Security Stack Logo
Phished logo

Security Awareness & TrainingEmail Security

Phished

Human risk management platform with automated phishing simulations and just-in-time training.

Phished Overview

What it does

Phished is a Human Risk Management (HRM) and security awareness training platform built to reduce employee-driven security incidents through continuous behavioral change rather than one-off annual courses. It combines automated, personalized phishing simulations, gamified micro-learning, and a proprietary Behavioral Risk Score that quantifies each user's and the organization's cyber resilience. The patent-pending Phished Assistant adds inbox-side isolation, coaching employees in the moment they interact with a suspicious email.

How it works

The platform runs continuous, automated phishing campaigns whose difficulty and content adapt to each user's skill and risk level, and delivers a short nanolearning the moment someone clicks a simulated attack. Phished Academy supplies gamified, bite-sized courses covering topics aligned to NIST, HIPAA, and PCI, while the Behavioral Risk Score tracks behavior change over time. More than 20 reports break down human risk by user, department, location, and country. Phished connects to Microsoft 365 and Google Workspace and syncs users automatically from identity providers such as Okta and Ping Identity, adding a one-click report button and inbox-side email isolation.

Credentials and traction

Phished is ISO 27001 certified (certificate 30050399) and holds a SOC 2 Type II (ISAE 3000) report and a Cyber Essentials certificate, and is GDPR compliant. The platform serves more than 6,500 businesses and 250 managed service provider partners across Europe, North America, and APAC, including VRT, Kinepolis, and Antwerp University Hospital. Content is delivered in English, French, Dutch, Spanish, and German, targeting European organizations that need localized human-risk training.

Key Capabilities

mapped to solution categories
Human Risk Management (HRM)

Provides team-level risk dashboards visible to people managers and HR, enabling business-side accountability for security behavior separate from the security team dashboard.

Includes training content mapped to specific compliance control requirements (HIPAA workforce training, GDPR data handling, PCI DSS cardholder data procedures).

Measures security culture and employee sentiment through surveys and behavioral indicators, tracking how attitudes and norms shift over time and which teams need leadership attention.

Assigns training modules based on each user's observed risk behaviors, role, and previous training results rather than delivering the same content to all users.

Intercepts risky actions (sending email to an external domain, uploading to an unapproved service), and presents a contextual security prompt before the action completes.

Calculates individual security risk scores from observed actions (phishing simulation results, policy violations, risky application usage), rather than training completion status alone.

Syncs user rosters, role changes, and offboarding events from HRIS and identity providers, keeping the platform enrollment current without manual administration.

Sends simulated phishing emails at configurable frequency and difficulty, tracking click, credential submission, and report rates per user and department.

Just-in-Time Security Awareness

Embeds interventions natively in email clients (Outlook, Gmail), browsers, and collaboration tools (Teams, Slack), intervening at the point of risk without requiring a separate application.

Tracks whether intervention recipients change the risky behavior over subsequent weeks, measuring actual behavioral impact rather than click-through or completion metrics.

Fires when a user initiates a specific risky action (sending email to an external domain, uploading a file to an unapproved service, clicking a suspicious link) delivering guidance before the action completes.

Varies intervention content, frequency, and tone based on the user's risk profile and response history, higher-risk users receive more frequent and direct interventions.

Compliance

certifications
Cyber EssentialsDORAGDPRISO 27001ISO 27701NIS2 DirectiveSOC 2 Type II

Integrations

compatible tools
Google WorkspaceMicrosoft 365OktaPing Identity

Implementation & support

Deployment model
SaaS
Support channels
Customer Success Manager (CSM)Knowledge BaseTicketing Portal

Info last updated on September 6, 2026

Buyers

See how Phished fits your stack

Add Phished to your shortlist and unlock all evaluation tools.

Vendors

Is this your product?

Claim your profile to connect with the teams looking for your solutions.

Security Stack Logo

The curated research platform for enterprise cybersecurity solutions.

Resources

All product and company names, logos, and brands are property of their respective owners and are used on this website for identification purposes only. Security Stack does not endorse any vendor, product, or service listed, and makes no warranties, express or implied, as to the accuracy or completeness of this content, including any warranties of merchantability or fitness for a particular purpose.

© 2026 Security Stack. All rights reserved.