business@xdepthsense.com
+91 97695 13095  |  +91 98335 86361  |  +91 96197 39550
// Managed Programme

Phishing Simulation &
Security Awareness

Your people are the last control standing when a look-alike invoice arrives. We run the programme that trains and measures them — on the platform we built ourselves.

Not a campaign.
A programme

Most organisations run one phishing test a year, get a click rate, and file it. Nothing changes, because a click rate is not a control. A programme is different: recurring multi-vector simulations, training delivered at the moment someone fails, a working report button so staff can raise the real ones, and a number that moves quarter on quarter.

We deploy the platform inside your environment, design the lure calendar around the threats your business actually faces, run every campaign, triage what employees escalate, and deliver a human-risk report written for the people who approve budgets — not for a SOC analyst.

Email & QR LuresBEC ScenariosJust-in-Time Training Report Button RolloutHuman Risk ScoringBoard Reporting
Scope a programme →

What we operate for you

Platform deployment & hardening

Installed in your environment, SSO and 2FA configured, sending domain warmed and authenticated

Lure design & campaign calendar

Scenarios built from real cases in your sector, scheduled so staff cannot pattern-match the timing

Report-button rollout & triage

Outlook or Gmail reporting deployed, and the real suspicious mail your staff raise gets reviewed

Training & escalation handling

Repeat clickers auto-enrolled, manager questions answered, HR-safe handling throughout

Quarterly human-risk report

Risk by department, trend against the previous quarter, and what to fix next

Four phases, then it repeats

Baseline

We agree scope and authorisation, deploy the platform, import your audience, and run an unannounced baseline simulation. This is the number everything afterwards is measured against.

Enable

The report button goes into Outlook or Gmail, staff are told the programme exists, and the training library is set up. Reporting is the behaviour we are actually trying to build.

Run

Campaigns go out on a rolling calendar across email, QR codes and calendar invites. Failures get a teaching page immediately; repeat failures are auto-enrolled in a module.

Report

Each quarter you get risk scores by department, the trend line, benchmark context, and a short list of what to change — in process, not just in training.

What lands on your desk

Programme charter

Scope, authorisation, audience, escalation path and data-retention position — signed before the first mail goes out.

Campaign records

Every lure, every send window and every result, retained in an append-only audit log you can hand to an auditor.

Human-risk report

Quarterly. Risk by user and department, quarter-on-quarter movement, benchmark comparison, and prioritised recommendations.

Board summary

A two-page version in business language, so the numbers survive contact with people who do not work in security.

Reported-mail triage

The genuinely suspicious mail your staff report, reviewed by our analysts — with escalation to our DFIR team if something is real.

Compliance evidence

Awareness-training evidence mapped to ISO 27001, SEBI CSCRF and DPDPA expectations, ready for your next audit.

We are not reselling somebody else’s platform

The programme runs on VoltPhish — an open-source phishing simulation and awareness platform that XDepthSense builds and maintains. That matters for three practical reasons.

There is no per-seat licence. You pay for the work we do, not for a headcount multiplier. Growing from 80 to 300 employees does not change the software cost, because there isn’t one.

Your data stays in your environment. The platform is self-hosted. Employee names, addresses and results never leave your infrastructure, which makes the DPDPA and GDPR conversation considerably shorter.

You are never locked in. If you stop the retainer, the platform is still yours — it is free software and it keeps running. You can take the programme in-house and we will hand over the runbook.

See the platform →

Where it earns its keep

Organisations where a single convincing email can move money or data: finance and accounts teams handling supplier payments, shipping and trading firms working long email threads with overseas counterparties, professional services holding client data, and any regulated entity that has to evidence awareness training.

It is a particularly good fit for organisations with no dedicated security team — where IT is one or two people already doing three jobs, and an awareness programme is the first thing to slip.

How it is priced

A fixed quarterly fee based on headcount band and the number of campaigns, not a per-user licence. Deployment is a one-off at the start. Everything is scoped on a short call and written down before anything is signed.

Simulation testing is also available as an add-on to an existing VAPT or SEBI CSCRF engagement, where the awareness evidence is needed for the same audit.

Get a quote →

Find out what your staff would actually do

A baseline simulation takes about a week to stand up and tells you more about your real exposure than most annual reports do. Start there.

Talk to us →