Tailored campaigns
We design simulations for your business, with scenarios varied by department, role, and exposure level, faithful to the tactics real attackers use.
The necessary ones make the site work. The others measure which pages help and which ads bring the people who need DM11. Your choice, and you can revisit it from the footer.

JIGPHISH®: SOCIAL ENGINEERING
The human element is present in 62% of data breaches and phishing appears in 16% of them, according to the Verizon DBIR 2026, the Data Breach Investigations Report, the annual study of confirmed data breaches. No tool solves the human factor on its own. Jigphish® tests, educates, and protects your workforce with realistic simulations conducted with empathy, never exposure.
62%
of breaches involve the human element
16%
of data breaches involve phishing
41%
of social engineering now arrives outside email
Source for the three figures: Verizon 2026 Data Breach Investigations Report, 19th edition, pages 12, 48 and 49, covering incidents between November 2024 and October 2025. Verified on 27 July 2026.
HOW IT WORKS
Zero tooling investment: our human risk and behavior management team handles everything.
We design simulations for your business, with scenarios varied by department, role, and exposure level, faithful to the tactics real attackers use.
Detailed behavioral reports: who opened, who clicked, who reported. We identify vulnerable groups and track progress campaign after campaign.
Every click on a simulation becomes immediate learning and targeted training. We use influence and empathy, never manipulation or fear tactics.
We track user actions securely and non-intrusively, with full respect for employee dignity and privacy requirements.
More than one-off campaigns: a permanent program that strengthens security culture and gets new employees up to speed faster.
Ready-to-use evidence for audits and regulatory requirements that demand an active awareness program.
SELF-ASSESSMENT
Objective questions about what happens when a well-crafted lure reaches someone on your team. The result shows where your defense is structure and where it still runs on luck.
A button in the mail client, a dedicated address, a contact on chat. The honest test: ask someone outside IT where they would send it.
The reading for each area, across the three result ranges. It is the same text emailed to those who identify themselves, published here for anyone who wants to understand what the score measures before answering.
Below 50
Without a known, safe reporting channel, the first warning of a real attack arrives late or not at all. Define one path for reporting, promote it until it becomes reflex, and make it explicit that speaking up after a click never brings punishment. A fast warning from someone who fell is worth more than the silence of someone who escaped.
50 to 79
The channel exists, but it depends on who remembers it and on how each manager reacts to a mistake. The jump in this range is answering every report and publicly treating whoever spoke up as part of the defense. A report that gets no reply dies within weeks.
80 or above
A strong reporting culture in your answers. The next refinement is measuring the time between the lure arriving and the first warning, because that interval is what decides the size of the damage on the real day.
Below 50
Rare, generic training prepares the team for yesterday's scam. Start with short, frequent sessions built on each area's actual work, and put the topic in every new hire's first weeks. Fifteen minutes a quarter beats one afternoon a year.
50 to 79
Training exists, but with irregular cadence or depth, and the difference shows between teams. Fit the scenario to the real job: whoever pays invoices trains with invoices, whoever hires trains with résumés. Generic content produces generic attention.
80 or above
Mature training in your answers. The next gain is tying content to what the simulations show: each campaign reveals which lure still works, and that lure sets the theme of the next session.
Below 50
Without MFA on every exposed account and DMARC in an enforcing mode, a phished password becomes access and anyone can send email in your brand's name. These are the two highest-return technical controls against phishing, and neither requires a new tool.
50 to 79
The foundation exists, but with exceptions, and the attacker hunts exactly the exception: the old account without a second factor, the forgotten domain without DMARC. Closing coverage is worth more than adding any new layer. After that, move the second factor toward forms that resist code theft.
80 or above
Authentication and email well handled in your answers. The next refinement is phishing-resistant second factors on the highest-privilege accounts, plus watching the DMARC reports, which show who is trying to use your domain.
Below 50
Without simulation, your team's first real test is the real attack, and it does not come with a report. One well-designed campaign, communicated with respect, shows the starting point without exposing anyone. What is not measured does not improve.
50 to 79
Simulations happen, but without firm cadence or without measuring what matters. Click rate alone misleads: report rate is the metric that predicts behavior on the real day. Measure both, by group, and compare campaign to campaign.
80 or above
Mature simulation and measurement in your answers. The next step is sophistication: lures specific to each area, channels beyond email, and difficulty rising along with the team.
Below 50
Today, a successful click would have to be handled by improvisation, and improvising while the attacker's session is active is expensive. Define the minimum steps now: revoke sessions, reset credentials and hunt the other copies of the same email. Writing it down takes an afternoon and changes the outcome of the bad day.
50 to 79
Response exists, but it depends on who is on duty. Turn improvisation into a script: who does what in the first thirty minutes, and one exercise a year to check that the script works. Include the payment case: supplier fraud is solved by process, not by technology.
80 or above
Structured response in your answers. The next gain is speed: automating session revocation and removing the email from every other inbox shortens the window in which the phished password is still worth something.
Below 50
If guidance covers only email, the attacker changes channel and finds open field: SMS, WhatsApp and voice have no filter and no report button. Start by bringing those channels into training, and agree on a simple verification for sensitive requests by phone. The scam migrates to wherever nobody is looking.
50 to 79
The other channels are on the radar, but without a firm procedure. What is missing is agreeing in advance how a sensitive request outside email gets verified: call back on the number you already had, confirm on a separate channel, use an agreed word when the matter is critical. Under improvisation, urgency wins.
80 or above
Mature channel coverage in your answers. Keep the procedure alive with occasional tests over SMS and voice, because cloning a voice has become cheap and the next convincing request may sound exactly like someone from the house.
Run a first pilot campaign and discover, with data, your team's real exposure to social engineering.