Security Awareness Training That Actually Works
ScamDrill sends realistic phishing simulations to your employees, measures their responses, and builds lasting security habits — all from one dashboard. Your first week is a baseline; then Autopilot runs the drills, assigns a short lesson to anyone who slips, and re-tests to prove it stuck.
Start with a 30-day free trial · see your team’s baseline click rate in 7 days · cancel anytime
How Does ScamDrill's Phishing Simulation Platform Work?
Get your organization up and training in minutes
Create Your Organization
Set up in minutes. Invite your security admins to get started.
Add Your Team
Invite by email, CSV upload, or directory sync from Okta, Azure AD, or Google Workspace. Organize into departments.
See Your Baseline
Your first week is a baseline — two unbiased drills per employee. We show you exactly where your team starts, with a one-page result you can take to your boss.
Let Autopilot Run
Autopilot takes over: regular drills, a lesson whenever someone slips, re-tests, and a board-ready report every month. Watch the click rate fall.
What does a workplace phishing simulation look like?
A realistic example of the kind of email your team would actually receive — and the red flags we'd walk them through after.
"Please DocuSign: ACH banking update — vendor onboarding"
A finance "coworker" sends an envelope containing a fraudulent ACH change. The yellow REVIEW DOCUMENT button opens a fake Microsoft 365 login page that captures credentials — used to push fraudulent wire transfers through accounts payable. DocuSign was the most-impersonated brand in workplace credential phishing in 2025.
See the full example →Also covering family-focused scams that target your team's parents and teens — see all 3 simulation examples →
What Does Your Organization Need to Stop Phishing?
Comprehensive tools for managing security training at scale
Adaptive Per-Employee Training
Each employee gets simulations tuned to their own performance—not a one-size-fits-all curriculum. Tactic weaknesses drive what gets sent next, and difficulty auto-progresses across three tiers. Admins see a per-tactic mastery heatmap and can pin a tier.
Realistic Phishing Simulations
Business-focused templates including CEO wire transfer (BEC), Microsoft 365 password expiry, DocuSign requests, and vendor invoice fraud. Each one is tagged by difficulty, channel, and persuasion tactic so it reaches the right employee at the right time.
Departments & Risk Scoring
Group employees into departments and run targeted campaigns — BEC for Finance, credential harvesting for Engineering, social engineering for HR. A live 0–100 resilience score shows which teams are strongest and weakest, blending real drill performance with training results so you know where to focus next.
Campaign Scheduling
Create training campaigns that send simulations automatically on a schedule. Set frequency, choose templates, target specific departments or difficulty tiers, and pause or resume any campaign with one click—independent of the adaptive engine’s cadence.
Compliance Audit Reports
Generate detailed reports with per-employee data: simulations sent, click rates, report rates, risk scores, and annual WBT completion. Export as CSV for SOC 2, ISO 27001, HIPAA, and other audit frameworks. Included on every paid plan.
AI Email Analysis
Business and Enterprise members can forward any suspicious email to check@scamdrill.com for instant AI-powered analysis. Returns a risk score, specific red flags, and a recommended action within seconds—no copy-paste, no separate tool, no extra login.
LMS API Integration
Enterprise REST API for integrating ScamDrill with your existing LMS, SIEM, or security tooling. Manage learners, fetch results, and receive webhook notifications for clicks and reports so your dashboards and analytics stay current in real time.
Annual Compliance Training
Assign a ~20-minute interactive WBT course to every employee once a year. Covers phishing and smishing fundamentals, includes short quizzes, and issues a printable certificate. ScamDrill tracks per-employee completion for SOC 2, ISO 27001, and HIPAA audits.
Autopilot — set-and-forget
Turn it on once and ScamDrill runs itself: pick a cadence (monthly, every two weeks, or weekly), get an adaptive drill schedule per employee, a 2-minute lesson auto-assigned whenever someone slips, a re-test to confirm the habit stuck, and a board-ready report emailed every month. No agents to deploy, no IT tickets. On every org plan.
Closed-loop remediation
A click isn’t the end — it’s the start of a loop. ScamDrill detects the miss, diagnoses the tactic that worked, assigns a short targeted lesson, and then re-tests on that same weakness to verify it landed. Each step fires a webhook (remediation.assigned / .completed / .resolved) so your own dashboards can follow the loop. Supportive, never punitive — and an employee who is on vacation and simply never opens a drill is never counted as a failure.
Report Button — one forward
Employees forward any suspicious email to report@scamdrill.com. If it was a drill, they get credit on the spot and their score goes up. If it was real, it’s logged as a caught threat — and on Business and Enterprise plans they get an AI verdict back within seconds. Works from every mail client on every org plan; no add-in to deploy. Native Outlook add-in: in development.
