New · Release 2026.04, Multi-tenant audit exports & SLA dashboards now live See changelog →
Security awareness

Phishing simulation and security awareness training

Build phishing email templates and landing pages, launch simulated campaigns against your own staff, see exactly who opened, clicked, submitted or reported, and assign follow-up training to the people who need it.

Product illustration · sample data
Platform Security
18/18 evidence
RLS2FAAudit logsCompliance
9.3/10
DIY assurance score · verified May 2026
Tenant tables with RLS10
Privileged roles · 2FAEnforced
Immutable audit eventsLive
Security controls verified18/18
Product proof

Already live in the product

Backed by app modules

Running in production today: campaigns, email templates, landing pages, sender profiles, training modules, and per-recipient tracking — scoped to your own organization.

Protected app route: /phishing-sim
How it works

Built around real workflows

Highlights below describe capabilities already present in the protected app behind this page.

Email templates with category and difficulty levels
Credential-capture and teachable-moment landing pages
Per-campaign SMTP sender profile, so each simulation can send from a different address
Per-recipient tracking: sent, opened, clicked, submitted and reported
Submitted credentials are never stored, only the field names are recorded
Security awareness training modules with per-employee assignment
Workflow

What teams can do here

Step 1
Create an email template and a landing page
Step 2
Add a sender profile with the SMTP account for this campaign
Step 3
Pick your target employees and schedule the campaign
Step 4
Watch opens, clicks and reports land per recipient
Step 5
Assign awareness training to whoever clicked
How it works

How it works

01
Build the lure
Create an email template with a category and a difficulty level — a password-expiry notice, a parcel update, an invoice. Lures are deliberately generic: Infronest never clones a real brand's email, by policy.
02
Pair it with a landing page
Choose what a click leads to: a credential-capture page that records only which field names were filled — never the credentials themselves — or a teachable-moment page that explains the miss on the spot.
03
Choose the sender
Each campaign uses its own SMTP sender profile, so every simulation can send from a different address through mail infrastructure you control.
04
Launch and track per recipient
Pick the target employees and schedule the campaign. Results are tracked per recipient — sent, opened, clicked, submitted and reported — so you see behaviour, not just an aggregate percentage.
05
Assign the training
Security awareness training modules are assigned per employee, so follow-up goes to the people who clicked or submitted rather than blanketing the whole company.
Example

A worked example

A typical 120-employee accounting firm schedules a medium-difficulty password-expiry campaign — a generic lure, deliberately not a clone of any real brand — paired with a teachable-moment landing page and sent through a sender profile created for this campaign. Within two days the per-recipient board tells the story: 97 delivered, 41 opened, 12 clicked, 4 typed something into the capture page (where only the field names are recorded, never the credentials), and 9 reported the email. The 12 clickers are assigned the awareness module on spotting spoofed senders, and the next quarter's campaign will measure whether the report rate climbs.

In depth

Why generic lures beat brand clones

Many phishing tools ship pixel-perfect copies of well-known login emails. Infronest deliberately does not: campaign templates are generic lures — a password-expiry notice, a parcel delivery update, an invoice attachment — never a clone of a real company's branding. Cloning a genuine brand's email teaches employees one narrow thing: distrust that specific fake. It also normalises reproducing another organisation's identity, which is exactly the behaviour security teams exist to stop.

Generic lures exercise the signals that transfer to any phish: an unexpected sender address, artificial urgency, a link that does not go where the text claims, a request that side-steps normal process. An employee who learns to check those tells is protected against next month's novel campaign, not just a familiar template.

Difficulty levels let you tune how obvious those tells are. An easy campaign establishes a baseline; harder ones tighten the craft — cleaner copy, more plausible pretexts — so the programme grows with your team instead of humiliating it on day one.

In depth

Measure the behaviour, not just the click rate

A single "click rate" hides what actually matters. Infronest records five states per recipient — sent, opened, clicked, submitted and reported — so a campaign result reads as a funnel of behaviour. Opening an email is unremarkable; clicking is a miss; typing into the capture page is the serious signal; and reporting is the behaviour you are actually trying to grow.

That last number deserves the attention. A security-mature organisation is not one where nobody ever clicks — that is unachievable — but one where suspicious email gets reported quickly enough for IT to warn everyone else. Tracking reports per recipient, campaign over campaign, tells you whether that reflex is developing.

The capture page itself is engineered to be safe to run: only the field names an employee filled are recorded, never the values. You learn that someone would have typed a password without ever holding one.

In depth

Close the loop with training, not shame

A simulation that ends with a spreadsheet of clickers has produced embarrassment, not security. The module closes the loop two ways: a teachable-moment landing page can explain the miss the instant it happens, and security awareness training modules are assigned per employee afterwards — targeted at the people who clicked or submitted, not broadcast to everyone as an annual chore.

Because campaigns are cheap to repeat with a fresh sender profile and a different lure, the programme becomes a rhythm rather than an event: run a campaign, train the misses, run the next at a higher difficulty, and watch the submitted count fall while the reported count rises.

FAQ

Frequently asked questions

Will the simulation store my employees' passwords?
No, by design. When someone types into a credential-capture landing page, only the names of the fields they filled are recorded — the submitted values themselves are never stored, so a simulation can never become a real credential leak.
Can the phishing email impersonate a real brand like Microsoft or a bank?
No, and that is deliberate policy: templates are generic lures — password expiries, parcel notices, invoices — never clones of a real company's branding. Generic lures train people to read the signals that generalise instead of memorising one fake.
Can each campaign send from a different address?
Yes. Sender profiles are per-campaign, each with its own SMTP account, so one simulation can arrive from a look-alike internal address and the next from an external one — through mail infrastructure you configure and control.
What exactly is tracked for each employee?
Five per-recipient states: sent, opened, clicked, submitted and reported. That granularity lets you distinguish someone who ignored the email, someone who clicked, and — most importantly — someone who reported it.
What happens to the people who click?
You assign them security awareness training modules individually, and a campaign can land clickers on a teachable-moment page that explains the tell-tale signs immediately, while the memory of the click is fresh.
Can other companies on the platform see our results?
No. Campaigns, templates, landing pages, sender profiles and every per-recipient result are scoped to your organization — phishing results are sensitive HR-adjacent data and are treated that way.
How much does phishing simulation cost?
It is a separately licensed module, so you can run it standalone or alongside the rest of the workspace — current per-employee rates are on the pricing page.

See also: Guide: what is endpoint security? · Guide: what is VAPT? · Security & VAPT · Access control · Pricing

Related

Explore connected offerings

Pricing

Phishing Simulation pricing

Billed per recipient — the employees your campaigns are sent to. Add it to Enterprise, or run it standalone.

Phishing Simulation

5 sub-modules · Dashboard · Campaigns · Email Templates · Awareness Training · Sender Profiles (SMTP)

₹85
per recipient / month

Run simulated phishing campaigns against your own staff, track who opened, clicked, submitted or reported, and assign awareness training to the people who need it — with a different sending address per campaign.

Submitted credentials are never stored — only field names.

₹42,500/mo· 500 recipients × ₹85

Recipients beyond the first 1,000 bill at ₹65/recipient.

100 recipients₹8,500/mo
500 recipients₹42,500/mo
2,500 recipients₹1,82,500/mo

Available with Enterprise, or standalone — talk to sales.

Talk to sales →

Find out who would click — before an attacker does

Generic-lure campaigns with per-recipient open, click and report tracking, and awareness training assigned exactly where it is needed.