How it works
A phishing simulation is a controlled attack your company sends to itself to measure who falls, to which kind of deception and how often. Fensivo's difference is not sending everyone the same email: the system picks for each person the simulation most likely to make them fall, crossing their past behavior, their role and department, the platforms the company really uses and the credentials leaked for that person (the signal provided by dark web monitoring). It sends one to three simulations per employee per month, at the right moment. For SMBs, with no team dedicated to building campaigns, that automatic matching is what makes the program workable.
More than 90 percent of successful cyberattacks start with a phishing email (CISA): training that reflex is training the door almost everything comes through.
Random or matched: the same number of sends, a different signal
Switch the mode and see how many simulations out of ten actually reveal risk.
75 to 90% effectiveness
Measured by click rate and credential submission. A figure from Fensivo's design, not a market statistic.
For each person, the simulation most likely to make them fall. More signal with the same number of sends.
What the system crosses to choose
- Past behavior
- Role and department
- Platforms the company really uses
- Credentials leaked for that person
The catalog
~400
curated templates: about 200 in Spanish and 200 in English
- 9 categories
- by the instinct they exploit: executive authority, financial pretext, urgency and more.
- Personalization
- programmatic, by field substitution on reviewed templates. Not AI-generated emails: consistency and controlled realism.
- Pace
- one to three simulations per person per month, at the right moment.
If someone resists one kind of pretext, the system tries another until it finds their weak spot. Why realism matters is explained in personalized phishing simulations that reduce risk.
What it measures, and what is not enough
Each simulation records three things. Only one is the early signal.
Click rate
Who opens the link. On its own it misleads: it drops when simulations become easy or predictable.
Credential submission
Who goes as far as typing their password. That is the fall that really costs.
Report rate
Who raises the flag in time. It is the early signal of a culture that works.
What to look at and in what order is in report rate, click rate and retest, and how often to test by role, in how often to send simulations.
What happens next: the retest
A simulation without this step measures a one-off. With a retest it measures resilience over time.
- Day 0The person fallsThey click or submit credentials in a simulation.
- Minutes laterMicro-learningA three-question chat about that deception: the signals it had and how to avoid it. Two out of three passes.
- Three weeks laterRetestA simulation of the same type and difficulty, with a different template and context.
- Until several passesRisk floorA failure sets a risk floor that only lifts after several consecutive simulations without falling.
The retest validates that the person changed their behavior, not that they remembered an email. Peer-reviewed evidence (IEEE Symposium on Security and Privacy, 2025 and 2022) shows that completing training does not by itself predict fewer real failures; what proves the change is testing the behavior again.
It is the same cycle that keeps a human risk management platform from being just a trap-email generator: the simulation feeds the micro-learning and the retest validates it. The category guide is at human risk management and the full platform, at product.
See a real simulation from your industry
A 30-minute demo with simulated data from your sector. Live in 1 day via OAuth; first executive report with a risk score per person in 48 hours. From 25 employees.
Per-employee pricing on the calculator. Honest comparisons with other platforms at Fensivo vs. KnowBe4.