QR “quishing” simulations
Attackers hide malicious links inside QR codes on fake parking notices, MFA-reset posters, and invoices — because a code can’t be hovered to preview. ScamDrill drills your team on quishing across the same tracking, scoring, and remediation as email and SMS. Multi-channel: Email · SMS · QR.
SSO + SCIM
Single sign-on via SAML 2.0 or OIDC plus automated user lifecycle management with SCIM 2.0. Syncs directly with Okta, Azure AD, Google Workspace, and other identity providers. Available as an add-on on Business and Enterprise plans.
Built for the way your industry gets attacked
Scenario libraries, compliance angles, and FAQ answers specific to your world.
Small Business
Run a real awareness program with no IT department.
Learn more →Schools & Education
Staff drills scheduled around the school calendar.
Learn more →Healthcare & Clinics
HIPAA awareness training without touching PHI.
Learn more →Banks & Financial
Wire-fraud drills with exam-ready records.
Learn more →Nonprofits
Protect donor data and grant funds on a budget.
Learn more →Phishing Simulation Pricing for Every Organization
Choose the right plan for your security needs — every plan starts with a 30-day free trial.
- Email simulations
- Baseline week + Autopilot with monthly report
- Adaptive per-employee training
- Auto-assigned lessons & re-tests on every slip
- Report button (forward to report@)
- Streaks, achievements & tactic mastery
- Centralized dashboard
- Organizational & employee risk scoring
- Annual compliance training (WBT)
- Compliance audit reports & CSV export
- Helpdesk support
- Knowledge base
- Need more than 25 seats? Upgrade to Team any time
30-day free trial
- Email simulations
- Baseline week + Autopilot with monthly report
- Adaptive per-employee training
- Auto-assigned lessons & re-tests on every slip
- Report button (forward to report@)
- Streaks, achievements & tactic mastery
- Centralized dashboard
- Organizational & employee risk scoring
- Annual compliance training (WBT)
- Compliance audit reports & CSV export
- Helpdesk support
- Knowledge base
- Additional seats available at $1.25/mo in blocks of 100
30-day free trial
- Everything in Team
- AI scam detection
- Recurring campaign scheduling
- Department grouping
- Department risk scoring
- Smart CSV import with directory matching
- SSO & SCIM + directory sync (Okta, Azure AD, Google Workspace)(optional add-on — $2,500/yr)
- Additional seats available at $1.00/mo in blocks of 100
30-day free trial
- Everything in Business
- White-label branding
- LMS API access
- Priority support
- SSO & SCIM + directory sync (Okta, Azure AD, Google Workspace)(optional add-on — $2,500/yr)
- Additional seats available at $0.67/mo in blocks of 250
30-day free trial
Need something in-between, SSO & SCIM included, or a custom plan beyond 2,500 seats?
Contact sales@scamdrill.comComparing vendors? See how ScamDrill stacks up against KnowBe4, Hoxhunt, and Huntress SAT — or meet your cyber-insurance training requirement.
FAQ
Common questions from security and IT leaders
An admin creates an organization, invites employees by email or bulk CSV, and manages everything from a centralized dashboard. Employees receive simulations on their own cadence; the admin sees aggregate analytics, department breakdowns, training progress, and audit-ready reports across the entire team.
When you activate an org plan (trial or paid), ScamDrill automatically runs a baseline: every employee gets two intermediate-difficulty email drills over the first seven days, with the adaptive engine and tactic-targeting switched off so the measurement is clean. About 48 hours after the last baseline drill you get a results page — click rate, report rate, per-tactic breakdown, and how you compare with the typical first two weeks of other ScamDrill organizations — plus a printable one-pager for your boss or board. We email you when it’s ready. Then Autopilot takes over.
Autopilot is on by default for every org plan. You choose a cadence — monthly, every two weeks (the cadence most security reviewers recommend), or weekly — and ScamDrill handles the rest: each employee gets drills on that schedule at a difficulty tuned to their own track record, anyone who clicks is assigned a two-minute lesson on the exact persuasion tactic that got them, they’re quietly re-tested on that tactic one to three weeks later, and the admins you list receive a monthly report by email. New employees inherit the cadence automatically. Campaign-level controls (hand-picked templates, department targeting) remain available on Business and Enterprise for teams that want them.
