Phishing Simulation & Awareness Training in India.
Realistic phishing-simulation programmes calibrated to Indian-context lures — UPI fraud pretexts, GST refund spoofs, payroll-portal redirects, vendor-invoice BEC. Quarterly cadence with role-segmented templates, click-rate benchmarks, and just-in-time coaching for repeat clickers.
What is a phishing simulation?
A phishing simulation sends controlled, realistic phishing emails to your staff to measure who clicks, reports, or submits credentials — then trains them. Macksofy runs GoPhish-based campaigns with India-context lures and board-ready metrics, turning your people from the weakest link into an active detection layer.
Your team will not click a DocuSign request.
Off-the-shelf awareness libraries are built for US and EU inboxes. An accounts team in Mumbai has never been chased by an Amazon Prime renewal — but a GSTN refund notice with a deadline gets opened every time. That gap is the whole reason a local programme outperforms.
Sender domains above are non-routable examples. Live campaigns use registered lookalikes agreed with you in scoping, and pretexts rotate each quarter so staff cannot pattern-match the programme instead of the threat.
A human-risk number your board can read.
Click-rate is the headline, but the metric that matters as a programme matures is how fast someone reports. Both are tracked per role and per campaign, with the trend line the audit committee actually asks for.
- Cut click-through rate from industry-baseline 15-22% to <5% within 4 quarters
- Identify repeat-clicker populations needing targeted coaching
- Build evidence pack for SEBI / RBI / ISO 27001 awareness-control requirements
- Reduce successful BEC + ransomware initial-access incidents
- Quantify human-risk metric for board-level dashboards
Allow-listed with your mail-security vendor during scoping, so delivery is not the variable being tested. Opens on their own are not a failure signal.
The headline number, segmented by role and risk tier — because an org-wide average hides the population that needs the coaching.
The stage that would have been a real incident. Tracked separately from clicks, including OAuth consent grants and MFA-fatigue approvals.
The positive-behaviour metric. Time-to-first-report matters more than click-rate once a programme matures.
SEBI awareness-control evidence passed first-pass
SOC 2 CC1.4 + ISO A.6.3 evidence cleared
Local-language coaching for the plant population
Three anonymised client programmes, not a benchmark. Your starting click-rate depends on sector, prior awareness work and mail-gateway posture — the trajectory is what we design for, not a number we guarantee.
Coaching, not a naming-and-shaming list.
Programmes that punish clicking teach people to hide it, which destroys your reporting rate — the one number you actually need in an incident. We escalate slowly, and you own the enforcement decision.
The landing page becomes a teaching moment immediately, while the click is still fresh. No manager notification, no name on a list.
A short, non-punitive session run jointly by Macksofy and the line manager, focused on the specific pretext that worked.
We document the pattern and hand it over. Whether it escalates to HR is your policy decision, never ours.
Five phases, then it repeats.
A single campaign is a measurement. A quarterly cadence with rotating pretexts is a programme — and only the second one moves the number.
- ▸Email-environment review (M365 / Workspace, MTA, gateway, DMARC posture)
- ▸Workforce segmentation by role + risk tier (finance, HR, engineering, exec)
- ▸Lure-library calibration to client industry + India regulatory context
- ▸Allow-list set-up with mail-security vendor (Proofpoint, Mimecast, ATP)
- ▸Pretext selection — GST refund, UPI alert, payroll, vendor BEC, internal IT
- ▸Landing page design (credential capture, attachment, MFA-fatigue, OAuth grant)
- ▸Difficulty tiering — easy / medium / hard / spear
- ▸Schedule + send-window with global / regional timezone awareness
- ▸Phased send-out from Macksofy's GoPhish-based platform
- ▸Real-time click, credential-entry, attachment-open, MFA-grant tracking
- ▸Reporter-button telemetry (positive behaviour signal)
- ▸Immediate just-in-time microlearning for clickers (60s screen)
- ▸Role-segmented post-campaign report with click-rate benchmarking
- ▸Repeat-offender list + 1:1 coaching path (or HR escalation)
- ▸Manager-tier dashboards for line-of-business owners
- ▸Awareness-content refresh: short videos, posters, intranet articles
- ▸Quarterly campaign with rotating pretexts (avoid pattern adaptation)
- ▸Trendline dashboards — click-rate, report-rate, time-to-report
- ▸ISO 27001 A.6.3 / SEBI / RBI evidence pack
- ▸Annual exec readout with industry-benchmark comparison
The pack your auditor asks for in week one.
Awareness, education and training evidence with dated campaign records and per-cohort completion.
Awareness-control evidence packs in the format Indian financial-sector reviewers accept without a rework cycle.
Demonstrated competence and awareness programme for the Type II observation window.
The platform runs on Macksofy infrastructure in India — no staff PII, mail content or click telemetry leaves Indian jurisdiction.
Where each one started and finished.
Scope · Quarterly phishing-sim across 4,200 staff, 4 quarters
Baseline · Q1 click-rate 19%; finance & ops teams 28%
Outcome · Q4 click-rate 4.1%; SEBI awareness-control evidence passed first-pass
Scope · Pre-SOC 2 Type II awareness baseline + 2 quarters
Baseline · Engineering grade tier showed 23% click on internal-IT lures
Outcome · Q2 click-rate to 6%; SOC 2 CC1.4 + ISO A.6.3 evidence cleared
Scope · Plant-floor + corporate awareness for ransomware-readiness
Baseline · Plant-engineer population had 31% click on vendor-portal lure
Outcome · Targeted local-language coaching; click-rate to 8% in 6 months
Run from our lab. Not a third-party processor.
Campaigns run on Macksofy’s own GoPhish-based platform hosted in India, so staff PII and click telemetry stay in jurisdiction. If you already license KnowBe4 or Cofense, we operate alongside it.
Transparent tiers. No surprises at quote time.
Indicative price ranges based on typical Indian engagements. Final fixed-price quote within 72 hours of the discovery call.
Build
- Tooling (Wazuh / ELK / Splunk) implementation
- Baseline detection rules
- Runbook authoring
Operate
- Everything in Build
- 24×7 monitoring across business hours
- Monthly threat-hunt + posture reviews
Resilience
- Everything in Operate
- L3 threat hunters + IR retainer
- Annual table-top + DR drill
Note · Indicative pricing in INR. Setup + 12-month operate is the most-asked combination. Custom blends available.
Rated 4.9 ★ from 612 client reviews.
“We've worked with three Big 4 firms before Macksofy. None found what their team did in our payments stack. The most actionable report we've received in a decade.”
“The CHFI training Macksofy delivered for our cyber cell raised investigation quality measurably. Practical, India-context-aware, and respectful of our operational realities.”
“Came in with zero security background. 5 weeks later I was running Burp Suite and Metasploit confidently. Cleared CEH on the first attempt.”
Questions before the first campaign.
Where Macksofy delivers Phishing Sim.
On-site engagements across India's BFSI, fintech, government and SaaS metros plus the UAE. Senior consultants fly from Mumbai BKC for kickoff, key reviews and exit briefings; remote weeks run through the rest of the engagement.
Macksofy delivers this work to the following standards and regulator requirements. Definitions and controls are sourced from the issuing bodies below.
Get a fixed-price proposal in 48 hours.
Tell us about your security need — pentest, audit, training or a wider engagement. A senior consultant will reply within a few business hours.
- CERT-In Empanelled
- EC-Council ATC · CompTIA Authorized
- 20,000+ professionals trained
- India + UAE engagements
