CyberSekCyberSek
NOW LIVE — Available on Boost Plan

Phishing Simulation
 

The most realistic phishing simulation for Indian enterprises — 25+ templates covering CEO fraud, SBI alerts, DocuSign, AWS, UPI scams, and more. First campaign live in 3 minutes.

0%
breaches start with phishing
0+
ready-to-use templates
0m
to launch your first campaign
Mail — Outlook
R
Rajan Mehta (CEO) via gmail.com
To: accounts@yourcompany.com · 2:47 PM
URGENT: Wire Transfer Required — Confidential
Hi Team,

I'm in a board meeting right now. Please process an urgent wire transfer of ₹18,50,000 to our new vendor before EOD. Keep this confidential.

Click below to verify your identity and initiate:
Regards,
Rajan Mehta | CEO
⚠ Sent via external server — not rajan@yourcompany.com
👆 Click the button above to experience what your employees see
🎯
91%
Of breaches start with phishing
📧
25+
Ready-to-deploy Indian templates
3 min
To launch your first campaign
🇮🇳
100%
Indian context SBI · UPI · DPDPA
Everything included

A complete phishing simulation engine

Every feature you need to run realistic, measurable, compliance-ready phishing simulations — from campaign creation to auditor-ready PDF reports.

Core
25+ Indian Templates
CEO fraud, SBI alerts, DocuSign, AWS, Razorpay, UPI scams — built by the same team running real VAPT engagements.
Smart
False-Click Detection
Filters SafeLinks, Proofpoint, and Mimecast bot-clicks automatically. Your click rates reflect real humans only.
Analytics
Department Analytics
Click rates, open rates, credential submission broken down by department. Know exactly who needs training.
Stealth
Staggered Sending
Random 30s–3min delays between sends mimic real attacker behaviour and bypass mass-send spam filters.
Auto
Smart Campaign Rounds
Auto-progression: easy → medium → hard. Employees who click repeatedly face increasingly sophisticated templates.
Testing
A/B Template Testing
Split a campaign across two templates. See which attack vector performs better. Data-driven security decisions.
Tracking
Per-Recipient Timeline
Full event log per employee — sent, opened, clicked, reported. Timestamped audit trail for ISO 27001 evidence.
AI
AI Template Generator
Generate custom templates with OpenAI, Claude, Gemini, or Groq. Describe a scenario, get a ready-to-deploy attack.
Remediation
Auto-Enrol Clickers
Employees who click are automatically enrolled in remedial training. Close the loop without manual admin effort.
Reporting
PDF & CSV Export
One-click branded PDF report or full CSV for your compliance team, auditors, and ISO 27001 evidence packs.
Alerts
Slack & Teams Webhooks
Real-time alerts to Slack, Teams, or any HTTP endpoint when employees click, report, or submit credentials.
SMTP
Bring Your Own SMTP
Connect Mailgun, SendGrid, or AWS SES. Send from your own domain for maximum realism. Full SPF/DKIM/DMARC support.
25+ Templates

Indian attacks that
actually fool people

Built by the same offensive security researchers who run real VAPT engagements. These reference SBI, Razorpay, GST, UPI, and UIDAI — not western templates repurposed for India.

CEO Wire Transfer Campaign
Live
Emails Sent247 (100%)
Opened189 (76%)
Clicked43 (17%)
Credentials8 (3%)
Reported12 (5%)
📄 PDF Report
📊 CSV Export
💸HARD
CEO Wire Transfer
🔐HARD
IT VPN Certificate
📝HARD
DocuSign Pending
🏦HARD
SBI Net Banking
☁️HARD
AWS API Key Alert
💳HARD
Razorpay Settlement
📹HARD
Zoom License Expiry
👥MEDIUM
LinkedIn Profile
🔑MEDIUM
Password Expiry
🧾MEDIUM
Expense Rejected
🏠MEDIUM
WFH Policy Update
📋MEDIUM
Jira Overdue
📱EASY
iPhone 15 Prize
📦EASY
Amazon Survey
🇮🇳EASY
Income Tax Refund
+10 more
Swiggy · Teams
Flipkart · Jira
How it works

From zero to campaign
in 3 minutes

01
Choose a template
Pick from 25+ Indian-context templates or generate a custom one with AI. Each comes with pre-configured landing pages, tracking pixels, and credential capture.
02
Select targets
Choose employees, departments, or your full company. Import via CSV or sync from your directory. Set departments for granular analytics.
03
Configure & launch
Set sending window, stagger delays, SMTP profile, and difficulty progression. Launch immediately or schedule for a specific date and time.
04
Track, report & remediate
Real-time analytics — opens, clicks, credential submissions. Auto-enrol clickers in training. One-click PDF for your ISO 27001 auditor.
Compliance ready

Evidence your auditor
will actually accept

Every campaign generates timestamped audit evidence — branded PDF reports with click rates, per-employee timelines, and remediation proof accepted by ISO 27001, DPDPA, PCI-DSS, and SOC 2 auditors.

ISO 27001:2022
Annex A 6.3 — Information security awareness
DPDPA 2023
Employee training on data handling obligations
PCI-DSS v4.0
Requirement 12.6 — Security awareness programme
SOC 2 Type II
CC1.4 — Commitment to competence and awareness
Campaign Report · CEO Wire Transfer
26 Jul 2026
📤 Emails Sent247
👁️ Opened189 (76%)
🎣 Clicked Phishing Link43 (17%)
🔑 Credentials Submitted8 (3%)
🛡️ Reported as Phishing12 (5%)
📚 Auto-enrolled in Training43
🤖 Bot-clicks Filtered7

Start simulating phishing attacks today.

Join Indian enterprises using CyberSek to measure and improve their human firewall. First campaign live in 3 minutes.