Awareness Campaigns is a timed, branded scam-spotting test built from the techniques criminals actually use — lookalike domains, fake CAPTCHAs, payment redirects, deepfake calls — across email, text, phone, QR and six more channels. Every person gets their own link and their own questions. You get a score, not a guess.
KnowBe4-style simulation platforms send your staff fake phishing emails and count who clicks. It sounds rigorous. Look closer at what the numbers actually mean.
Someone who never saw the simulation — buried inbox, out of office, filtered to junk — is scored as if they resisted it. Most of your “improvement” is people not opening an email. You learn nothing about the majority of your company.
Preview panes, phones and security scanners register “opens” on their own. And a human opening an email hasn’t fallen for anything — reading is what you want people to do before they judge. Yet open-rates end up in the board report as risk.
Simulations are email templates from a library — no rn↔m lookalike domains, no fake CAPTCHA that hijacks your clipboard, no payment-redirect cons, no deepfake voice calls. Scams arrive by text, phone, QR and chat; a simulation only ever knocks on the inbox.
Deceptive tests have triggered union grievances and HR escalations, and research finds they erode trust in leadership — people stop reporting real threats because reporting got a colleague shamed. Security that your people resent is security that fails quietly.
No traps, no fake emails from “HR”. People know they’re being tested — then they meet the real techniques, under time pressure, and every answer is scored. Try one:
Which of these is the genuine MailNest sign-in page?
https://login.rnailnest.com https://login.mailnest.com https://login.mai1nest.comThe tell: the first swaps the m for an r and an n pushed together — nearly identical in an address-bar font. The third uses the digit 1 for the letter l. Most people miss at least one at reading speed. That miss, in your results, is a gap you can close — before a criminal finds it first.
From first click to results, without touching your mail servers or installing anything.
Choose from 250+ questions built on real scam techniques — including packs for NZ, Australia, the UK, US and Canada — or add your own. Your name, your logo, your colours. Recipients never see ours.
Pay once for the number of people you’re testing and get a unique link for each. You send them from your own address, so the invitation carries your name and your trust — not a stranger’s domain. Each person gets a different subset of questions, so shared answers are worthless.
Score distributions, the hardest questions, which channels catch your people out, who’s over the time budget — and an export your auditor or insurer will accept as training evidence. Run it anonymously and you get the numbers with no names stored at all.
What a simulation platform tells you, against what an Awareness Campaign tells you.
| Traditional phishing simulation | SafeToOpen Awareness Campaigns | |
|---|---|---|
| What’s measured | ✗Who clicked one template email | ✓Scored judgment across real scam techniques |
| Non-participation | ✗Counted as a pass — silence looks like skill | ✓Visible as “not started” — you know who you know nothing about |
| Channels tested | ✗Email only | ✓Email, SMS, voice, QR, web, chat, social, app, marketplace, post |
| Realism | ✗Template library | ✓Lookalike domains, fake CAPTCHAs, payment redirects, deepfakes, regional scams |
| Staff experience | ✗Deception — documented trust and HR fallout | ✓An open test people can even enjoy — feedback after every answer |
| Who you can test | ✗Employees on your directory | ✓Staff and customers — white-label, no directory needed |
| Privacy | ✗Per-employee tracking, always | ✓Anonymous mode: results without names ever stored |
| Pricing | ✗Per-user annual subscription | ✓Pay per campaign. Run one, or four a year — your call |
Priced per person tested, with volume tiers. A 100-person company runs its annual scam check for less than a tenth of a typical training subscription.
Part of Business Plus. Testing a customer base of 10,000+? Talk to us about population pricing.
No — deliberately. Nobody is tricked and nothing is disguised. People take an open, timed test against real scam techniques, get feedback after every answer, and are scored on judgment. You get better data, and your staff don’t learn to resent security.
Never. You get one personal link per person and send them yourself, from your own address — so the invitation arrives with your name on it, and your sending reputation stays yours. An unexpected email from an unknown security vendor asking people to click a link would be exactly the thing we’re testing for.
Yes. In anonymous mode no address is ever written to our database — not hidden, not hashed, never stored. You see the scores and the gaps; nobody sees names. It’s the mode works councils and privacy teams approve.
Yes — it’s built for it. The test is fully white-label, needs no directory or login, and includes country-specific scam content. If your organisation carries the cost when customers are scammed, measuring their scam literacy is the first step to reducing it.
Completion and score records export per campaign, which is the evidence ISO 27001, SOC 2 and PCI DSS awareness controls — and cyber-insurance questionnaires — ask for. A scored assessment is stronger evidence than a completion certificate, because it shows what people can actually do.
Build it in an afternoon, send it from your own address, and know by Friday where the gaps are.