// Offensive Security · Human risk

Phishing Simulation

Realistic phishing campaigns against your own team, per-department reporting and just-in-time training for those who click. Measure your human risk — and watch it drop.

Talk to a specialist

By submitting, you agree to our Privacy Policy.

Recurring

Monthly or quarterly campaigns, new scenarios every round

Per team

Click, credential-submit and report rates — by department

Instant

Whoever clicks lands on a training page right away, not a lecture later

// How it works

Four steps, one repeating cycle

Not a one-off test. A continuous program that turns your team from weakest link into first line of defense.

Step 01

Scenarios

Emails, SMS and fake pages inspired by real attacks on your industry — invoices, HR, executives, vendors, MFA. Approved by you before sending.

EmailSMSCloned pagesQR codeMFA fatigue
Step 02

Controlled delivery

Staggered sending by groups, without tipping off the team or flooding support. Legitimate-looking domains and senders, allow-listed in your mail.

Allow-listGroupsScheduling
Step 03

Just-in-time training

Anyone who clicks or submits credentials lands on a short page explaining what happened and how to spot it next time. Education without embarrassment.

Teaching pageMicro-lessonNo blame
Step 04

Reporting & progress

Rates by team and scenario, comparison with the previous round and recommendations. Evidence for audits and the board.

DashboardTrendISO 27001LGPD
// What's included

Full program, zero effort from your team

UPX designs, runs and reports. You approve scenarios and receive results.

01Tailored scenarios

Templates aligned with your industry, brand and real vendors — what an attacker would do.

02Segmentation

Campaigns by department, role or business unit. Executives and finance get their own scenarios.

03Metrics that matter

Click, credential submitted, attachment opened and — the best one — how many reported it as suspicious.

04Contextual training

Teaching page at the moment of the mistake and micro-lessons for repeat clickers.

05Report button

Outlook and Gmail integration so the team reports phishing in one click — real or simulated.

06Executive report

Monthly or quarterly summary with trend, per-team comparison and audit evidence.

// Who it's for

Fits three situations

From those who never measured to those who must prove it to auditors.

Never tested

Initial baseline

Wants to know the real risk before an attacker finds out. First round as a baseline.

  • Unannounced baseline round
  • Click rate per team
  • Generic and targeted scenarios
  • Recurring program plan
Compliance requirement

Continuous evidence

ISO 27001, LGPD, PCI-DSS or a customer asking for awareness evidence. Reports ready.

  • Documented quarterly campaigns
  • ISO 27001 / LGPD / PCI reports
  • Per-person training record
  • Trend for the board
Already had an incident

Intensive program

Suffered phishing and wants to make sure it doesn't repeat. Intensive program focused on affected teams.

  • Focus on affected teams
  • Scenarios based on the real attack
  • Monthly rounds until stable
  • Report button deployed
// Why simulate

Annual training vs. continuous simulation

Phishing is the most common initial vector in incidents. A yearly talk doesn't change behavior — repetition does.

Annual training

Ticks the box, doesn't change the click

One video a year, forgotten in a week
No measurement of who would actually fall for it
High-risk teams (finance, executives) treated like everyone else
No evidence of progress for audits
Problem discovered only in the real incident
UPX Simulation

Measure, train, repeat

Recurring rounds with fresh scenarios
Click and report rates measured per team
Dedicated scenarios for those with the most access
Trend reporting — evidence of improvement
Team learns from the simulated mistake, not the real one
// Deliverables

What you get

Baseline
Baseline

Initial round with base rate per team

Campaigns
Campaigns

Monthly or quarterly, scenarios approved by you

Training
Training

Instant teaching page + micro-lessons

Report
Report

Executive, with trend and audit evidence