Human risk management platform

PhishGun: phishing simulation and security awareness training for your team

Most incidents still start with a person, not a port. PhishGun sends realistic but harmless phishing to your own people, turns a risky click into training while the mistake is still fresh, and gives you a number for human risk that you can put in front of a board.

It is built by Haxoris out of what our ethical hackers see in real social engineering engagements — and the scenarios are localized, not translated.

The PhishGun dashboard showing total employees, emails sent, opened, links clicked and forms submitted, beside a chart of email interactions over time

PhishGun is built and run by Haxoris. The product itself lives at phishgun.com.

5 minto brief a campaign from a localized template
1 clickfor an employee to report a suspicious message
M365 + Googleuser import from the directory you already run

Overview

What PhishGun does

PhishGun runs simulated phishing against your own employees and measures what happens next: who opened it, who clicked, who typed something in, and — the number most programmes never collect — who reported it.

The click is where most tools stop. PhishGun treats it as the start: it opens a short, contextual lesson that walks the person through the signals that message actually carried, at the one moment they are guaranteed to be paying attention.

What comes out is a measurable trend per team rather than a completion certificate — and a set of records that a NIS2, ISO 27001 or DORA reviewer will accept as evidence that awareness training happened.

Security leaders

A defensible human-risk number, trended over time, and the evidence to show a board or a regulator what changed.

IT administrators

Users imported from Microsoft 365 or Google Workspace, campaigns that throttle themselves, and no new directory to maintain.

Compliance owners

Dated, per-person records of awareness activity — the artefact an auditor asks for when a policy document is not enough.

Features and benefits

Four things the platform actually does

Not a content library with a quiz attached. Each of these exists because it changes a number you can measure the following quarter.

Smart phishing simulations

Campaigns segmented by department, risk level, language and business context — an invoice lure to finance and an MFA prompt to engineering, not one generic template fired at everybody on the same Tuesday morning.

Training in the moment

A risky click opens a short lesson that names the signals the message carried — the display name that did not match the domain, the urgency, the link that resolved somewhere else. Delivered while the mistake is still fresh, which is the only time it sticks.

One-click report button

Employees report a suspicious message straight from their mail client. That turns a silent non-event into a measurable signal, reinforces the people who got it right, and shortens the path from a real attack landing to your team hearing about it.

Analytics that hold up

Click rate, report rate, training completion, repeat risk and campaign progress — per team and over time. The trend is the deliverable; a single campaign's click rate on its own tells you very little.

The PhishGun template library: a grid of phishing templates impersonating Atlassian, Telekom, Slovenská pošta, Finančná správa, VÚB, Tatra banka, Alza, Google, Zoom and Microsoft, each tagged by intent

Template library

Templates that look local, because they are

A lure only works if it belongs. The library ships the senders your people actually get mail from — Slovenská pošta, Finančná správa, Tatra banka, VÚB, Packeta, Alza — next to the global ones every workforce sees: Microsoft, Google, Atlassian, Zoom.

Each template is tagged by what it is after — credentials, card data, PII — and by whether it impersonates a public brand or something internal. That is what lets you aim a campaign at one specific risk instead of hoping a generic lure lands.

Reporting

The whole funnel, not just the click rate

Sent, opened, clicked, submitted — with the drop-off at every step. A click rate on its own hides the number that matters most: how many people went past the click and actually handed something over.

That last percentage is the one worth taking to a board, because it is the closest measurable proxy for what a real attacker would have walked away with.

A PhishGun campaign results funnel: 100% sent to 120 recipients, 47% opened, 14% clicked, 4.2% submitted a form

Start with one free campaign

The fastest way to know whether this is a problem in your organisation is to run it once. One campaign, your own people, your own numbers — before any commitment.

  • Pick one department to start with — you do not need to import the whole directory.
  • Choose a localized scenario or adapt one to a lure your sector is seeing right now.
  • Get click rate, report rate and a per-team breakdown at the end of the run.

How it works

Five steps from an empty account to a reportable trend

The first campaign takes an afternoon. Everything after it is a repeat of the same loop on a shorter cycle.

1

Connect your users

Import teams from Microsoft 365 or Google Workspace, or upload a list. Group people by department, seniority or risk profile so a campaign can be aimed rather than broadcast.

2

Choose the scenario

Pick a localized template — invoice, delivery notice, HR announcement, MFA prompt, internal IT request — or adapt one to a lure your sector is actually seeing this quarter.

3

Launch safely

Guardrails, send throttling and controlled landing pages keep a simulation from disrupting the business or setting off your own detection stack. The window and the scope are agreed before anything goes out.

4

Train at the moment of the click

Anyone who clicks gets the short lesson. Anyone who reports gets reinforcement instead of silence — which is what turns the report button from a feature into a habit.

5

Report the trend

Click rate, report rate and completion by team, tracked across campaigns. That is what goes to leadership, and it is the same record set that answers an auditor asking how awareness training is evidenced.

