How to choose a phishing simulation platform: 10 questions

By OpsinelPublished 7 min read

Short answer: When choosing a phishing simulation platform, check five things: whether the emails are written in your employees’ language, what an employee sees after clicking, whether the emails will reach inboxes, what a manager sees in the reports and what the full scope costs per year. Before buying, send a simulation to yourself and see what an employee would receive.

There are many phishing simulation platforms, and their websites sound alike: realistic emails, automated training, clear reports. The differences only show once you start using one. Below are ten questions worth asking a vendor before signing a contract. They apply whichever platform you choose in the end.

First decide what you need

Before comparing vendors, answer three questions. How many employees will take part? Who in the company will run the campaigns, and how much time will they have? Who will see the results: management, IT or department heads? The answers decide whether you need a self-service tool or a service where the vendor sends the campaigns.

10 questions for the vendor

1. Which languages are the email templates written in?

Employees spot an email with machine-translation errors straight away, so such a test tells you nothing. Ask to see several templates in your employees’ language and judge whether they resemble the emails your people actually receive: from couriers, banks, public authorities or work tools.

2. Can the email be adapted to your company?

The company name, domain, internal systems. An email that looks as if it came from your own IT department tests far more than a generic “Dear customer”. Ask whether you can upload your own HTML template.

3. What does an employee see after clicking?

This is the most important question. If an employee who clicks sees only an error page, or a week later gets a link to an hour-long video, the test has taught them nothing. What works best is a lesson straight after the click about that same email and the signs the person missed. Ask to see it yourself.

4. How will the emails reach inboxes?

Microsoft 365 and Google Workspace often hold back simulation emails or check their links in advance. Then the emails do not reach employees, or the results are skewed. Ask whether the vendor gives step-by-step instructions for allowing simulations in your mail system, and whether emails can be sent through your own mail server (SMTP).

5. Are automatic clicks separated from people’s actions?

Email security systems open links in emails themselves to check them. If the platform does not separate these clicks, the report will contain clicks that no employee made. Ask how this is handled.

6. What is stored when an employee enters a password?

The right answer: nothing except the fact that details were entered. A simulation does not need a real password, and storing one creates a new risk. At the same time, ask where employee data is kept and whether the vendor signs a data processing agreement.

7. What will a manager see?

Ask for a sample report. Does it show each employee’s result, a comparison of departments, the change over several months, finished lessons? Can you download it as a PDF or receive it by email every month? If the report has to be put together by hand each time, soon nobody will put it together.

8. How much time will administration take?

Find out how employees are added (by CSV file or by hand), whether campaigns can be scheduled several months ahead and whether training is assigned automatically. If the company has no dedicated security specialist, the platform has to work without daily attention.

9. What will it cost per year?

The monthly price of one seat does not tell the whole story. Ask about the minimum number of employees, platform fees, courses sold separately, annual commitments and the payment method: card or invoice. Then work out the full annual amount for your number of employees.

10. Can we try it before buying?

The best check is to send a simulation to yourself: you will see the email, the page after the click, the lesson and the report. If the platform can only be seen in a sales presentation, ask for trial access for your team.

Signs that a platform will not suit you

  • Templates only in English, or with obvious translation errors.
  • An employee who clicks learns nothing, or the training arrives only days later.
  • The platform stores entered passwords.
  • There are no prices on the website, and the contract is for a full year straight away, with no way to try it.
  • To make results understandable for management, you have to export them and tidy them up in a spreadsheet.

Free tools: when they are enough

With open-source phishing tools you can send a simulation for free. But you will have to build and maintain the server, email templates, training page, lessons and reports yourself. That suits a company with a security specialist. Without one, the money saved usually turns into working hours.

How Opsinel answers these questions

Opsinel wrote this article, so here are our answers. Compare them with other vendors’.

Languages
Templates in Lithuanian and English; Latvian, Estonian and Polish on request. You can upload your own HTML template.
After the click
The employee learns straight away that it was a simulation and gets a lesson of about 15 minutes about that same email.
Email delivery
The dashboard has instructions for Microsoft 365 and Google Workspace. Emails can be sent through Opsinel or through your SMTP server.
Automatic clicks
Clicks by known email security systems are separated from employees’ actions.
Passwords
Entered details are never stored; only the action is recorded.
Reports
Each employee’s result, departments, the trend, finished lessons, PDF and scheduled email delivery.
Price
€30 per month for 10 employees, each additional seat from €0.55, prices exclude VAT. Paid by bank transfer against an invoice, with 7 days to change your mind.
Trying it
A free account with sample data. You can send a simulation to yourself and see what an employee would receive.

More: how Opsinel works, how a phishing simulation works and the price calculator.

Try it yourself

Could you spot a phishing email?

10 realistic emails and an explanation after each answer. About 5 minutes, no sign-up.

Take the phishing quiz

Can scammers send email in your name?

A free SPF, DKIM and DMARC check of your domain. The domains you enter are not stored.

Frequently asked questions

How much does a phishing simulation platform cost?

Usually you pay per employee per month, sometimes with a platform fee or a minimum number of employees. Compare the annual amount for your team, including courses sold separately. Opsinel costs €30 per month for 10 employees, and you can work out the price for your team in the price calculator.

Do you need IT skills to use the platform?

Not to launch a campaign. The most technical part is email delivery: simulations need to be allowed in the Microsoft 365 or Google Workspace settings. This is done once, usually by the IT administrator.

Self-service tool or managed service?

If someone in the company can regularly spend time on campaigns, a self-service tool is enough. If not, choose a service where the vendor plans and sends the campaigns. Opsinel offers both: Self-Service and Fully Managed.

How long does it take to get started?

Creating an account takes a few minutes. Most time goes into adding the employee list and setting up email delivery. With Opsinel the first campaign can be launched in about 30 minutes.

Sources and further reading

Public guidance from security agencies and standards bodies.

From theory to practice

A phishing simulation lets your employees practise: they get a realistic email and, if they click, a short lesson straight away. Create an account and see sample data straight away.