Simulations

Every channel attackers use. Simulated.

Most companies test one channel; attackers use eight. NOUSEC runs continuous, randomized simulation waves with AI-crafted, native-language lures — including deepfake voice — so your measurements reflect the attacks your people will actually face.

8
attack channels — email to deepfake to USB drops
1 in 3
employees click a phishing link when untested (industry baseline)
−86%
average drop in phish-prone rate after 12 months of continuous simulation¹

The eight channels

Email Phishing
AI-crafted lures matched to role, language, and current events.
Smishing (SMS)
Delivery notices, MFA resets, executive requests — on the device people trust most.
Vishing (Voice)
AI-voiced phone simulations in your employees' native language.
Deepfake Voice & Video
Cloned-voice scenarios targeting finance and executive teams.
WhatsApp Phishing
Messaging-app lures where corporate guards are lowest.
QR Phishing (Quishing)
Poisoned QR codes in the flows employees scan without thinking.
USB Drop
Physical baiting campaigns that test curiosity at the desk.
Callback (TOAD)
Harmless-looking emails that route victims to a hostile phone call.

¹ Industry benchmark research, 2025 — based on 67.7M phishing simulations across 14.5M users.

Continuous waves, not annual blasts

One mass test warns the whole office by lunchtime. NOUSEC samples continuously instead.

Randomized delivery
Small waves, varied timing, varied templates — so results measure behavior, not office gossip.
AI-crafted lures
Generated per campaign, matched to role and language. No recycled template museum that everyone has seen twice.
Feeds the score
Every interaction — click, credential entry, report, ignore — flows straight into the Human Risk Score and each employee's adaptive program.

Frequently asked questions

Which attack channels can NOUSEC simulate?

Eight: email phishing, smishing (SMS), vishing (voice), deepfake voice & video, WhatsApp phishing, QR code phishing (quishing), USB drops, and callback scams (TOAD). Attackers don't stop at email — neither do the simulations.

Are the simulations realistic enough to matter?

Lures are AI-crafted per campaign in employees' native languages, and voice simulations use deepfake-grade audio your executives will believe — because the attackers' versions will be. Realism is the point: a test nobody could fail measures nothing.

Will simulations disrupt or embarrass employees?

No. Campaigns run in small randomized waves rather than one office-wide blast, results drive private, adaptive micro-training rather than public shaming, and reporting is celebrated as the win condition.

Do we need to whitelist servers or install anything?

No endpoint agents and no software installation are required. Deliverability setup is guided, and reporting works through one-click Gmail and Outlook add-ins.

Test the channels attackers actually use.

See a live multi-channel simulation — including a deepfake voice call — in a 20-minute demo.

Book a demo