Skip to content

How it works

One loop, four moves, each one feeding the next.

Most awareness tools run a campaign and produce a number. This one is a circuit: what your people catch becomes intelligence, the intelligence shapes the next simulation, and the simulation decides who gets which training. Every pass raises the score rather than repeating the measurement.

  1. Move 01
    01

    Collect Threat Intelligence

    Continuously gather intelligence from vulnerability feeds, breach and leak sources, threat communities, malicious infrastructure, open-source intelligence and other external channels.

    The add-in puts a Report button in every mailbox, so the person who spotted the lure does not have to forward it, describe it, or decide whether it is worth mentioning. The full message — headers, body, attachments — reaches an analyst queue intact, which is what makes it usable as evidence rather than as an anecdote.

  2. Move 02
    02

    Enrich & Correlate

    Identify CVEs, IPs, domains, URLs, hashes, malware, threat actors and campaigns, then enrich and correlate them using exploitability, reputation, source reliability, recency and threat context.

    A report on its own is one email. Against the catalogue it becomes a data point: is this infrastructure new, who else has seen it, does it match an actor we profile, and are any of your people already exposed in a breach corpus. That is the difference between a spam folder and an intelligence picture.

  3. Move 03
    03

    Match to Your Environment

    Campaigns modelled on what is actually circulating here this quarter — safe, measured, department by department.

    Templates derive from what is landing in inboxes in this market now, not from a global library’s greatest hits. Campaigns run per department and per risk profile, tracking opens, clicks, attachment opens and credential submission, so a result is specific enough to act on.

  4. Move 04and back to 01
    04

    Prioritise & Act

    Surface the most relevant threats through alerts, reports and analyst workflows, and push validated intelligence into SOC/SIEM environments for hunting, detection, investigation and response.

    Assignment follows the outcome rather than the calendar. Someone who submitted credentials to a payroll lure gets the payroll lesson, not the annual video. Completion and comprehension are tracked to the individual, and anyone who clicks twice is surfaced rather than averaged away.

Why it is a loop and not a checklist

A checklist ends. The reason this is drawn as a circuit is that move 04 changes move 03: the training someone completes changes what they fall for, so next quarter’s simulation has to be different to tell you anything. And move 01 changes move 02 — every report from a client organisation is a data point no global feed has, which is what makes the analysis regional rather than generic.

Run once, it is an audit. Run continuously, it is a control.

See it on your own estate

Thirty minutes, with lures from your sector and the intelligence view your organisation would see on day one.

Or see what is in it

One package with the whole platform in it, listed capability by capability. Then we scope it with you and put a number in writing.