Phishing Exposure Service

Find Out Who'd Actually Click

AI has made spear phishing faster, more convincing, and harder to spot than ever. Our exposure service tells you, with evidence, not guesswork, how your organisation would really hold up.

Overview

Beyond Generic Phishing Tests

Off-the-shelf phishing tests use the same handful of templates everyone's seen before. We go further: using Open-Source Intelligence (OSINT) and real social engineering techniques to build attack scenarios tailored to your organisation, and checking staff email addresses against known data breaches to understand what's already out there about each person.

1
Establish
Each person's current exposure: what's already been leaked or compromised.
2
Identify
Who's genuinely susceptible to a phishing attack, and why.
3
Enhance
Security awareness, backed by evidence specific to your team.
goDeep Phishing brochure cover Service Brochure

Get the Full Brochure

Download the goDeep Phishing brochure for the full breakdown of the exposure service: simulation levels, process and timeline, and the reporting you walk away with.

Download the Brochure (PDF) →

Exposure Analysis & Simulation Levels

Three Levels of Realism

Start with an exposure check on every address: has it turned up in a known breach, and what's the risk? Then run three escalating tiers of simulation to build a full staff risk profile.

Level 1: Mass Scale

Broad, unresearched phishing with familiar themes: delivery notifications, password resets, bank alerts, clickbait. Establishes a baseline for every user's vulnerability.

Level 2: Targeted

Phishing emails built around your sector: mimicking the tools, suppliers, and business operations typical of organisations like yours, without deep research into your specific people or processes.

Level 3: Spear Phishing

Ultra-targeted emails built from deep research into your operational structure, internal communication patterns, and even your own email signatures and banners.

Reporting, Insights & Staff Presentation

What You Walk Away With

Engagement Metrics

Click rates, login attempts, and detailed user behaviour analysis across every simulation tier.

Risk Assessment

Identification of your highest-risk users and the attack vectors most likely to succeed against them.

Breach Comparison

Insight into how prior data exposures actually impact susceptibility to a live attack.

Recommendations

Actionable next steps, awareness training and security improvements, to close the gaps we find.

Hands-Free Scheduling

Set the cadence once and we run it: simulations launch automatically on schedule. No admin overhead, just read the results as they come in.

Managed Spear Phishing

An ongoing managed service that uses OSINT to target specific individuals with tailored spear phishing or text-based (smishing) attempts.

Inside the Reporting Dashboard

What a Risk Profile Actually Looks Like

Every engagement runs on the same live reporting inside the goDeep platform: click activity tracked across rolling time windows, department-level breakdowns, and a per-person risk score that blends phishing behaviour with real breach exposure. Here's an illustrative look at what your team would see.

Illustrative example data shown below, not a live client account.
18.4
Phish Risk Score
22.0
Breach Risk Score
19.8
Combined Score: High

Combined Score = (Phish Score × 60%) + (Breach Score × 40%)  =  (18.4 × 0.60) + (22.0 × 0.40)  =  19.8: one example individual, not an organisation-wide average.

Staff Risk Distribution
Click Rate Trend Across Time Windows
Click Rate by Department
Phishes Sent vs Clicks vs Credentials Given

See Where Your Team Actually Stands

A 30-minute conversation is all it takes to scope out a phishing exposure assessment for your organisation.