Skip to content
ENTERPRISE SECURITY AWARENESS · AI ROADMAP

AI for phishing, training and everyday awareness.

Our planned AI capabilities tailor phishing exercises, explain simulation outcomes, recommend lessons and help employees apply approved security policies at work.

Planned capabilities

These capabilities are planned and are not yet available. Scope, integrations and availability will be confirmed after implementation and validation.

Proposed workflow
  1. Draft with AI
  2. Review & approve
  3. Practice & measure
AI platform

Nine capabilities. One controlled learning cycle.

The proposed experience connects relevant practice with learning support and clear reporting. Every capability below is part of the development roadmap.

How AI supports phishing, training and awareness

Planned capabilities
  1. Tailored scenarios

    Generate exercise drafts around an employee’s role, language and approved learning objectives.

  2. Personalised debriefs

    After an exercise closes, explain the warning signs and the employee’s decision using the approved scenario.

  3. Targeted follow-up

    Recommend a short lesson and the next exercise’s difficulty for the programme owner to review.

Example learning experienceAn employee misses a suspicious request to change payroll bank details. The debrief explains the verification step, then suggests a short refresher.

Planned capabilities

AI Scenario Studio

Draft phishing and social-engineering exercises around a role, language and learning objective. Approved policy material would guide context; reviewers would control every release.

Planned output

Editable scenarios with learning objectives, warning signs and review history.

Planned capabilities

Adaptive Learning Paths

Recommend short learning activities from quiz results and simulation outcomes. Explain each recommendation and let programme owners adjust it before assignment. After an exercise closes, provide a personalised explanation grounded in the approved scenario and observed response.

Planned output

A learning path with reasons for each suggested next step.

Planned capabilities

Policy AI Coach

Help employees navigate approved security policies through questions and practical examples. Answers would cite accessible source passages and escalate questions without sufficient evidence.

Planned output

Source-linked guidance, with a clear route to the security team.

Planned capabilities

AI Reporting Copilot

Turn campaign results into readable summaries for security leaders and programme owners. Link observations to actual metrics, comparison periods and supporting records.

Planned output

Reviewable summaries, evidence links and suggested follow-up actions.

Planned capabilities

Voice & Deepfake Exercises

Plan role-play exercises about voice impersonation and deepfake requests using licensed or authorised synthetic media. Focus on independent verification and escalation.

Planned output

Controlled voice scenarios, facilitator notes and verification exercises.

Planned capabilities

Multilingual Content Studio

Adapt approved scenarios and lessons for different languages, roles and local terminology. Keep versions linked and require language review before publication.

Planned output

Localised drafts, a shared glossary and an approval record.

Planned capabilities

AI Phishing Triage

Help the security team review employee-reported suspicious emails. Group related reports, highlight supporting indicators and suggest review priorities, with the final decision kept with an analyst.

Planned output

An explained review queue, linked evidence and draft feedback for the reporting employee.

Planned capabilities

AI Campaign Copilot

Turn programme goals, team needs and learning gaps into an editable campaign plan. Suggest audiences, timing and follow-up activities while checking exclusions, overlaps and training fatigue before approval.

Planned output

A reviewable campaign calendar with audience choices, reasons and approval history.

Planned capabilities

AI Simulation Insights

Interpret simulation outcomes alongside exercise difficulty and audience context. For email exercises, use the NIST Phish Scale as a reference for human-reviewed difficulty ratings and explain the limits of each comparison.

Planned output

Difficulty-aware comparisons, traceable metrics and suggestions for the next exercise.

Planned capabilities

Prepare people for what comes next.

Planned coverage for evolving phishing, identity fraud and AI risks, with reviewed scenarios, short practice and measurable learning outcomes.

  1. Phishing across channels

    AI-assisted drafts for email, QR-code, SMS, collaboration-message and callback scenarios. Begin with safe in-platform practice; live delivery through each channel needs separate validation.

    Related capability: Phishing across channels
  2. Deceptive sign-ins and access requests

    Practise responding to unexpected MFA prompts, device-code requests, app permissions and help-desk impersonation. Teach verification of the requested action, even when a sign-in page looks familiar.

    Related capability: Deceptive sign-ins and access requests
  3. Business fraud and voice impersonation

    Rehearse account-recovery, employee-data and supplier-payment decisions with synthetic records. Approved voice role-play teaches verification through a known channel, beyond judging how convincing a voice sounds.

    Related capability: Business fraud and voice impersonation
  4. Safe AI and assistant use

    Practise protecting customer data, checking AI answers and recognising instructions hidden in documents. Learn to inspect the recipient, data and scope before approving an AI assistant's action.

    Related capability: Safe AI and assistant use
  5. Adaptive practice and reinforcement

    Recommend short lessons from observed learning gaps, then revisit key decisions through spaced practice. Reviewed question banks, clear explanations and programme-controlled frequency keep the experience useful.

    Related capability: Adaptive practice and reinforcement
  6. Evidence of safer decisions

    Track reporting, time to report and retained knowledge alongside exercise difficulty. Show comparable cohorts and data limitations, with supportive follow-up instead of unsupported predictions about individual employees.

    Related capability: Evidence of safer decisions

First pilot programme

Prioritise reviewed email and in-platform scenarios, everyday verification decisions, learning debriefs, source-based policy answers and a clear measurement baseline. Start personalisation with transparent rules.

Expand after validation

Add authorised voice exercises, validated delivery channels and analyst integrations after the learner journey works. Review new threat sources and model changes before they affect a live programme.

Safer decisions for every team.

Illustrative role-based scenarios for organisations across industries. Select a team to explore the proposed exercise.

Practice scenario

Customer operations

A person impersonating a customer pressures an agent to bypass the account-recovery process.

Decision to practise

Follow the approved verification process and escalate exceptions without disclosing customer information.

Enterprise controls in the implementation brief.

These are proposed acceptance requirements. Hosting choices and integrations require agreement and technical validation for each deployment.

Human approval

Separate draft, review and release permissions; retain campaign and content approval history.

Data boundaries

Define tenant separation, permitted AI inputs, retention, deletion and provider data-use terms.

Identity & integration

Validate SSO, user provisioning, access roles and reporting integrations against your organisation’s systems.

Evidence & evaluation

Test answer grounding, unsafe outputs and language quality; retain traceable evaluation and audit records.

A practical delivery sequence.

Proposed priorities, with availability confirmed only after each capability passes validation. No release dates are committed here.

  1. 01 · Foundation

    Scenario drafts, multilingual review, evidence-linked reports and simulation insights.

  2. 02 · Personalisation

    A learner pilot with adaptive follow-up, a source-grounded policy coach and reviewed campaign planning.

  3. 03 · Advanced practice

    Analyst-assisted email triage, authorised voice exercises and validated channels for a wider organisational rollout.

Discuss your requirements

Define the audience, policies, languages and integration requirements for an agreed pilot scope.

Read the AI security awareness guide
Discuss your requirements
WhatsApp