Detect → diagnose → assign → deliver → verify. When an employee clicks a simulated link, the debrief page they land on already offers the lesson for the tactic that worked on them (authority, urgency, scarcity, fear, social proof, reciprocity, commitment, or liking). If they don’t start it, they get a reminder email the next day and one more nudge two days later; lessons expire after a week rather than nagging forever. Each lesson is two to four minutes with a three-question check. Completing it schedules a re-test: their next drill carrying that same tactic arrives 7–21 days later, and reporting it closes the loop. The same lesson is never assigned twice within 30 days, and a repeat slip on the same tactic within 90 days is flagged as escalated in the webhook event — nobody’s manager is ever notified automatically. Ignoring a drill is not a failure and never triggers a lesson.
Yes. Employees forward a suspicious email to report@scamdrill.com from any mail client — Outlook, Gmail, Apple Mail, mobile — with nothing to install. If it was a ScamDrill drill they get credit immediately. If it was a real phishing email, it’s recorded as a caught threat, and on Business and Enterprise plans the employee receives the same AI risk verdict as check@scamdrill.com, framed as a thank-you rather than a scam check. A native Outlook add-in (task-pane button, deployed from the Microsoft 365 admin center) is in development.
Publicly and with the method written down. For each customer organization we compare click rate in its first four weeks of activity with weeks 9–12, counting only organizations with enough sends and active employees in both windows, and we report the median relative change with the interquartile range across at least ten organizations. Internal and test accounts are excluded. The number is computed monthly and only appears on this page once it clears that bar; until then we show nothing rather than a cherry-picked figure. Your own dashboard shows your organization’s trend from day one.
Yes — a one-time setup so simulated phishing lands in inboxes the way real phishing would, instead of getting flagged by your gateway. Our guided Email Delivery wizard walks your IT admin through a few clicks in Microsoft 365, Google Workspace, or your provider of choice. No DNS changes required to get started.
Yes, optionally. By default, simulations come from third-party lookalike domains we own — DHL-style shipping notices, DocuSign-style signature requests, and so on — which mirror real external phishing. For higher-realism internal pretexts (CEO BEC, IT helpdesk, payroll), your admin can pre-approve your own domain in the Email Delivery wizard, and those campaigns will land with your real domain in the From: header. Both modes use an explicit consent click and a full audit log of which sender domains you've authorized.
Realistic enough that click rates on first-month simulations typically match what attackers see in the wild — that's the point. Templates cover the highest-volume real-world pretexts (shipping notifications, document-share requests, Microsoft 365 admin alerts, voicemail notifications, invoice fraud, IT helpdesk tickets, payroll updates, CEO wire-transfer requests). Each simulation pairs a brand-correct visual layout with a sender domain that matches the pretext, and the educational debrief shown after a click teaches the specific red flags that template exercised.
Yes. Organize employees into departments and run targeted training campaigns that send specific simulation templates on a schedule. For example, you can run BEC pretexts for Finance, credential-harvesting campaigns for Engineering, and HR-themed lures for everyone during open enrollment.
Forward any suspicious email to check@scamdrill.com and receive an instant AI-powered analysis: sender authentication, content-pattern review, and link inspection — returning a risk score, red flags, and recommended actions within seconds. Included with Business and Enterprise organization plans.
Every org plan — Starter, Team, Business, and Enterprise — includes audit-ready reports with employee-level detail: simulation delivery records, click and report rates, risk scores, and annual web-based-training completion. Reports export to CSV for SOC 2, ISO 27001, HIPAA, PCI-DSS, and other frameworks. Custom date ranges are supported, and Enterprise+ customers can pull the same data via the REST API.
The Enterprise plan includes a REST API plus webhook events for real-time campaign activity (sent, opened, clicked, reported), remediation lifecycle events (assigned, completed, resolved), and real threats reported by employees. SAML SSO and SCIM directory sync via WorkOS are available as an add-on — works with Okta, Entra ID (Azure AD), Google Workspace, OneLogin, JumpCloud, and any SAML 2.0 IdP, so deprovisioning a user from your IdP automatically deactivates them in ScamDrill.
Yes, on the Enterprise plan. Customize primary and secondary colors, sender display names, and email footers across all training and notification mail. Full white-label mode removes ScamDrill branding entirely so simulations and report emails appear as internal training from your security team.
See ScamDrill in Action
Explore a live demo of the organization dashboard with real data.
Launch Interactive DemoFrom the blog
Practical guides for security leaders at small and mid-sized businesses.
Phishing Simulation for SMBs
Stand up a working program in 30 days — templates, KPIs, and the debrief script.
Why 56% of SMB Employees Still Click
What annual training misses — and what actually moves click rates down.
5 Scam Trends Spiking in 2026
The five fraud categories driving the biggest losses in the IC3's 2025 annual report.
Join our free newsletter to stay ahead of the scammers
Receive updates on monthly scam trends, along with best practices to protect yourself and those you care about.