A PhishGun employee detail view: campaigns, compromised and reported counts, a risk score of 78 out of 100, and radar charts of attack vector and attack intent exposure

Human risk scoring

A score for every person, and the reason behind it

Each employee carries a score built from what they have actually done across campaigns — compromised, reported, ignored — rather than from a quiz result at the end of a slide deck.

The exposure breakdown shows which attack vectors and which intents that person has been tested against. A low score is never a mystery, and a high one arrives with the specific gap to close.

Capabilities

What is included

PhishGun is delivered as a hosted platform, separate from Haxoris consulting engagements and with its own subscription.

AreaIncluded
CampaignsLocalized email templates, controlled landing pages, targeting by department, risk level, language and business context, send throttling and campaign guardrails
TrainingJust-in-time training triggered by a risky click, contextual explanation of the signals the message carried, completion tracking per person
Report buttonOne-click reporting of a suspicious message from the employee's mail client, reinforcement for correct reports, report-rate tracking
Users and administrationUser import from Microsoft 365 or Google Workspace, grouping by team, department and risk profile
AnalyticsClick rate, report rate, training completion, repeat risk and campaign progress, per campaign and per team
Compliance evidenceRecords of awareness activity that can be produced for NIS2, ISO 27001 and DORA reviews

Current plans, limits and pricing live on the PhishGun pricing page.

Regulatory context

Why awareness training is now a named obligation

Three European frameworks put security awareness on the record rather than leaving it to good intentions. In all three, the burden is evidence — not a policy stating that training exists.

NIS2

Article 20(2) requires members of management bodies to follow training and to encourage regular training for staff. Article 21(2)(g) lists basic cyber hygiene practices and cybersecurity training among the baseline measures. Recurring simulations and dated completion records are how that is shown. NIS2 testing at Haxoris.

ISO/IEC 27001

Annex A control 6.3 requires awareness, education and training appropriate to a person's role, updated regularly. An auditor asks for per-person evidence over time, which a one-off onboarding deck cannot produce. ISO 27001 testing at Haxoris.

DORA

Article 13(6) requires financial entities to run ICT security awareness programmes and digital operational resilience training as compulsory modules — explicitly covering senior management, not only technical staff.

Where PhishGun sits next to a Haxoris engagement

They answer different questions, and most organisations end up wanting both. A social engineering assessment is a point-in-time engagement: our ethical hackers build bespoke pretexts, run phishing, vishing and smishing against an agreed scope, and report how far a determined attacker got.

PhishGun is the programme that runs between those engagements — continuous, self-service, and aimed at moving the baseline rather than proving a single breach path.

In practice:

  • Assessment first, platform after — an engagement tells you which pretexts actually work on your people; those become the scenarios worth repeating.
  • Platform for the trend — click and report rates per team, quarter over quarter, is the metric that shows the programme is working.
  • Training for the gaps the numbers expose — see cybersecurity awareness training for instructor-led sessions built on your own campaign results.
  • Assessment again to verify — a fresh engagement against a trained population is the honest test of whether the number moved.

Frequently asked questions

01 Is PhishGun a Haxoris product?

Yes. PhishGun is built and operated by Haxoris, and the scenarios come from the same team that runs our social engineering engagements. It has its own site and its own subscription at phishgun.com, because it is a platform rather than a consulting service — but it is our product, not a reseller arrangement.

02 How is this different from a Haxoris social engineering assessment?

An assessment is an engagement: bespoke pretexts, phishing plus vishing and smishing, run by our testers against an agreed scope, ending in a report on how far an attacker got and why. PhishGun is a platform you run yourself, continuously, to move the baseline between those engagements. The assessment tells you what works against your people; the platform is how you fix it and prove the fix.

03 Are the simulated messages safe to send to real employees?

Yes — a simulation is built to measure a reaction, not to compromise anything. There is no malware and no payload. Campaigns run with guardrails and send throttling so a simulation does not disrupt the business, and the scope, the window and exactly what is recorded are agreed before the first message goes out.

04 Which languages are the scenarios available in?

Slovak, Czech and English. They are localized rather than machine-translated, which matters more than it sounds: a lure that reads like it was translated is caught for the wrong reason, and the campaign then measures your employees' feel for awkward phrasing instead of their feel for a phishing attempt.

05 Do we have to import our whole directory to start?

No. Start with one department. Users can be imported from Microsoft 365 or Google Workspace or uploaded as a list, and the scope can widen once you have seen what the first campaign returns.

06 Does running PhishGun make us NIS2, ISO 27001 or DORA compliant?

No tool makes an organisation compliant, and treat any vendor who says otherwise with suspicion. What PhishGun produces is the evidence for one specific obligation inside each of those frameworks — that security awareness training happens, reaches the right people including management, and repeats. That is one control among many, and it is a control that is otherwise very hard to evidence.

See what your own click rate looks like

Start with one free campaign, or book a demo and we will walk through the platform with your environment in mind.

Request accessBook a demo