Real-world phishing simulations
Stay one step ahead of cyber-attacks with our extensive library of phishing simulations and educational landing pages.


Create and schedule phishing simulations with ease
Sending phishing simulations with Boxphish is simple. We have over 150 simulation templates covering both B2C and B2B for you to choose from, or create your own using our simulation builder. Once you've chosen your simulation, simply choose your user group and schedule your send.


Educate users with informative landing pages
Our phishing simulations are designed to educate. Select from a number of landing page options that include hints and tips on how to spot the top signs of phishing should a user click a simulation link. Or, create custom landing pages that reinforce your internal cyber security processes and link to specific policies.
Explore our latest resources
Check out our latest podcasts, webinars, articles and customer stories. Our cyber resources are designed to help you stay one step ahead with expert insights, industry trends and practical tips.
EXPLORE
Product features
All the features you need to raise awareness and strengthen your cyber security posture.

Seamless user sync
Boxphish integrates with both Google and Microsoft Office 365 for seamless user syncing and management.

Single sign-on
Single sign-on means portal access is quick and simple, allowing users to access training efficiently whilst at their desk or on the go.

Phish report button
Allow users to report suspected phishing emails and cyber-attacks with ease directly from their inbox.

Automation
Automated learning journeys mean you can set and forget, with the confidence your employees are getting the training they need.

On-demand
For those wanting to be a little more hands on, on-demand allows you to set up and send simulations and training on an adhoc basis.

Custom content
For customers with bespoke content requirements, we can completely customise training to suit your needs.
FEATURES
Keep the latest threats front of mind with real-world phishing simulations
Simulate the latest cyber security threats
Build awareness and simulate the latest and most prominent phishing attacks. Gain access to templated simulations such as Microsoft 365, HMRC, Dropbox, QR codes and Deliveroo along with custom simulations specific to your organisation. We're always adding to our simulation library, ensuring you have access to rising threats. All simulation campaign data is stored in our reporting suite so you can analyse click rates throughout and track progress.
Access automated learning journeys
Consistency is key when raising cyber awareness and mitigating the risk of attack. Access 12 or 24-month automated learning journeys that consist of a monthly phishing simulation, followed by a short video-based training course that keep threats and key learnings front of mind; giving you the confidence that your users are getting the training they need with minimal strain on internal resources.
Address vulnerabilities with on-demand assignments
Whether you want to create and schedule adhoc phishing simulations to vulnerable user groups or get ahead of an emerging phishing threat, our on-demand functionality allows you to select and send simulations to all users or specific groups. Features such as staggered sending and randomised sending mean you can stagger and mix up your simulation sends; enabling your to simulate a real-world attack.
INCREASING THREAT
Effective risk mitigation goes beyond technical controls
%
of businesses report having experienced some form of cyber security breach or attack
2024 UK Government's Cyber Security Breaches Survey
%
of businesses experience attacks at least once a month
2024 UK Government's Cyber Security Breaches Survey
%
of these attacks are phishing attacks
2024 UK Government's Cyber Security Breaches Survey
%
of breaches involved a non-malicious human element, like a person falling victim to a social engineering attack
Verizon's 2024 Data Breach Investigations Report

LEARN MORE
Online phishing simulation FAQs
How long does it take to implement?
We would typically advise that in order to complete technical pre-requisites around whitelisting, create your phishing and learning journeys and build your report dashboard you need around 7-10 days. The actual time required from the client is minimal, around 60 minutes to complete a 12 month cyber security training programme for your employees.
Do you have an integration to Microsoft365?
Ease of management of the ongoing user base of any SaaS application is key. Boxphish has developed a Microsoft365 integration that will handle the management of your employees meaning that you can deliver one of the best cyber security training programmes available in the market.
How regularly should the employee cyber security training be delivered?
In our view to ensure you provide the best cyber security training to your employees, the training and simulated phishing should be delivered monthly. As part of the onboarding process, you can define the regularity you would like to ensure we meet your exact requirements.
Can the courses be delivered in SCORM format?
Boxphish has created an online employee security training application that has a built in LMS. Should you be interested in delivering cyber security training to your employees via your existing Learning Management System (LMS) then a request would need to be raised with your Account Manager to ensure the SCORM files are sent to you as part of the onboarding process. Please get in touch if you would like further information about this product.
What metrics does the reporting suite show?
The Boxphish report suite is industry leading, providing our customers with insightful metrics on the following;
- Risk Score – Company Wide
- Risk Score – By Department
- Risk Score – by individual
- Heat maps showing overview of simulation
- Engagement by type
- Users enroled in cyber security training
- programme
- Course complete rates
- Timeline of cyber courses
PROVEN SOLUTIONS
Loved by users, backed by G2
KEEP UP TO DATE
See our latest cyber resources
Mar 5, 2026
Local Authority data breaches report: Q3 2025 (Nov 25 - Jan 26)
Mar 5, 2026
Retail data breaches report: Q3 2025 (Nov 25 - Jan 26)
Mar 5, 2026
Education data breaches report: Q3 2025 (Nov 25 - Jan 26)













