-vector data tells you which channels your people are weakest on.
vector-01
Email phishing
Credential harvest, malware attachments, business email compromise, executive impersonation, supplier fraud.
vector-02
SMS (smishing)
Bank fraud lures, parcel-delivery scams, HR impersonation, MFA code phishing, corporate-IT helpdesk impersonation.
vector-03
Voice (vishing)
Live and AI-generated voice calls. CEO fraud, IT helpdesk impersonation, payroll change requests, account-recovery social engineering.
vector-04
QR (quishing)
QR-coded lures in print, signage, and email. Bypasses link scanners, lands on mobile devices outside corporate controls. Fastest-growing 2025–26.
vector-05
MFA fatigue
Repeated MFA push prompts to wear down user vigilance. The technique behind the 2022 Uber and Cisco breaches, still effective today.
Real attacker craft

What separates a useful simulation from a meaningless click.

The point of phishing simulation is not to fool employees. It is to fool them with lures realistic enough that the click-rate data actually predicts behaviour against real attacks. Most SaaS platforms fail this test.
most platforms

Template-library phishing

Generic global templates recycled across thousands of customers. Employees who switch employer have already seen them.
Email-only, or email plus a token SMS option. No vishing, no QR, no MFA fatigue.
Stale TTPs. Templates added quarterly at best. Cannot keep pace with current ransomware affiliate tactics.
No reconnaissance. No OSINT against your org. The lure could be sent to any company.
Soft language tells. Awkward phrasing, generic greetings, easy spoof domains. Real attackers don't make these mistakes anymore.
Compliance theatre. The report exists; whether it would survive an auditor's scrutiny is another question.
Auditone

Adversary-grade phishing

Bespoke lures per engagement. Crafted by our hackers against your specific org, branding, suppliers, and current news cycle.
All five vectors. Email, SMS, voice (including AI deepfake on request), QR, and MFA fatigue — combined as a real attacker would.
Current TTPs. Designed against the tactics our pen-test team is using this month against actual targets. What we use to break in, applied to your training.
OSINT-grounded. We research your org-chart, recent press, supplier list and tech stack before crafting. The lures look like they came from someone who knows you.
Native-language craft. Native-quality German, French, Spanish, Polish and more. No machine-translated tells.
Audit-grade reporting. Reports formatted to satisfy ISO 27001, SOC 2, NIS2 and DORA evidence requirements. Our auditors review the report before it ships.
how it works

From kick-off to baseline data in under a week.

01
Scoping & threat model
24 to 48 hours
We confirm employee count, target departments, languages, vectors in scope, and the threat model that matters to you — opportunistic phishing, targeted spear-phishing, executive impersonation. You receive a fixed quote and a programme calendar.
02
Setup & allowlisting
2 to 4 days
We allowlist sending infrastructure in Microsoft 365 or Google Workspace, configure user provisioning (SCIM, AD sync, or CSV), set up the just-in-time training landing pages, and integrate with your SIEM or ticketing system on request.
03
Baseline campaign
Day 1 of the programme
Your first wave goes out. We measure click rate, credential submission, attachment open, reply, and report rate. No training pressure yet — this is the unsweetened baseline you will compare every subsequent campaign against.
04
Just-in-time training
Triggered on click
When an employee falls for a lure, they land on a training page that walks them through what they missed and what to look for next time — in their language, within 30 seconds of the click. This is the most effective training moment, and it is automated.
05
Ongoing cadence & reporting
Monthly or quarterly
Subsequent campaigns escalate in sophistication. You receive per-campaign reports plus a quarterly executive dashboard with trend data, per-department breakdown, and the evidence pack your auditors will ask for.

FAQs

How is this different from KnowBe4, Hoxhunt, or Sosafe?

Three differences. Craft — our lures are designed by working pen-testers using current adversary tactics, not pulled from a shared template library. Vectors — we cover email, SMS, voice (including AI-deepfake on request), QR, and MFA fatigue as standard. Most SaaS competitors are email-first and treat the other vectors as add-ons or roadmap items. Reporting — our reports are reviewed by our audit team before they ship and are formatted to satisfy ISO 27001, SOC 2, NIS2 and DORA evidence requirements without rework. Where SaaS platforms win is on price-per-seat at scale; we are typically the right choice when realism and audit-grade evidence matter more than per-seat pricing optimisation.

How is the programme priced?

Annual programmes priced per employee per year, with discounts at common breakpoints (250+, 1,000+, 5,000+ employees). Pricing scales with vector mix and cadence — an email-only quarterly programme is cheaper than a multi-vector monthly programme. Pilot campaigns (a single baseline plus debrief) are available as a one-off engagement for organisations that want to see results before committing to an annual programme. Contact us at hello@auditone.io for an indicative range.

How long until we see results?

Baseline click rate is measured on day one. Meaningful reduction shows up after 60–90 days of programme — typically a 30–50% drop from baseline. Mature click rates (under 5%) require sustained monthly cadence over 9–12 months and escalating sophistication, because employees adapt to the lures they have seen. The programme is not a one-off project; it is a control that compounds with sustained operation.

Will this cause IT support overhead?

A well-run programme actively reduces helpdesk load over time, because employees become better at recognising and reporting real phishing. Initial campaigns do generate "I got a suspicious email" reports — which is the desired behaviour, not noise. We provide your helpdesk with a triage playbook so reported simulation emails are auto-acknowledged. Customers typically see reported-phishing tickets become useful threat intelligence by month three.

Is phishing simulation legal in our jurisdiction?

In most jurisdictions, including the EU under GDPR, internal phishing simulations are lawful as part of a legitimate-interest security programme — provided the programme is documented, proportionate, and employee data is processed in line with normal HR data handling. We provide a DPIA template and works-council briefing pack with every engagement. In some jurisdictions (notably Germany) the works council must be consulted before the programme starts; we walk you through that process if relevant.

Do you cover AI-powered phishing and deepfake voice?

Yes — and this is where the gap between AuditOne and most platforms is widest. We can generate LLM-crafted spear-phishing with native-language quality, AI-generated voice calls (vishing) that clone a target executive's voice from public audio, and multi-modal sequences that combine an email with a follow-up phone call. These are exactly the tactics being deployed against real organisations in 2026. AI-vishing in particular requires explicit scope authorisation and works-council sign-off; we manage that consent flow as part of scoping.

Does this work with our existing email security stack?

Yes. Our sending infrastructure is allowlisted as part of setup so simulations bypass Microsoft Defender, Proofpoint, Mimecast, or Google Workspace's built-in filtering — otherwise the test would measure your gateway's accuracy, not your employees' behaviour. We can also configure the opposite: send simulations through your gateway specifically to test whether your security stack catches them. Both modes are useful for different reasons.

Can we run a pilot before committing to a full programme?

Yes. The most common starting point is a single baseline campaign — one email-vector simulation across all employees, no prior training, full reporting, no annual commitment. You see your real click rate, your real reporting rate, and your real worst-case exposure. Most customers convert to an annual programme after seeing their baseline; some discover their existing programme is already working and decide they don't need us. Either outcome is fine.