Human risk management platform
PhishGun: phishing simulation and security awareness training for your team
Most incidents still start with a person, not a port. PhishGun sends realistic but harmless phishing to your own people, turns a risky click into training while the mistake is still fresh, and gives you a number for human risk that you can put in front of a board.
It is built by Haxoris out of what our ethical hackers see in real social engineering engagements — and the scenarios are localized, not translated.
PhishGun is built and run by Haxoris. The product itself lives at phishgun.com.
Overview
What PhishGun does
PhishGun runs simulated phishing against your own employees and measures what happens next: who opened it, who clicked, who typed something in, and — the number most programmes never collect — who reported it.
The click is where most tools stop. PhishGun treats it as the start: it opens a short, contextual lesson that walks the person through the signals that message actually carried, at the one moment they are guaranteed to be paying attention.
What comes out is a measurable trend per team rather than a completion certificate — and a set of records that a NIS2, ISO 27001 or DORA reviewer will accept as evidence that awareness training happened.
A defensible human-risk number, trended over time, and the evidence to show a board or a regulator what changed.
Users imported from Microsoft 365 or Google Workspace, campaigns that throttle themselves, and no new directory to maintain.
Dated, per-person records of awareness activity — the artefact an auditor asks for when a policy document is not enough.
Features and benefits
Four things the platform actually does
Not a content library with a quiz attached. Each of these exists because it changes a number you can measure the following quarter.
Smart phishing simulations
Campaigns segmented by department, risk level, language and business context — an invoice lure to finance and an MFA prompt to engineering, not one generic template fired at everybody on the same Tuesday morning.
Training in the moment
A risky click opens a short lesson that names the signals the message carried — the display name that did not match the domain, the urgency, the link that resolved somewhere else. Delivered while the mistake is still fresh, which is the only time it sticks.
One-click report button
Employees report a suspicious message straight from their mail client. That turns a silent non-event into a measurable signal, reinforces the people who got it right, and shortens the path from a real attack landing to your team hearing about it.
Analytics that hold up
Click rate, report rate, training completion, repeat risk and campaign progress — per team and over time. The trend is the deliverable; a single campaign's click rate on its own tells you very little.
Template library
Templates that look local, because they are
A lure only works if it belongs. The library ships the senders your people actually get mail from — Slovenská pošta, Finančná správa, Tatra banka, VÚB, Packeta, Alza — next to the global ones every workforce sees: Microsoft, Google, Atlassian, Zoom.
Each template is tagged by what it is after — credentials, card data, PII — and by whether it impersonates a public brand or something internal. That is what lets you aim a campaign at one specific risk instead of hoping a generic lure lands.
Reporting
The whole funnel, not just the click rate
Sent, opened, clicked, submitted — with the drop-off at every step. A click rate on its own hides the number that matters most: how many people went past the click and actually handed something over.
That last percentage is the one worth taking to a board, because it is the closest measurable proxy for what a real attacker would have walked away with.
Start with one free campaign
The fastest way to know whether this is a problem in your organisation is to run it once. One campaign, your own people, your own numbers — before any commitment.
- Pick one department to start with — you do not need to import the whole directory.
- Choose a localized scenario or adapt one to a lure your sector is seeing right now.
- Get click rate, report rate and a per-team breakdown at the end of the run.
How it works
Five steps from an empty account to a reportable trend
The first campaign takes an afternoon. Everything after it is a repeat of the same loop on a shorter cycle.
Connect your users
Import teams from Microsoft 365 or Google Workspace, or upload a list. Group people by department, seniority or risk profile so a campaign can be aimed rather than broadcast.
Choose the scenario
Pick a localized template — invoice, delivery notice, HR announcement, MFA prompt, internal IT request — or adapt one to a lure your sector is actually seeing this quarter.
Launch safely
Guardrails, send throttling and controlled landing pages keep a simulation from disrupting the business or setting off your own detection stack. The window and the scope are agreed before anything goes out.
Train at the moment of the click
Anyone who clicks gets the short lesson. Anyone who reports gets reinforcement instead of silence — which is what turns the report button from a feature into a habit.
Report the trend
Click rate, report rate and completion by team, tracked across campaigns. That is what goes to leadership, and it is the same record set that answers an auditor asking how awareness training is evidenced.
Human risk scoring
A score for every person, and the reason behind it
Each employee carries a score built from what they have actually done across campaigns — compromised, reported, ignored — rather than from a quiz result at the end of a slide deck.
The exposure breakdown shows which attack vectors and which intents that person has been tested against. A low score is never a mystery, and a high one arrives with the specific gap to close.
