Skip to content
Macksofy Technologies
Targeted campaigns · Click-rate metrics · Repeat-offender coaching

Phishing Simulation & Awareness Training in India.

Realistic phishing-simulation programmes calibrated to Indian-context lures — UPI fraud pretexts, GST refund spoofs, payroll-portal redirects, vendor-invoice BEC. Quarterly cadence with role-segmented templates, click-rate benchmarks, and just-in-time coaching for repeat clickers.

India
hosted platform
Quarterly
campaign cadence
4 tiers
easy to spear
A.6.3
ISO evidence pack
In short

What is a phishing simulation?

A phishing simulation sends controlled, realistic phishing emails to your staff to measure who clicks, reports, or submits credentials — then trains them. Macksofy runs GoPhish-based campaigns with India-context lures and board-ready metrics, turning your people from the weakest link into an active detection layer.

The lure library

Your team will not click a DocuSign request.

Off-the-shelf awareness libraries are built for US and EU inboxes. An accounts team in Mumbai has never been chased by an Amazon Prime renewal — but a GSTN refund notice with a deadline gets opened every time. That gap is the whole reason a local programme outperforms.

Lure library · India context
Tap a card for the tell

Sender domains above are non-routable examples. Live campaigns use registered lookalikes agreed with you in scoping, and pretexts rotate each quarter so staff cannot pattern-match the programme instead of the threat.

What you get back

A human-risk number your board can read.

Click-rate is the headline, but the metric that matters as a programme matures is how fast someone reports. Both are tracked per role and per campaign, with the trend line the audit committee actually asks for.

  • Cut click-through rate from industry-baseline 15-22% to <5% within 4 quarters
  • Identify repeat-clicker populations needing targeted coaching
  • Build evidence pack for SEBI / RBI / ISO 27001 awareness-control requirements
  • Reduce successful BEC + ransomware initial-access incidents
  • Quantify human-risk metric for board-level dashboards
Per-campaign telemetry · what gets measured
Delivered & opened

Allow-listed with your mail-security vendor during scoping, so delivery is not the variable being tested. Opens on their own are not a failure signal.

Clicked

The headline number, segmented by role and risk tier — because an org-wide average hides the population that needs the coaching.

Credentials or MFA granted

The stage that would have been a real incident. Tracked separately from clicks, including OAuth consent grants and MFA-fatigue approvals.

Reported to the SOC

The positive-behaviour metric. Time-to-first-report matters more than click-rate once a programme matures.

Three anonymised programmes · click-rate before → after
at baseline at close
Listed NBFC4,200 staff, quarterly · 4 quarters
Whole organisation
19%
4.1%

SEBI awareness-control evidence passed first-pass

B2B SaaS (Series C)Pre-SOC 2 Type II baseline · 2 quarters
Engineering, internal-IT lures
23%
6%

SOC 2 CC1.4 + ISO A.6.3 evidence cleared

Pharma manufacturerPlant floor + corporate · 6 months
Plant engineers, vendor-portal lure
31%
8%

Local-language coaching for the plant population

Every one of these started above the 15–22% band we typically see at baseline

Three anonymised client programmes, not a benchmark. Your starting click-rate depends on sector, prior awareness work and mail-gateway posture — the trajectory is what we design for, not a number we guarantee.

Repeat clickers

Coaching, not a naming-and-shaming list.

Programmes that punish clicking teach people to hide it, which destroys your reporting rate — the one number you actually need in an incident. We escalate slowly, and you own the enforcement decision.

Click 1–2
60-second microlearning

The landing page becomes a teaching moment immediately, while the click is still fresh. No manager notification, no name on a list.

Click 3
1:1 coaching with their manager

A short, non-punitive session run jointly by Macksofy and the line manager, focused on the specific pretext that worked.

Click 4+
Escalation path, if your policy has one

We document the pattern and hand it over. Whether it escalates to HR is your policy decision, never ours.

Methodology

Five phases, then it repeats.

A single campaign is a measurement. A quarterly cadence with rotating pretexts is a programme — and only the second one moves the number.

Phase 1
Baseline + scoping
  • Email-environment review (M365 / Workspace, MTA, gateway, DMARC posture)
  • Workforce segmentation by role + risk tier (finance, HR, engineering, exec)
  • Lure-library calibration to client industry + India regulatory context
  • Allow-list set-up with mail-security vendor (Proofpoint, Mimecast, ATP)
Phase 2
Campaign design
  • Pretext selection — GST refund, UPI alert, payroll, vendor BEC, internal IT
  • Landing page design (credential capture, attachment, MFA-fatigue, OAuth grant)
  • Difficulty tiering — easy / medium / hard / spear
  • Schedule + send-window with global / regional timezone awareness
Phase 3
Execution + telemetry
  • Phased send-out from Macksofy's GoPhish-based platform
  • Real-time click, credential-entry, attachment-open, MFA-grant tracking
  • Reporter-button telemetry (positive behaviour signal)
  • Immediate just-in-time microlearning for clickers (60s screen)
Phase 4
Coaching + remediation
  • Role-segmented post-campaign report with click-rate benchmarking
  • Repeat-offender list + 1:1 coaching path (or HR escalation)
  • Manager-tier dashboards for line-of-business owners
  • Awareness-content refresh: short videos, posters, intranet articles
Phase 5
Quarterly cadence + reporting
  • Quarterly campaign with rotating pretexts (avoid pattern adaptation)
  • Trendline dashboards — click-rate, report-rate, time-to-report
  • ISO 27001 A.6.3 / SEBI / RBI evidence pack
  • Annual exec readout with industry-benchmark comparison
Evidence, not just training

The pack your auditor asks for in week one.

