Training Programme

Phishing & Social Engineering Simulation

A 4 to 12 week organisation-wide programme combining simulated phishing and social engineering with structured, non-punitive follow-up training.

Phishing & Social Engineering Simulation

Awareness training without measurement is a compliance exercise.


Awareness training without measurement is a compliance exercise, evidence of a session having happened, not evidence that anyone would actually behave differently when it mattered. This programme runs simulated phishing and social engineering attempts against your organisation over an agreed period, measures how the organisation actually responds rather than how it says it would, and follows up with targeted, non-punitive training for the patterns the simulation surfaces. Scoped and reported on by a named analyst throughout, so the result is a genuine, evidenced picture of organisational resilience rather than a certificate of attendance.

What's Covered

What this programme covers.


Simulated phishing campaigns built around current, realistic fraud typologies

Pretext phone or in-person social engineering scenarios where agreed in scope

Departmental and role-based response measurement, not individual scorekeeping

Structured, non-punitive follow-up training targeted at the patterns the simulation actually reveals

A final report showing genuine organisational response, not stated intentions

Outcomes

What attendees leave able to do.


Delivery

How it's run.


Delivered as a 4 to 12 week programme, scoped to your organisation's size and objectives, combining simulated phishing and, where agreed, social engineering scenarios with structured follow-up training. Scoped, run and reported on throughout by a named Greyline analyst, with results aggregated at department or role level rather than used to identify or penalise individuals.

Frequently Asked

Questions we're asked most.


Will individual employees be named or penalised for failing a simulation?

No. Results are reported in aggregate, by department or role, specifically to support targeted follow-up training rather than to identify or penalise individuals.

How is this different from off-the-shelf phishing simulation software?

Scenarios are built by analysts around current, real fraud typologies relevant to your sector, rather than generic templates, and the programme includes structured human-led follow-up training, not just a dashboard of click rates.

Can this include social engineering beyond email, like phone or in-person attempts?

Yes, where agreed as part of scope, and always under clear, written rules of engagement confirmed with you before any simulation runs.

How long does the full programme typically run?

Between 4 and 12 weeks, scoped to your organisation's size and objectives, confirmed on your scoping call.

What happens after the programme ends?

You receive a final report on organisational response patterns and the specific training delivered in response, and many clients repeat the programme periodically to track improvement over time.

Bring This to Your Organisation

Enquire and scope this programme.

Every programme is scoped to the organisation, its sector, incident history and regulatory drivers, before delivery. Submit an inquiry and we'll arrange a scoping call.