The proposed experience connects relevant practice with learning support and clear reporting. Every capability below is part of the development roadmap.
How AI supports phishing, training and awareness
Planned capabilities
01
Tailored scenarios
Generate exercise drafts around an employee’s role, language and approved learning objectives.
02
Personalised debriefs
After an exercise closes, explain the warning signs and the employee’s decision using the approved scenario.
03
Targeted follow-up
Recommend a short lesson and the next exercise’s difficulty for the programme owner to review.
Example learning experienceAn employee misses a suspicious request to change payroll bank details. The debrief explains the verification step, then suggests a short refresher.
01
Adaptive learning
Use quiz results and completed lessons to recommend a relevant learning path.
02
AI learning coach
Explain difficult topics with examples and approved policy sources, and refer unresolved questions to the security team.
03
Practice and feedback
Draft role-based practice questions, explain answers and adapt approved lessons to the learner’s language.
Example learning experienceA customer-service employee practises account recovery, receives an explanation of a missed check and reviews the relevant policy.
01
Policy answers in context
Help employees apply approved security policies to everyday work questions, with source references.
02
Short refreshers
Suggest brief reminders and learning activities for topics that need reinforcement, within an approved programme.
03
Safe use of AI tools
Explain which information may be shared with AI tools using the organisation’s approved guidance.
Example learning experienceAn employee asks whether a customer ticket can be pasted into an AI assistant. The coach cites the policy and explains permitted options.
Planned capabilities
AI Scenario Studio
Draft phishing and social-engineering exercises around a role, language and learning objective. Approved policy material would guide context; reviewers would control every release.
Planned output
Editable scenarios with learning objectives, warning signs and review history.
Planned capabilities
Adaptive Learning Paths
Recommend short learning activities from quiz results and simulation outcomes. Explain each recommendation and let programme owners adjust it before assignment. After an exercise closes, provide a personalised explanation grounded in the approved scenario and observed response.
Planned output
A learning path with reasons for each suggested next step.
Planned capabilities
Policy AI Coach
Help employees navigate approved security policies through questions and practical examples. Answers would cite accessible source passages and escalate questions without sufficient evidence.
Planned output
Source-linked guidance, with a clear route to the security team.
Planned capabilities
AI Reporting Copilot
Turn campaign results into readable summaries for security leaders and programme owners. Link observations to actual metrics, comparison periods and supporting records.
Planned output
Reviewable summaries, evidence links and suggested follow-up actions.
Planned capabilities
Voice & Deepfake Exercises
Plan role-play exercises about voice impersonation and deepfake requests using licensed or authorised synthetic media. Focus on independent verification and escalation.
Planned output
Controlled voice scenarios, facilitator notes and verification exercises.
Planned capabilities
Multilingual Content Studio
Adapt approved scenarios and lessons for different languages, roles and local terminology. Keep versions linked and require language review before publication.
Planned output
Localised drafts, a shared glossary and an approval record.
Planned capabilities
AI Phishing Triage
Help the security team review employee-reported suspicious emails. Group related reports, highlight supporting indicators and suggest review priorities, with the final decision kept with an analyst.
Planned output
An explained review queue, linked evidence and draft feedback for the reporting employee.
Planned capabilities
AI Campaign Copilot
Turn programme goals, team needs and learning gaps into an editable campaign plan. Suggest audiences, timing and follow-up activities while checking exclusions, overlaps and training fatigue before approval.
Planned output
A reviewable campaign calendar with audience choices, reasons and approval history.
Planned capabilities
AI Simulation Insights
Interpret simulation outcomes alongside exercise difficulty and audience context. For email exercises, use the NIST Phish Scale as a reference for human-reviewed difficulty ratings and explain the limits of each comparison.
Planned output
Difficulty-aware comparisons, traceable metrics and suggestions for the next exercise.
Planned capabilities
Prepare people for what comes next.
Planned coverage for evolving phishing, identity fraud and AI risks, with reviewed scenarios, short practice and measurable learning outcomes.
01
Phishing across channels
AI-assisted drafts for email, QR-code, SMS, collaboration-message and callback scenarios. Begin with safe in-platform practice; live delivery through each channel needs separate validation.
Practise responding to unexpected MFA prompts, device-code requests, app permissions and help-desk impersonation. Teach verification of the requested action, even when a sign-in page looks familiar.
Rehearse account-recovery, employee-data and supplier-payment decisions with synthetic records. Approved voice role-play teaches verification through a known channel, beyond judging how convincing a voice sounds.
Practise protecting customer data, checking AI answers and recognising instructions hidden in documents. Learn to inspect the recipient, data and scope before approving an AI assistant's action.
Recommend short lessons from observed learning gaps, then revisit key decisions through spaced practice. Reviewed question banks, clear explanations and programme-controlled frequency keep the experience useful.
Track reporting, time to report and retained knowledge alongside exercise difficulty. Show comparable cohorts and data limitations, with supportive follow-up instead of unsupported predictions about individual employees.
Prioritise reviewed email and in-platform scenarios, everyday verification decisions, learning debriefs, source-based policy answers and a clear measurement baseline. Start personalisation with transparent rules.
Expand after validation
Add authorised voice exercises, validated delivery channels and analyst integrations after the learner journey works. Review new threat sources and model changes before they affect a live programme.
Safer decisions for every team.
Illustrative role-based scenarios for organisations across industries. Select a team to explore the proposed exercise.
Practice scenario
Customer operations
A person impersonating a customer pressures an agent to bypass the account-recovery process.
Decision to practise
Follow the approved verification process and escalate exceptions without disclosing customer information.
Practice scenario
HR & people teams
A message impersonating an employee asks HR to change payroll bank details without the usual verification.
Decision to practise
Verify the request through a known contact channel and follow the approved payroll-change process while protecting personal information.
Practice scenario
IT & security
A supposed supplier asks for emergency maintenance access outside the normal ticket process.
Decision to practise
Verify the contact and change request independently, then use the approved access workflow.
Practice scenario
Finance & procurement
A voice message attributed to a senior executive requests an urgent supplier-bank-detail change.
Decision to practise
Confirm through a known channel and follow the established payment-approval process.
Enterprise controls in the implementation brief.
These are proposed acceptance requirements. Hosting choices and integrations require agreement and technical validation for each deployment.
Human approval
Separate draft, review and release permissions; retain campaign and content approval history.
Data boundaries
Define tenant separation, permitted AI inputs, retention, deletion and provider data-use terms.
Identity & integration
Validate SSO, user provisioning, access roles and reporting integrations against your organisation’s systems.
Evidence & evaluation
Test answer grounding, unsafe outputs and language quality; retain traceable evaluation and audit records.
A practical delivery sequence.
Proposed priorities, with availability confirmed only after each capability passes validation. No release dates are committed here.
01 · Foundation
Scenario drafts, multilingual review, evidence-linked reports and simulation insights.
02 · Personalisation
A learner pilot with adaptive follow-up, a source-grounded policy coach and reviewed campaign planning.
03 · Advanced practice
Analyst-assisted email triage, authorised voice exercises and validated channels for a wider organisational rollout.
Discuss your requirements
Define the audience, policies, languages and integration requirements for an agreed pilot scope.