$ anchor services --phish
Technical Services

Phishing Simulation

Training tells your team what to watch for. This measures whether it worked.

Authorized, scoped phishing campaigns that show you exactly how your organization responds to a real attempt — then close the gap with targeted follow-up.

What We Run

Every campaign is scoped and authorized in writing before it launches — a fixed engagement, not ongoing surveillance of your employees.

Baseline Phishing Assessment

A realistic, generic-pretext campaign across your organization to establish an honest starting point — click rate, credential-submission rate, and report rate.

Deliverables
  • Full-organization or sampled campaign
  • Click, submission, and report-rate metrics
  • Comparison against industry benchmarks
  • Prioritized follow-up recommendations

Targeted Pretext Simulation

A campaign built around pretexts relevant to your industry or a real incident you've seen — invoice fraud, vendor impersonation, internal IT requests.

Deliverables
  • Pretext scenarios scoped to your actual risk
  • Role-based targeting (finance, IT, leadership)
  • Results broken out by department
  • Debrief with your leadership team

Credential Harvesting Simulation

Tests whether employees will enter real credentials into a convincing fake login page — the highest-impact failure mode, measured directly.

Deliverables
  • Cloned, safe landing-page simulation
  • Immediate in-the-moment training page on click
  • Credential-submission rate, isolated from click rate
  • Recommendations for MFA/conditional access gaps

Quishing (QR Code Phishing)

Tests whether employees scan and follow unverified QR codes — a fast-growing vector that skips most email security filters entirely, since the payload is an image, not a link.

Deliverables
  • QR-based lures embedded in email or printed materials
  • Scan-through rate tracked via the same landing-page infrastructure
  • Device/platform breakdown (personal vs. managed devices)
  • Guidance on physical placement risk (breakrooms, parking lots, mailers)

Reporting & Follow-Up Training

The part most vendors skip: turning results into an actual reduction in risk, not just a scorecard to file away.

Deliverables
  • Plain-language report for leadership
  • Targeted micro-training for repeat clickers
  • Re-test scheduling to measure improvement
  • Recommendations for reporting-button tooling

Our Approach

A phishing test should change behavior, not morale.

Authorized, Never a Trap

Every campaign has documented, written authorization from your leadership before it launches — defined scope, defined targets, defined boundaries.

Built to Improve, Not Shame

Results are reported in aggregate to leadership, with constructive follow-up training for repeat clickers — not a public list used to embarrass anyone.

Fixed-Scope Campaigns

This is a scoped engagement with a start and an end, not continuous monitoring of your employees' inboxes.

Open-Source Tools, Deployed Right

No third-party platform holding a list of who clicked what. We run open-source campaign tooling ourselves, on infrastructure scoped to your engagement.

GoPhish
Open-source phishing campaign framework — templates, tracking, and safe landing pages. Actively maintained, handles multi-campaign and multi-pretext work natively.

What Makes This Different

  • Written authorization, always
    No campaign launches without documented sign-off on scope and pretext
  • Your data stays yours
    Results live in your report, not a vendor's SaaS dashboard
  • Debrief, not just a scorecard
    We walk leadership through what happened and what to do next
  • Pairs with real training
    Follow-up training targeted at what your team actually got wrong

Engagement Process

Scoped and authorized before anything launches — you'll know exactly what's being tested and why.

1

Scope & Authorize

Define targets, pretexts, and boundaries — get written sign-off

2

Campaign Design

Build a realistic pretext relevant to your organization

3

Launch & Measure

Track opens, clicks, submissions, and reports as they happen

4

Report & Train

Debrief results and deliver targeted follow-up training

Want to know how your team would actually respond?

Let's scope an authorized phishing simulation — fixed engagement, clear reporting, real follow-up training.

Request a Free Phishing Test