Phishing SimulationPhishing simulation — and the seven channels most platforms ignore.

Most programmes test email and call it awareness. Attackers use eight channels — deepfake calls, WhatsApp lures, QR drops — so all eight get simulated.

GDPR ready · EU data residency (Frankfurt)
CHANNELS SIMULATED18EmailSMSVoiceDeepfakeWhatsAppQRUSBCallbackemail is one eighth of the surface, not the surface
CHANNELS SIMULATED8EmailSMSVoiceDeepfakeWhatsAppQRUSBCallbackemail is one eighth of the surface,not the surface
8
attack channels — email to deepfake to USB drops
33.2%
of employees fail a phishing test at baseline, before any programme runs¹
4.2%
after twelve months of continuous simulation and training¹

The eight channels

Email Phishing
AI-crafted lures matched to role, language, and current events.
Smishing (SMS)
Delivery notices, MFA resets, executive requests — on the device people trust most.
Vishing (Voice)
AI-voiced phone simulations in your employees' native language.
Deepfake Voice & Video
Cloned-voice scenarios targeting finance and executive teams.
WhatsApp Phishing
Messaging-app lures where corporate guards are lowest.
QR Phishing (Quishing)
Poisoned QR codes in the flows employees scan without thinking.
USB Drop
Physical baiting campaigns that test curiosity at the desk.
Callback (TOAD)
Harmless-looking emails that route victims to a hostile phone call.

¹ KnowBe4 Phishing by Industry Benchmarking Report, 2026 — 42 million simulations across 14.8 million users at 64,000 organizations. Industry research, not NOUSEC results.

Continuous waves, not annual blasts

One mass test warns the whole office by lunchtime. NOUSEC samples continuously instead.

Randomized delivery
Small waves, varied timing, varied templates — so results measure behavior, not office gossip.
AI-crafted lures
Generated per campaign, matched to role and language. No recycled template museum that everyone has seen twice.
Feeds the score
Every interaction — click, credential entry, report, ignore — flows straight into the Human Risk Score and each employee's adaptive training program.

Frequently asked questions

Which attack channels can NOUSEC simulate?

Eight: email phishing, smishing (SMS), vishing (voice), deepfake voice & video, WhatsApp phishing, QR code phishing (quishing), USB drops, and callback scams (TOAD). Attackers don't stop at email — neither do the simulations.

Are the simulations realistic enough to matter?

Lures are AI-crafted per campaign in employees' native languages, and voice simulations use deepfake-grade audio your executives will believe — because the attackers' versions will be. Realism is the point: a test nobody could fail measures nothing.

Will simulations disrupt or embarrass employees?

No. Campaigns run in small randomized waves rather than one office-wide blast, results drive private, adaptive micro-training rather than public shaming, and reporting is celebrated as the win condition.

Do we need to whitelist servers or install anything?

No endpoint agents and no software installation are required. Deliverability setup is guided, and reporting works through one-click Gmail and Outlook add-ins.

Test the channels attackers actually use.

See a live multi-channel simulation — including a deepfake voice call — in a 20-minute demo.

Book a demo