ISO 27001 A.6.3

Awareness, education and training evidence with dated campaign records and per-cohort completion.

SEBI CSCRF & RBI

Awareness-control evidence packs in the format Indian financial-sector reviewers accept without a rework cycle.

SOC 2 CC1.4

Demonstrated competence and awareness programme for the Type II observation window.

DPDP data residency

The platform runs on Macksofy infrastructure in India — no staff PII, mail content or click telemetry leaves Indian jurisdiction.

Programme snapshots

Where each one started and finished.

Listed NBFC

Scope · Quarterly phishing-sim across 4,200 staff, 4 quarters

Baseline · Q1 click-rate 19%; finance & ops teams 28%

Outcome · Q4 click-rate 4.1%; SEBI awareness-control evidence passed first-pass

Risk severity · High
LMHC
B2B SaaS (Series C)

Scope · Pre-SOC 2 Type II awareness baseline + 2 quarters

Baseline · Engineering grade tier showed 23% click on internal-IT lures

Outcome · Q2 click-rate to 6%; SOC 2 CC1.4 + ISO A.6.3 evidence cleared

Risk severity · High
LMHC
Pharma manufacturer

Scope · Plant-floor + corporate awareness for ransomware-readiness

Baseline · Plant-engineer population had 31% click on vendor-portal lure

Outcome · Targeted local-language coaching; click-rate to 8% in 6 months

Risk severity · High
LMHC
Platform

Run from our lab. Not a third-party processor.

Campaigns run on Macksofy’s own GoPhish-based platform hosted in India, so staff PII and click telemetry stay in jurisdiction. If you already license KnowBe4 or Cofense, we operate alongside it.

Mail-gateway allow-listing is set up in phase 1, and is reversible.
Tools we operate
GoPhish (Macksofy-hosted)Macksofy Phishing-Sim Lab (in-house)Microsoft Defender for O365 allow-listProofpoint / Mimecast integrationKnowBe4 (optional content library)Cofense PhishMe (reporter button)Custom Indian lure templates (CBDT / GSTN / EPFO / RBI / NSE / BSE)
Indicative pricing · INR

Transparent tiers. No surprises at quote time.

Indicative price ranges based on typical Indian engagements. Final fixed-price quote within 72 hours of the discovery call.

Free 30-day retest · CERT-In format reports
Tier 01

Build

₹4L–₹8L
Initial setup · single SOC tier
  • Tooling (Wazuh / ELK / Splunk) implementation
  • Baseline detection rules
  • Runbook authoring
Request a fixed-price quote
Tier 02

Operate

₹10L–₹20L
L1 + L2 with retainer
  • Everything in Build
  • 24×7 monitoring across business hours
  • Monthly threat-hunt + posture reviews
Request a fixed-price quote
Tier 03

Resilience

Starts at ₹24L
Full 24×7 SOC + threat intel
  • Everything in Operate
  • L3 threat hunters + IR retainer
  • Annual table-top + DR drill
Request a fixed-price quote

Note · Indicative pricing in INR. Setup + 12-month operate is the most-asked combination. Custom blends available.

What clients say · Trusted India + UAE

Rated 4.9 ★ from 612 client reviews.

CERT-In Empanelled
Govt of India · MeitY
EC-Council ATC
Authorized Training
ISO 27001 Certified
Info Security Mgmt
We've worked with three Big 4 firms before Macksofy. None found what their team did in our payments stack. The most actionable report we've received in a decade.
AK
Aisha Khan
Information Security Manager · Listed Fintech · BKC, Mumbai
The CHFI training Macksofy delivered for our cyber cell raised investigation quality measurably. Practical, India-context-aware, and respectful of our operational realities.
RK
R. Karandikar
Cyber Cell · Maharashtra Police · Mumbai
Came in with zero security background. 5 weeks later I was running Burp Suite and Metasploit confidently. Cleared CEH on the first attempt.
VI
Vivek Iyer
DevSecOps Lead · Healthcare SaaS · Hyderabad
FAQ

Questions before the first campaign.

Off-the-shelf libraries are 80% US/EU lures (DocuSign, Amazon Prime, HR portal). Macksofy templates are built for Indian context — GST refunds, EPFO notices, RBI circulars, NSE/BSE compliance notes — which is what your staff actually fall for. We can also operate alongside an existing KnowBe4 if you want both.
Delivery footprint

Where Macksofy delivers Phishing Sim.

On-site engagements across India's BFSI, fintech, government and SaaS metros plus the UAE. Senior consultants fly from Mumbai BKC for kickoff, key reviews and exit briefings; remote weeks run through the rest of the engagement.

References & standards

Macksofy delivers this work to the following standards and regulator requirements. Definitions and controls are sourced from the issuing bodies below.

Talk to us

Get a fixed-price proposal in 48 hours.

Tell us about your security need — pentest, audit, training or a wider engagement. A senior consultant will reply within a few business hours.

CERT-In Empanelled
Information Security Auditor · India
  • CERT-In Empanelled
  • EC-Council ATC · CompTIA Authorized
  • 20,000+ professionals trained
  • India + UAE engagements