Human risk, measured · A DATADEFENZ product
It measures who is actually at risk — not who attended the training.
PhishingPulse sends realistic, safe phishing simulations to your employees, measures exactly what each person does, and turns that behaviour into a live human-risk score for every person, department and the organisation. Fail one, and it re-tests you on the same attack type rather than sending another course.
The three attacker goals
Everything is scored against what the attacker was actually after.
Not "did they click", but what the click would have cost. Each category carries its own maximum penalty, and the action steps are calibrated to sum exactly to that cap.
Credentials, a session, or an approval that grants account access.
Code execution on the endpoint.
The human to disclose data, or move money directly.
The scoring model
Bounded by design, explainable in one line.
Every employee starts each year at 100. Each failure chain lands exactly on its category cap — so the worst a single simulation can ever cost is a number you can state before it happens, and an intermediate step still scores less than a full compromise.
Nimal starts the year at 100.
100He clicks the link.
−595He submits his credentials. Total 25 — exactly the Identity cap.
−2075Had he clicked but stopped, he would have lost 5. The chain distinguishes a shallow slip from a full compromise.
Risk bands
From one action to one board number.
Category score is 100 minus that category's capped penalties. A user's overall is the mean of their three category scores. Department and organisation are the mean of those. Averages, never raw penalties — because categories carry different maximums, so raw totals would not compare between two people who faced different content.
The simulation library
Defined four levels deep.
Every simulation resolves down to a payload carrying three attributes: the psychological trigger it exploits, whether it is time-sensitive, and who it impersonates. A minimum of four payloads per category-and-tactic pair means an adaptive re-send is never the same email twice.
Category
The attacker's goal — identity, device or data.
Tactic
The approach taken to reach that goal.
Technique
Web link, QR, attachment, reply or approval.
Payload
The email itself, carrying a psychological trigger, a time-sensitivity flag and an impersonated sender.
Web link · QR · Attachment · Reply · Approval
Authority · Urgency · Scarcity · Fear · Curiosity · Reward · Trust · Convenience · Reciprocity · Responsibility · Personal relevance · Compliance
Every employee faces the same standardised set across the year. Only order and timing vary — so comparing two scores is comparing like with like, and no single warning at the water cooler covers everyone.
How each action is detected
No agents. No mailbox access.
Everything rests on a unique, meaningless token per recipient and ordinary web requests.
When someone submits, the system records that it happened. The values are discarded at the point of receipt and never reach storage, logs or telemetry. There is no code path by which a real password enters the platform.
The reports
One dataset, two audiences.
Leadership sees one page. The analyst can drill into everything behind it.
One page, and a named priority
Organisation human-risk score and trend, band distribution, per-category scores, department ranking, and auto-written recommendations that name the actual worst department, category and tactic — not a generic "improve awareness".
Everything behind the number
User Risk Register, Watch List, Department Analysis, Attack Analysis by category, tactic, technique, trigger and sender, Payload Performance, Improving Users, and the full event log — every row showing the penalty and the category cap it counted against.
A worked demonstration across 100 employees and 1,240 simulations produced an organisation score of 82/100, with a realistic spread across the bands and 27 users flagged with a named weakness.
Security, privacy and ethics
The constraints are the product.
A phishing simulator earns trust by what it refuses to do. These are enforced controls, not policy statements.
Phase 1 — stated plainly
What the score does not yet mean.
Capturing "user reported this email" needs a mail-platform integration most pilot customers will not have on day one. So the model records risky actions only, and the top band is No Risk Detected — deliberately not "Champion".
A score of 100 means no risky action was observed. That includes someone who never engaged at all. It is not proof of vigilance, and we would rather say so than let a dashboard imply otherwise. Reporting is reserved at +20 and activates when capture is enabled.
Two adjacent capabilities
Beyond the simulation programme.
Email Security Posture Testing
A separate check the customer runs against their own gateway, with no allow-listing needed. It uses safe inert artifacts — EICAR, GTUBE, safe replicas — to reveal which modern attacks slip past their filters, rolling into a separate posture score. No real malware, ever.
Risk Intelligence
Calibrates the model to a customer's sector, controls and history using sector threat intelligence and Monte Carlo simulation. Crucially, Monte Carlo only sets parameter ranges and recommendations — it never changes what a real employee action scores. Once a weight is approved, every identical action scores identically.
Year one
The first year is the map, not the deliverable.
You end it with your blind spots named: which psychological lever works on your workforce, which technique slips through, which department carries the risk, and which individuals have a specific, named weakness.
Year two is not a repeat. It is aimed. The programme compounds because you finally know where to point it.
Human risk, with a number attached
See it running against your own workforce.
The full platform, pricing and pilot details live on the product site.
