PhishDrill: turning a company's weakest security link into its early warning system
A cybersecurity consultancy saw the same pattern at client after client: expensive defences bypassed by one employee clicking one link. We built PhishDrill: realistic phishing simulations tailored by department, bite-sized training at the moment of a mistake, a one-click report button, and risk dashboards — a SaaS platform the consultancy now offers to its clients.

One click past every defence
PhishDrill's founder ran incident response for clients. Again and again, attacks began with a convincing email: a fake invoice, a password reset, a message from the 'CEO'. Annual awareness videos were clicked through and forgotten. He wanted training that happened in the moment and measured whether behaviour changed.
“People don't learn from a video once a year. They learn from almost making a mistake.”
Teaching without shaming
We interviewed security teams and employees at client companies. Employees disliked 'gotcha' programmes that felt punitive. Security teams needed measurable improvement. The design had to make simulations realistic, feedback kind and immediate, and reporting suspicious emails the behaviour that got rewarded.
- Realistic simulations tailored by role
- Kind, immediate learning moments
- Reward reporting, not just avoid clicking
- Measure behaviour change over time

Simulate, teach, report, measure
PhishDrill sends simulations tailored to departments — finance gets invoice lures, HR gets CV attachments — drafted with AI assistance and reviewed by the security team. If someone clicks, they see a short, friendly lesson about the exact signs they missed. A report button in their email client lets them flag suspicious messages, and reporting simulated phishing earns recognition.
Dashboards show click and report rates over time by department, so security teams can see risk falling.
The team
Email deliverability and multi-tenancy were the core technical work.
Client interviews and launch.
Learning moments and dashboards.
Campaigns, portal, add-ins and multi-tenancy.
Email infrastructure and deliverability.
Template drafting and personalisation.
6 people in total, working as one team.
Decisions we made
Agreed with the founder and consultancy partners.
Punish or teach?
- Report clicks to managers
- Immediate, private learning moments
Our call: Immediate, private learning moments. Shaming reduced engagement; kind, private feedback changed behaviour.
Generic or tailored simulations?
- Same template for everyone
- Tailored by department, reviewed by security teams
Our call: Tailored by department, reviewed by security teams. Realistic, role-specific lures taught the right lessons.
Measure clicks only?
- Click rate
- Click and report rates
Our call: Click and report rates. Reporting turns employees into an early warning system.
Every feature, module by module
Everything that shipped for administrators, employees and the consultancy.
- 01Campaign builder
Targets, schedules and templates.
- 02Department tailoring
Lures relevant to each role.
- 03AI-assisted drafting
Templates drafted, reviewed by admins.
- 04Landing page library
Realistic simulated pages.
- 05Randomised timing
Avoids predictable patterns.
- 06Learning moments
Lessons shown right after a click.
- 07Micro-lessons
Two-minute modules.
- 08Report button
One-click reporting in email.
- 09Recognition
Credit for reporting.
- 10Risk dashboard
Click and report trends.
- 11Department heatmap
Where risk is highest.
- 12Reported email triage
Real reports sent to security.
- 13Compliance reports
Training completion for audits.
- 14Multi-client console
Manage many client organisations.
- 15Directory sync
Users from Microsoft 365 or Google.
- 16Deliverability controls
Allow-listing and sending infrastructure.
- 17Role-based access
Consultants, client admins and employees.
- 18Audit trail
Campaigns and changes recorded.

Launch
The consultancy launched PhishDrill with three existing clients. Over successive campaigns, reporting rose and clicks fell — and several real phishing emails were reported by employees who had learned from simulations.
- Weeks 1–2Discovery
Security teams and employees interviewed.
- Weeks 3–4Design
Learning moments and dashboards.
- Weeks 5–12Build
Campaigns, add-ins, portal and multi-tenancy.
- Weeks 13–15Deliverability testing
Allow-listing with pilot clients.
- Week 16First clients
Three clients live.
What we learned
Reward the right behaviour. Reporting became the metric that mattered.
Kind feedback works. Employees engaged with lessons that did not shame them.
- Next.js
- NestJS
- PostgreSQL multi-tenant
- Email sending infrastructure
- LLM-assisted template drafting
- Microsoft 365 and Google Workspace add-ins
- AWS

