Taking new engagements — Q4 hello@datadefenz.com Employee Login
ServicesAll servicesGRC & Compliance7Security Culture1Risk Management3Technical Security5Leadership Advisory1Fast-Turnaround1
ProductsResourcesPracticeAboutLet's Work TogetherBook a 30-minute callContact
Products / PhishingPulse

Human risk, measured · A DATADEFENZ product

It measures who is actually at risk — not who attended the training.

PhishingPulse sends realistic, safe phishing simulations to your employees, measures exactly what each person does, and turns that behaviour into a live human-risk score for every person, department and the organisation. Fail one, and it re-tests you on the same attack type rather than sending another course.

The loop, running continuously across the yearUploadSegmentSimulateMeasureTeachScoreAdapt
9Mandatory simulations per employee, per year
66Payloads in the library, so a re-send is never a repeat
1–5Difficulty, climbing toward spear-phishing
0–100One board-ready score, with the evidence attached

The three attacker goals

Everything is scored against what the attacker was actually after.

Not "did they click", but what the click would have cost. Each category carries its own maximum penalty, and the action steps are calibrated to sum exactly to that cap.

Identity Compromise
25max penalty

Credentials, a session, or an approval that grants account access.

Device Compromise
25max penalty

Code execution on the endpoint.

Data Compromise
20max penalty

The human to disclose data, or move money directly.

The scoring model

Bounded by design, explainable in one line.

Every employee starts each year at 100. Each failure chain lands exactly on its category cap — so the worst a single simulation can ever cost is a number you can state before it happens, and an intermediate step still scores less than a full compromise.

Category / path1st action2nd action3rd actionTotal
Identity · 2-stepLink/QR click −5Credential submitted −2025
Identity · 1-stepApprove request −2525
Device · 3-stepLink/QR click −5Download attachment −10Execute file −1025
Data · 2-stepLink/QR click −5Information submitted −1520
Worked example · an Identity credential lure
0

Nimal starts the year at 100.

100
1

He clicks the link.

−595
2

He submits his credentials. Total 25 — exactly the Identity cap.

−2075

Had he clicked but stopped, he would have lost 5. The chain distinguishes a shallow slip from a full compromise.

Risk bands

From one action to one board number.

Category score is 100 minus that category's capped penalties. A user's overall is the mean of their three category scores. Department and organisation are the mean of those. Averages, never raw penalties — because categories carry different maximums, so raw totals would not compare between two people who faced different content.

90–100No Risk Detected
70–89Low Risk
50–69Medium Risk
30–49High Risk
0–29Critical Risk

The simulation library

Defined four levels deep.

Every simulation resolves down to a payload carrying three attributes: the psychological trigger it exploits, whether it is time-sensitive, and who it impersonates. A minimum of four payloads per category-and-tactic pair means an adaptive re-send is never the same email twice.

01

Category

The attacker's goal — identity, device or data.

02

Tactic

The approach taken to reach that goal.

03

Technique

Web link, QR, attachment, reply or approval.

04

Payload

The email itself, carrying a psychological trigger, a time-sensitivity flag and an impersonated sender.

Techniques

Web link · QR · Attachment · Reply · Approval

Triggers

Authority · Urgency · Scarcity · Fear · Curiosity · Reward · Trust · Convenience · Reciprocity · Responsibility · Personal relevance · Compliance

Fairness

Every employee faces the same standardised set across the year. Only order and timing vary — so comparing two scores is comparing like with like, and no single warning at the water cooler covers everyone.

How each action is detected

No agents. No mailbox access.

Everything rests on a unique, meaningless token per recipient and ordinary web requests.

ActionHow it is detectedCategory step
Click / QR scanA tracked redirect carrying the token; the QR encodes the same link.5
Credential submitA neutered login page posts a submit event plus token — never the typed values.Identity 20
Attachment downloadA tracked file link fires download_attachment.Device 10
Attachment executeAn inert beacon inside the document fires execute_file.Device 10
Approve requestA mock approval screen posts an approve event — no real IdP involved.Identity 25
Information submitA neutered form posts a submit event plus token.Data 15
Passwords are never captured

When someone submits, the system records that it happened. The values are discarded at the point of receipt and never reach storage, logs or telemetry. There is no code path by which a real password enters the platform.

The reports

One dataset, two audiences.

Leadership sees one page. The analyst can drill into everything behind it.

Management dashboard

One page, and a named priority

Organisation human-risk score and trend, band distribution, per-category scores, department ranking, and auto-written recommendations that name the actual worst department, category and tactic — not a generic "improve awareness".

Analyst views

Everything behind the number

User Risk Register, Watch List, Department Analysis, Attack Analysis by category, tactic, technique, trigger and sender, Payload Performance, Improving Users, and the full event log — every row showing the penalty and the category cap it counted against.

A worked demonstration across 100 employees and 1,240 simulations produced an organisation score of 82/100, with a realistic spread across the bands and 27 users flagged with a named weakness.

Security, privacy and ethics

The constraints are the product.

A phishing simulator earns trust by what it refuses to do. These are enforced controls, not policy statements.

No real malicious contentInert markers and safe replicas only. Live malware never enters the platform.
Passwords never capturedA submit records the event only; values are discarded at the point of receipt.
Ownership-gated cloningOnly a customer's own verified domain, and the check runs before any fetch.
Frequency limitsRoughly one simulation per person per ten days, with a quarterly cap on adaptive re-sends.
Ethical lure exclusionsDistress-based lures are off by default and need explicit customer sign-off.
Tenant isolation and MFAStrict data scoping, MFA for admins, audit logging on every action.
Minimal dataOnly name, email, employee ID, department and role.
Configurable visibilityWho sees individual scores versus department aggregates is the customer's choice.

Phase 1 — stated plainly

What the score does not yet mean.

Reporting is not scored yet

Capturing "user reported this email" needs a mail-platform integration most pilot customers will not have on day one. So the model records risky actions only, and the top band is No Risk Detected — deliberately not "Champion".

A score of 100 means no risky action was observed. That includes someone who never engaged at all. It is not proof of vigilance, and we would rather say so than let a dashboard imply otherwise. Reporting is reserved at +20 and activates when capture is enabled.

Two adjacent capabilities

Beyond the simulation programme.

Self-service

Email Security Posture Testing

A separate check the customer runs against their own gateway, with no allow-listing needed. It uses safe inert artifacts — EICAR, GTUBE, safe replicas — to reveal which modern attacks slip past their filters, rolling into a separate posture score. No real malware, ever.

Optional module

Risk Intelligence

Calibrates the model to a customer's sector, controls and history using sector threat intelligence and Monte Carlo simulation. Crucially, Monte Carlo only sets parameter ranges and recommendations — it never changes what a real employee action scores. Once a weight is approved, every identical action scores identically.

Year one

The first year is the map, not the deliverable.

You end it with your blind spots named: which psychological lever works on your workforce, which technique slips through, which department carries the risk, and which individuals have a specific, named weakness.

Year two is not a repeat. It is aimed. The programme compounds because you finally know where to point it.

Human risk, with a number attached

See it running against your own workforce.

The full platform, pricing and pilot details live on the product site.