Capabilities
What is included
PhishGun is delivered as a hosted platform, separate from Haxoris consulting engagements and with its own subscription.
| Area | Included |
|---|---|
| Campaigns | Localized email templates, controlled landing pages, targeting by department, risk level, language and business context, send throttling and campaign guardrails |
| Training | Just-in-time training triggered by a risky click, contextual explanation of the signals the message carried, completion tracking per person |
| Report button | One-click reporting of a suspicious message from the employee's mail client, reinforcement for correct reports, report-rate tracking |
| Users and administration | User import from Microsoft 365 or Google Workspace, grouping by team, department and risk profile |
| Analytics | Click rate, report rate, training completion, repeat risk and campaign progress, per campaign and per team |
| Compliance evidence | Records of awareness activity that can be produced for NIS2, ISO 27001 and DORA reviews |
Current plans, limits and pricing live on the PhishGun pricing page.
Regulatory context
Why awareness training is now a named obligation
Three European frameworks put security awareness on the record rather than leaving it to good intentions. In all three, the burden is evidence — not a policy stating that training exists.
NIS2
Article 20(2) requires members of management bodies to follow training and to encourage regular training for staff. Article 21(2)(g) lists basic cyber hygiene practices and cybersecurity training among the baseline measures. Recurring simulations and dated completion records are how that is shown. NIS2 testing at Haxoris.
ISO/IEC 27001
Annex A control 6.3 requires awareness, education and training appropriate to a person's role, updated regularly. An auditor asks for per-person evidence over time, which a one-off onboarding deck cannot produce. ISO 27001 testing at Haxoris.
DORA
Article 13(6) requires financial entities to run ICT security awareness programmes and digital operational resilience training as compulsory modules — explicitly covering senior management, not only technical staff.
Where PhishGun sits next to a Haxoris engagement
They answer different questions, and most organisations end up wanting both. A social engineering assessment is a point-in-time engagement: our ethical hackers build bespoke pretexts, run phishing, vishing and smishing against an agreed scope, and report how far a determined attacker got.
PhishGun is the programme that runs between those engagements — continuous, self-service, and aimed at moving the baseline rather than proving a single breach path.
In practice:
- Assessment first, platform after — an engagement tells you which pretexts actually work on your people; those become the scenarios worth repeating.
- Platform for the trend — click and report rates per team, quarter over quarter, is the metric that shows the programme is working.
- Training for the gaps the numbers expose — see cybersecurity awareness training for instructor-led sessions built on your own campaign results.
- Assessment again to verify — a fresh engagement against a trained population is the honest test of whether the number moved.
Frequently asked questions
01 Is PhishGun a Haxoris product?
Yes. PhishGun is built and operated by Haxoris, and the scenarios come from the same team that runs our social engineering engagements. It has its own site and its own subscription at phishgun.com, because it is a platform rather than a consulting service — but it is our product, not a reseller arrangement.
02 How is this different from a Haxoris social engineering assessment?
An assessment is an engagement: bespoke pretexts, phishing plus vishing and smishing, run by our testers against an agreed scope, ending in a report on how far an attacker got and why. PhishGun is a platform you run yourself, continuously, to move the baseline between those engagements. The assessment tells you what works against your people; the platform is how you fix it and prove the fix.
03 Are the simulated messages safe to send to real employees?
Yes — a simulation is built to measure a reaction, not to compromise anything. There is no malware and no payload. Campaigns run with guardrails and send throttling so a simulation does not disrupt the business, and the scope, the window and exactly what is recorded are agreed before the first message goes out.
04 Which languages are the scenarios available in?
Slovak, Czech and English. They are localized rather than machine-translated, which matters more than it sounds: a lure that reads like it was translated is caught for the wrong reason, and the campaign then measures your employees' feel for awkward phrasing instead of their feel for a phishing attempt.
05 Do we have to import our whole directory to start?
No. Start with one department. Users can be imported from Microsoft 365 or Google Workspace or uploaded as a list, and the scope can widen once you have seen what the first campaign returns.
06 Does running PhishGun make us NIS2, ISO 27001 or DORA compliant?
No tool makes an organisation compliant, and treat any vendor who says otherwise with suspicion. What PhishGun produces is the evidence for one specific obligation inside each of those frameworks — that security awareness training happens, reaches the right people including management, and repeats. That is one control among many, and it is a control that is otherwise very hard to evidence.
See what your own click rate looks like
Start with one free campaign, or book a demo and we will walk through the platform with your environment in mind.
Request accessBook a demo